1  <vuln vid="cf484358-b5d6-11dc-8de0-001c2514716c">
2    <topic>dovecot -- Specific LDAP + auth cache configuration may mix up user logins</topic>
3    <affects>
4      <package>
5	<name>dovecot</name>
6	<range><lt>1.0.10</lt></range>
7      </package>
8    </affects>
9    <description>
10      <body xmlns="http://www.w3.org/1999/xhtml">
11	<p>Dovecot reports:</p>
12	<blockquote cite="http://www.dovecot.org/list/dovecot-news/2007-December/000057.html">
13	  <p>If two users with the same password and same pass_filter
14	    variables log in within auth_cache_ttl seconds (1h by default),
15	    the second user may get logged in with the first user's cached
16	    pass_attrs. For example if pass_attrs contained the user's
17	    home/mail directory, this would mean that the second user will
18	    be accessing the first user's mails.</p>
19	</blockquote>
20      </body>
21    </description>
22    <references>
23      <url>http://www.dovecot.org/list/dovecot-news/2007-December/000057.html</url>
24    </references>
25    <dates>
26      <discovery>2007-12-21</discovery>
27      <entry>2007-12-29</entry>
28    </dates>
29  </vuln>
30
31  <vuln vid="4aab7bcd-b294-11dc-a6f0-00a0cce0781e">
32    <topic>gallery2 -- multiple vulnerabilities</topic>
33    <affects>
34      <package>
35	<name>gallery2</name>
36	<range><lt>2.2.4</lt></range>
37      </package>
38    </affects>
39    <description>
40      <body xmlns="http://www.w3.org/1999/xhtml">
41	<p>The Gallery team reports:</p>
42	<blockquote cite="http://gallery.menalto.com/gallery_2.2.4_released">
43	  <p>Gallery 2.2.4 addresses the following security
44	    vulnerabilities:</p>
45	  <ul>
46	    <li>Publish XP module - Fixed unauthorized album creation
47	      and file uploads.</li>
48	    <li>URL rewrite module - Fixed local file inclusion
49	      vulnerability in unsecured admin controller and
50	      information disclosure in hotlink protection.</li>
51	    <li>Core / add-item modules - Fixed Cross Site Scripting
52	      (XSS) vulnerabilities through malicious file names.</li>
53	    <li>Installation (Gallery application) - Update
54	      web-accessibility protection of the storage folder for
55	      Apache 2.2.</li>
56	    <li>Core (Gallery application) / MIME module - Fixed
57	      vulnerability in checks for disallowed file extensions
58	      in file uploads.</li>
59	    <li>Gallery Remote module - Added missing permissions
60	      checks for some GR commands.</li>
61	    <li>WebDAV module - Fixed Cross Site Scripting (XSS)
62	      vulnerability through HTTP PROPPATCH.</li>
63	    <li>WebDAV module - Fixed information (item data)
64	      disclosure in a WebDAV view.</li>
65	    <li>Comment module - Fixed information (item data)
66	      disclosure in comment views.</li>
67	    <li>Core module (Gallery application) - Improved
68	      resilience against item information disclosure
69	      attacks.</li>
70	    <li>Slideshow module - Fixed information (item data)
71	      disclosure in the slideshow.</li>
72	    <li>Print modules - Fixed information (item data)
73	      disclosure in several print modules.</li>
74	    <li>Core / print modules - Fixed arbitrary URL redirection
75	      (phishing attacks) in the core module and several print
76	      modules.</li>
77	    <li>WebCam module - Fixed proxied request weakness.</li>
78	  </ul>
79	</blockquote>
80      </body>
81    </description>
82    <references>
83      <cvename>CVE-2007-6685</cvename>
84      <cvename>CVE-2007-6686</cvename>
85      <cvename>CVE-2007-6687</cvename>
86      <cvename>CVE-2007-6689</cvename>
87      <cvename>CVE-2007-6690</cvename>
88      <cvename>CVE-2007-6692</cvename>
89      <url>http://gallery.menalto.com/gallery_2.2.4_released</url>
90    </references>
91    <dates>
92      <discovery>2007-12-24</discovery>
93      <entry>2007-12-25</entry>
94      <modified>2010-05-12</modified>
95    </dates>
96  </vuln>
97
98  <vuln vid="299e3f81-aee7-11dc-b781-0016179b2dd5">
99    <topic>e2fsprogs -- heap buffer overflow</topic>
100    <affects>
101      <package>
102	<name>e2fsprogs</name>
103	<range><lt>1.40.3</lt></range>
104      </package>
105    </affects>
106    <description>
107      <body xmlns="http://www.w3.org/1999/xhtml">
108	<p>Theodore Y. Ts'o reports:</p>
109	<blockquote cite="http://sourceforge.net/project/shownotes.php?group_id=2406&amp;release_id=560230">
110	  <p>Fix a potential security vulnerability where an untrusted
111	    filesystem can be corrupted in such a way that a program using
112	    libext2fs will allocate a buffer which is far too small.  This
113	    can lead to either a crash or potentially a heap-based buffer
114	    overflow crash.  No known exploits exist, but main concern is
115	    where an untrusted user who possesses privileged access in a
116	    guest Xen environment could corrupt a filesystem which is then
117	    accessed by thus allowing the untrusted user to gain privileged
118	    access in the host OS.  Thanks to the McAfee AVERT Research group
119	    for reporting this issue.</p>
120	</blockquote>
121      </body>
122    </description>
123    <references>
124      <bid>26772</bid>
125      <cvename>CVE-2007-5497</cvename>
126      <url>http://secunia.com/advisories/27889/</url>
127      <url>http://sourceforge.net/project/shownotes.php?group_id=2406&amp;release_id=560230</url>
128    </references>
129    <dates>
130      <discovery>2007-12-07</discovery>
131      <entry>2007-12-20</entry>
132    </dates>
133  </vuln>
134
135  <vuln vid="8a835235-ae84-11dc-a5f9-001a4d49522b">
136    <topic>wireshark -- multiple vulnerabilities</topic>
137    <affects>
138      <package>
139	<name>wireshark</name>
140	<name>wireshark-lite</name>
141	<name>ethereal</name>
142	<name>ethereal-lite</name>
143	<name>tethereal</name>
144	<name>tethereal-lite</name>
145	<range><ge>0.8.16</ge><lt>0.99.7</lt></range>
146      </package>
147    </affects>
148    <description>
149      <body xmlns="http://www.w3.org/1999/xhtml">
150	<p>The Wireshark team reports of multiple vulnerabilities:</p>
151	<blockquote cite="http://www.wireshark.org/security/wnpa-sec-2007-03.html">
152	  <ul>
153	    <li>Wireshark could crash when reading an MP3 file.</li>
154	    <li>Beyond Security discovered that Wireshark could loop
155	      excessively while reading a malformed DNP packet.</li>
156	    <li>Stefan Esser discovered a buffer overflow in the SSL
157	      dissector.</li>
158	    <li>The ANSI MAP dissector could be susceptible to a
159	      buffer overflow on some platforms.</li>
160	    <li>The Firebird/Interbase dissector could go into an
161	      infinite loop or crash.</li>
162	    <li>The NCP dissector could cause a crash.</li>
163	    <li>The HTTP dissector could crash on some systems while
164	      decoding chunked messages.</li>
165	    <li>The MEGACO dissector could enter a large loop and
166	      consume system resources.</li>
167	    <li>The DCP ETSI dissector could enter a large loop and
168	      consume system resources.</li>
169	    <li>Fabiodds discovered a buffer overflow in the iSeries
170	      (OS/400) Communication trace file parser.</li>
171	    <li>The PPP dissector could overflow a buffer.</li>
172	    <li>The Bluetooth SDP dissector could go into an infinite
173	      loop.</li>
174	    <li>A malformed RPC Portmap packet could cause a
175	      crash.</li>
176	    <li>The IPv6 dissector could loop excessively.</li>
177	    <li>The USB dissector could loop excessively or crash.</li>
178	    <li>The SMB dissector could crash.</li>
179	    <li>The RPL dissector could go into an infinite loop.</li>
180	    <li>The WiMAX dissector could crash due to unaligned
181	      access on some platforms.</li>
182	    <li>The CIP dissector could attempt to allocate a huge
183	      amount of memory and crash.</li>
184	  </ul>
185
186	  <h2>Impact</h2>
187
188	  <p>It may be possible to make Wireshark or Ethereal crash or
189	    use up available memory by injecting a purposefully
190	    malformed packet onto the wire or by convincing someone to
191	    read a malformed packet trace file.</p>
192	</blockquote>
193      </body>
194    </description>
195    <references>
196      <cvename>CVE-2007-6112</cvename>
197      <cvename>CVE-2007-6113</cvename>
198      <cvename>CVE-2007-6114</cvename>
199      <cvename>CVE-2007-6115</cvename>
200      <cvename>CVE-2007-6117</cvename>
201      <cvename>CVE-2007-6118</cvename>
202      <cvename>CVE-2007-6120</cvename>
203      <cvename>CVE-2007-6121</cvename>
204      <cvename>CVE-2007-6438</cvename>
205      <cvename>CVE-2007-6439</cvename>
206      <cvename>CVE-2007-6441</cvename>
207      <cvename>CVE-2007-6450</cvename>
208      <cvename>CVE-2007-6451</cvename>
209      <url>http://www.wireshark.org/security/wnpa-sec-2007-03.html</url>
210    </references>
211    <dates>
212      <discovery>2007-12-19</discovery>
213      <entry>2007-12-19</entry>
214      <modified>2007-12-22</modified>
215    </dates>
216  </vuln>
217
218  <vuln vid="31b045e7-ae75-11dc-a5f9-001a4d49522b">
219    <topic>opera -- multiple vulnerabilities</topic>
220    <affects>
221      <package>
222	<name>opera</name>
223	<name>opera-devel</name>
224	<name>linux-opera</name>
225	<range><lt>9.25</lt></range>
226      </package>
227    </affects>
228    <description>
229      <body xmlns="http://www.w3.org/1999/xhtml">
230	<p>Opera Software ASA reports about multiple security
231	  fixes:</p>
232	<blockquote cite="http://www.opera.com/docs/changelogs/freebsd/925/">
233	  <ul>
234	    <li>Fixed an issue where plug-ins could be used to allow
235	      cross domain scripting, as reported by David
236	      Bloom. Details will be disclosed at a later date.</li>
237	    <li>Fixed an issue with TLS certificates that could be
238	      used to execute arbitrary code, as reported by Alexander
239	      Klink (Cynops GmbH). Details will be disclosed at a
240	      later date.</li>
241	    <li>Rich text editing can no longer be used to allow cross
242	      domain scripting, as reported by David Bloom. See our
243	      advisory.</li>
244	    <li>Prevented bitmaps from revealing random data from
245	      memory, as reported by Gynvael Coldwind. Details will be
246	      disclosed at a later date.</li>
247	  </ul>
248	</blockquote>
249      </body>
250    </description>
251    <references>
252      <cvename>CVE-2007-6520</cvename>
253      <cvename>CVE-2007-6521</cvename>
254      <cvename>CVE-2007-6522</cvename>
255      <cvename>CVE-2007-6524</cvename>
256      <url>http://www.opera.com/docs/changelogs/freebsd/925/</url>
257      <url>http://www.opera.com/support/search/view/875/</url>
258    </references>
259    <dates>
260      <discovery>2007-12-19</discovery>
261      <entry>2007-12-19</entry>
262      <modified>2007-12-29</modified>
263    </dates>
264  </vuln>
265
266  <vuln vid="31435fbc-ae73-11dc-a5f9-001a4d49522b">
267    <topic>peercast -- buffer overflow vulnerability</topic>
268    <affects>
269      <package>
270	<name>peercast</name>
271	<range><lt>0.1218</lt></range>
272      </package>
273    </affects>
274    <description>
275      <body xmlns="http://www.w3.org/1999/xhtml">
276	<p>Luigi Auriemma reports that peercast is vulnerable to a
277	  buffer overflow which could lead to a DoS or potentially
278	  remote code execution:</p>
279	<blockquote cite="http://aluigi.altervista.org/adv/peercasthof-adv.txt">
280	  <p>The handshakeHTTP function which handles all the requests
281	    received by the other clients is vulnerable to a heap
282	    overflow which allows an attacker to fill the
283	    loginPassword and loginMount buffers located in the
284	    Servent class with how much data he wants.</p>
285	</blockquote>
286      </body>
287    </description>
288    <references>
289      <cvename>CVE-2007-6454</cvename>
290      <url>http://aluigi.altervista.org/adv/peercasthof-adv.txt</url>
291      <url>http://secunia.com/advisories/28120/</url>
292    </references>
293    <dates>
294      <discovery>2007-12-17</discovery>
295      <entry>2007-12-19</entry>
296      <modified>2010-05-12</modified>
297    </dates>
298  </vuln>
299
300  <vuln vid="fee7e059-acec-11dc-807f-001b246e4fdf">
301    <topic>ganglia-webfrontend -- XSS vulnerabilities</topic>
302    <affects>
303      <package>
304	<name>ganglia-webfrontend</name>
305	<range><lt>3.0.6</lt></range>
306      </package>
307    </affects>
308    <description>
309      <body xmlns="http://www.w3.org/1999/xhtml">
310	<p>The Ganglia project reports:</p>
311	<blockquote cite="http://ganglia.info/?p=60">
312	  <p>The Ganglia development team is pleased to release Ganglia
313	    3.0.6 (Foss) which is available[...].  This release includes a
314	    security fix for web frontend cross-scripting vulnerability.</p>
315	</blockquote>
316      </body>
317    </description>
318    <references>
319      <url>http://sourceforge.net/mailarchive/message.php?msg_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com</url>
320      <url>http://sourceforge.net/mailarchive/forum.php?thread_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com&amp;forum_name=ganglia-developers</url>
321    </references>
322    <dates>
323      <discovery>2007-12-10</discovery>
324      <entry>2007-12-17</entry>
325      <modified>2007-12-18</modified>
326    </dates>
327  </vuln>
328
329  <vuln vid="30f5ca1d-a90b-11dc-bf13-0211060005df">
330    <topic>qemu -- Translation Block Local Denial of Service Vulnerability</topic>
331    <affects>
332      <package>
333	<name>qemu</name>
334	<name>qemu-devel</name>
335	<range><lt>0.9.0_4</lt></range>
336	<range><ge>0.9.0s.20070101*</ge><lt>0.9.0s.20070802_1</lt></range>
337      </package>
338    </affects>
339    <description>
340      <body xmlns="http://www.w3.org/1999/xhtml">
341	<p>SecurityFocus reports:</p>
342	<blockquote cite="http://www.securityfocus.com/bid/26666/discuss">
343	  <p>QEMU is prone to a local denial-of-service vulnerability
344	    because it fails to perform adequate boundary checks when
345	    handling user-supplied input.</p>
346	  <p>Attackers can exploit this issue to cause denial-of-service
347	    conditions. Given the nature of the issue, attackers may also be
348	    able to execute arbitrary code, but this has not been confirmed.</p>
349	</blockquote>
350      </body>
351    </description>
352    <references>
353      <bid>26666</bid>
354      <cvename>CVE-2007-6227</cvename>
355      <url>http://www.securityfocus.com/archive/1/484429</url>
356    </references>
357    <dates>
358      <discovery>2007-11-30</discovery>
359      <entry>2007-12-12</entry>
360      <modified>2007-12-14</modified>
361    </dates>
362  </vuln>
363
364  <vuln vid="fa708908-a8c7-11dc-b41d-000fb5066b20">
365    <topic>drupal -- SQL injection vulnerability</topic>
366    <affects>
367      <package>
368	<name>drupal5</name>
369	<range><lt>5.4</lt></range>
370      </package>
371      <package>
372	<name>drupal4</name>
373	<range><lt>4.7.9</lt></range>
374      </package>
375    </affects>
376    <description>
377      <body xmlns="http://www.w3.org/1999/xhtml">
378	<p>The Drupal Project reports:</p>
379	<blockquote cite="http://drupal.org/node/198162">
380	  <p>The function taxonomy_select_nodes() directly injects variables
381	    into SQL queries instead of using placeholders. While taxonomy
382	    module itself validates the input passed to
383	    taxonomy_select_nodes(), this is a weakness in Drupal core.
384	    Several contributed modules, such as taxonomy_menu, ajaxLoader,
385	    and ubrowser, directly pass user input to taxonomy_select_nodes(),
386	    enabling SQL injection attacks by anonymous users.</p>
387	</blockquote>
388      </body>
389    </description>
390    <references>
391      <cvename>CVE-2007-6299</cvename>
392      <url>http://drupal.org/node/198162</url>
393      <url>http://secunia.com/advisories/27932/</url>
394    </references>
395    <dates>
396      <discovery>2007-12-05</discovery>
397      <entry>2007-12-12</entry>
398    </dates>
399  </vuln>
400
401  <vuln vid="ffcbd42d-a8c5-11dc-bec2-02e0185f8d72">
402    <topic>samba -- buffer overflow vulnerability</topic>
403    <affects>
404      <package>
405	<name>samba</name>
406	<name>samba3</name>
407	<name>ja-samba</name>
408	<range><lt>3.0.28</lt></range>
409	<range><gt>*,1</gt><lt>3.0.28,1</lt></range>
410      </package>
411    </affects>
412    <description>
413      <body xmlns="http://www.w3.org/1999/xhtml">
414	<p>Secuna Research reports:</p>
415	<blockquote cite="http://secunia.com/advisories/27760/">
416	  <p>Secunia Research has discovered a vulnerability in Samba, which
417	    can be exploited by malicious people to compromise a vulnerable
418	    system.  The vulnerability is caused due to a boundary error within
419	    the "send_mailslot()" function.  This can be exploited to cause a
420	    stack-based buffer overflow with zero bytes via a specially crafted
421	    "SAMLOGON" domain logon packet containing a username string placed
422	    at an odd offset followed by an overly long GETDC string.
423	    Successful exploitation allows execution of arbitrary code, but
424	    requires that the "domain logons" option is enabled.</p>
425	</blockquote>
426      </body>
427    </description>
428    <references>
429      <cvename>CVE-2007-6015</cvename>
430      <url>http://secunia.com/advisories/27760/</url>
431    </references>
432    <dates>
433      <discovery>2007-12-10</discovery>
434      <entry>2007-12-12</entry>
435      <modified>2008-09-26</modified>
436    </dates>
437  </vuln>
438
439  <vuln vid="b2571f88-a867-11dc-a6f0-00a0cce0781e">
440    <topic>smbftpd -- format string vulnerability</topic>
441    <affects>
442      <package>
443	<name>smbftpd</name>
444	<range><lt>0.96</lt></range>
445      </package>
446    </affects>
447    <description>
448      <body xmlns="http://www.w3.org/1999/xhtml">
449	<p>Secunia reports:</p>
450	<blockquote cite="http://secunia.com/advisories/27014/">
451	  <p>Format string vulnerability in the SMBDirList function in dirlist.c
452	    in SmbFTPD 0.96 allows remote attackers to execute arbitrary code
453	    via format string specifiers in a directory name.</p>
454	</blockquote>
455      </body>
456    </description>
457    <references>
458      <cvename>CVE-2007-5184</cvename>
459      <url>http://secunia.com/advisories/27014/</url>
460      <url>http://sourceforge.net/project/shownotes.php?release_id=543077</url>
461    </references>
462    <dates>
463      <discovery>2007-10-01</discovery>
464      <entry>2007-12-12</entry>
465    </dates>
466  </vuln>
467
468  <vuln vid="6ae7cef2-a6ae-11dc-95e6-000c29c5647f">
469    <topic>jetty -- multiple vulnerabilities</topic>
470    <affects>
471      <package>
472	<name>jetty</name>
473	<range><lt>6.1.6</lt></range>
474      </package>
475    </affects>
476    <description>
477      <body xmlns="http://www.w3.org/1999/xhtml">
478	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5613">
479	  <p>Cross-site scripting (XSS) vulnerability in Dump Servlet in
480	    Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject
481	    arbitrary web script or HTML via unspecified parameters and
482	    cookies.</p>
483	</blockquote>
484	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5614">
485	  <p>Mortbay Jetty before 6.1.6rc1 does not properly handle "certain
486	    quote sequences" in HTML cookie parameters, which allows remote
487	    attackers to hijack browser sessions via unspecified vectors.</p>
488	</blockquote>
489	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5615">
490	  <p>CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0
491	    allows remote attackers to inject arbitrary HTTP headers and
492	    conduct HTTP response splitting attacks via unspecified vectors.
493	  </p>
494	</blockquote>
495      </body>
496    </description>
497    <references>
498      <certvu>237888</certvu>
499      <certvu>212984</certvu>
500      <certvu>438616</certvu>
501      <cvename>CVE-2007-5613</cvename>
502      <cvename>CVE-2007-5614</cvename>
503      <cvename>CVE-2007-5615</cvename>
504      <url>http://svn.codehaus.org/jetty/jetty/trunk/VERSION.txt</url>
505    </references>
506    <dates>
507      <discovery>2007-12-05</discovery>
508      <entry>2007-12-10</entry>
509    </dates>
510  </vuln>
511
512  <vuln vid="821afaa2-9e9a-11dc-a7e3-0016360406fa">
513    <topic>liveMedia -- DoS vulnerability</topic>
514    <affects>
515      <package>
516	<name>liveMedia</name>
517	<range><lt>2007.11.18,1</lt></range>
518      </package>
519    </affects>
520    <description>
521      <body xmlns="http://www.w3.org/1999/xhtml">
522	<p>The live555 development team reports:</p>
523	<blockquote cite="http://www.live555.com/liveMedia/public/changelog.txt">
524	  <p>Fixed a bounds-checking error in "parseRTSPRequestString()"
525	    caused by an int vs. unsigned problem.</p>
526	</blockquote>
527	<blockquote cite="http://aluigi.altervista.org/adv/live555x-adv.txt">
528	  <p>The function which handles the incoming queries from the
529	    clients is affected by a vulnerability which allows an attacker
530	    to crash the server remotely using the smallest RTSP query
531	    possible to use.</p>
532    </blockquote>
533      </body>
534    </description>
535    <references>
536      <cvename>CVE-2007-6036</cvename>
537      <url>http://aluigi.altervista.org/adv/live555x-adv.txt</url>
538      <url>http://www.live555.com/liveMedia/public/changelog.txt</url>
539    </references>
540    <dates>
541      <discovery>2007-11-20</discovery>
542      <entry>2007-12-08</entry>
543      <modified>2007-12-09</modified>
544    </dates>
545  </vuln>
546
547  <vuln vid="610bc692-a2ad-11dc-900c-000bcdc1757a">
548    <topic>GNU finger vulnerability</topic>
549    <affects>
550      <package>
551	<name>gnu-finger</name>
552	<range><le>1.37_1</le></range>
553      </package>
554    </affects>
555    <description>
556      <body xmlns="http://www.w3.org/1999/xhtml">
557	<p>GNU security announcement:</p>
558	<blockquote cite="http://www.gnu.org/software/finger/">
559	  <p>GNU Finger unfortunately has not been updated in
560	   many years, and has known security vulnerabilities.
561	   Please do not use it in production environments.</p>
562	</blockquote>
563      </body>
564    </description>
565    <references>
566      <cvename>CVE-1999-1165</cvename>
567      <url>http://www.gnu.org/software/finger/</url>
568    </references>
569    <dates>
570      <discovery>1999-07-21</discovery>
571      <entry>2007-12-05</entry>
572    </dates>
573  </vuln>
574
575  <vuln vid="6eb580d7-a29c-11dc-8919-001c2514716c">
576    <topic>Squid -- Denial of Service Vulnerability</topic>
577    <affects>
578      <package>
579	<name>squid</name>
580	<range><ge>2.0</ge><lt>2.6.16_1</lt></range>
581	<range><ge>3.*</ge><lt>3.0.r1.20071001_1</lt></range>
582      </package>
583    </affects>
584    <description>
585      <body xmlns="http://www.w3.org/1999/xhtml">
586	<p>Squid secuirty advisory reports:</p>
587	<blockquote cite="http://www.squid-cache.org/Advisories/SQUID-2007_2.txt">
588	  <p>Due to incorrect bounds checking Squid is vulnerable
589	    to a denial of service check during some cache update
590	    reply processing.</p>
591	  <p>This problem allows any client trusted to use the
592	    service to perform a denial of service attack on the
593	    Squid service.</p>
594	</blockquote>
595      </body>
596    </description>
597    <references>
598      <bid>26687</bid>
599      <cvename>CVE-2007-6239</cvename>
600    </references>
601    <dates>
602      <discovery>2007-11-28</discovery>
603      <entry>2007-12-04</entry>
604      <modified>2007-12-07</modified>
605    </dates>
606  </vuln>
607
608  <vuln vid="30acb8ae-9d46-11dc-9114-001c2514716c">
609    <topic>rubygem-rails -- session-fixation vulnerability</topic>
610    <affects>
611      <package>
612	<name>rubygem-rails</name>
613	<range><lt>1.2.6</lt></range>
614      </package>
615    </affects>
616    <description>
617      <body xmlns="http://www.w3.org/1999/xhtml">
618	<p>Rails core team reports:</p>
619	<blockquote cite="http://weblog.rubyonrails.com/2007/11/24/ruby-on-rails-1-2-6-security-and-maintenance-release">
620	  <p>The rails core team has released ruby on rails 1.2.6 to
621	    address a bug in the fix for session fixation attacks
622	    (CVE-2007-5380). The CVE Identifier for this new issue
623	    is CVE-2007-6077.</p>
624	</blockquote>
625      </body>
626    </description>
627    <references>
628      <cvename>CVE-2007-6077</cvename>
629    </references>
630    <dates>
631      <discovery>2007-11-24</discovery>
632      <entry>2007-11-27</entry>
633    </dates>
634  </vuln>
635
636  <vuln vid="44fb0302-9d38-11dc-9114-001c2514716c">
637    <topic>rubygem-rails -- JSON XSS vulnerability</topic>
638    <affects>
639      <package>
640	<name>rubygem-rails</name>
641	<range><lt>1.2.5</lt></range>
642      </package>
643      <package>
644	<name>rubygem-activesupport</name>
645	<range><lt>1.4.4</lt></range>
646      </package>
647    </affects>
648    <description>
649      <body xmlns="http://www.w3.org/1999/xhtml">
650	<p>Rails core team reports:</p>
651	<blockquote cite="http://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-release">
652	  <p>All users of Rails 1.2.4 or earlier are advised to upgrade
653	    to 1.2.5, though it isn't strictly necessary if you
654	    aren't working with JSON. For more information the JSON
655	    vulnerability, see CVE-2007-3227.</p>
656	</blockquote>
657      </body>
658    </description>
659    <references>
660      <cvename>CVE-2007-3227</cvename>
661    </references>
662    <dates>
663      <discovery>2007-10-12</discovery>
664      <entry>2007-11-28</entry>
665      <modified>2007-12-01</modified>
666    </dates>
667  </vuln>
668
669  <vuln vid="31d9fbb4-9d09-11dc-a29d-0016d325a0ed">
670    <topic>ikiwiki -- improper symlink verification vulnerability</topic>
671    <affects>
672      <package>
673	<name>ikiwiki</name>
674	<range><lt>2.14</lt></range>
675      </package>
676    </affects>
677    <description>
678      <body xmlns="http://www.w3.org/1999/xhtml">
679	<p>The ikiwiki development team reports:</p>
680	<blockquote cite="http://ikiwiki.info/security/#index29h2">
681	  <p>Ikiwiki did not check if path to the srcdir to contained a
682	    symlink. If an attacker had commit access to the directories in
683	    the path, they could change it to a symlink, causing ikiwiki to
684	    read and publish files that were not intended to be
685	    published. (But not write to them due to other checks.)</p>
686	</blockquote>
687      </body>
688    </description>
689    <references>
690      <url>http://ikiwiki.info/security/#index29h2</url>
691    </references>
692    <dates>
693      <discovery>2007-11-26</discovery>
694      <entry>2007-11-27</entry>
695    </dates>
696  </vuln>
697
698  <vuln vid="f1f6f6da-9d2f-11dc-9114-001c2514716c">
699    <topic>firefox -- multiple remote unspecified memory corruption vulnerabilities</topic>
700    <affects>
701      <package>
702	<name>firefox</name>
703	<range><lt>2.0.0.10,1</lt></range>
704      </package>
705      <package>
706	<name>linux-firefox</name>
707	<range><lt>2.0.0.10</lt></range>
708      </package>
709      <package>
710	<name>seamonkey</name>
711	<name>linux-seamonkey</name>
712	<range><lt>1.1.7</lt></range>
713      </package>
714      <package>
715	<name>flock</name>
716	<name>linux-flock</name>
717	<range><lt>1.0.2</lt></range>
718      </package>
719      <package>
720	<name>linux-firefox-devel</name>
721	<range><lt>3.0.a2007.12.12</lt></range>
722      </package>
723      <package>
724	<name>linux-seamonkey-devel</name>
725	<range><lt>2.0.a2007.12.12</lt></range>
726      </package>
727    </affects>
728    <description>
729      <body xmlns="http://www.w3.org/1999/xhtml">
730	<p>Mozilla Foundation reports:</p>
731	<blockquote cite="http://www.mozilla.org/security/announce/2007/mfsa2007-38.html">
732	  <p>The Firefox 2.0.0.10 update contains fixes for three bugs that
733	    improve the stability of the product. These crashes showed some
734	    evidence of memory corruption under certain circumstances and we
735	    presume that with enough effort at least some of these could be
736	    exploited to run arbitrary code.</p>
737	</blockquote>
738      </body>
739    </description>
740    <references>
741      <bid>26593</bid>
742      <cvename>CVE-2007-5959</cvename>
743    </references>
744    <dates>
745      <discovery>2007-11-26</discovery>
746      <entry>2007-11-27</entry>
747      <modified>2007-12-14</modified>
748    </dates>
749  </vuln>
750
751  <vuln vid="15485ae8-9848-11dc-9e48-0016179b2dd5">
752    <topic>phpmyadmin -- Cross Site Scripting</topic>
753    <affects>
754      <package>
755	<name>phpmyadmin</name>
756	<range><lt>2.11.2.2</lt></range>
757      </package>
758    </affects>
759    <description>
760      <body xmlns="http://www.w3.org/1999/xhtml">
761	<p>phpMyAdmin security announcement:</p>
762	<blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8">
763	  <p>The login page auth_type cookie was vulnerable to XSS via
764	    the convcharset parameter. An attacker could use this to
765	    execute malicious code on the visitors computer</p>
766	</blockquote>
767      </body>
768    </description>
769    <references>
770      <cvename>CVE-2007-6100</cvename>
771      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8</url>
772      <url>http://www.nth-dimension.org.uk/downloads.php?id=38</url>
773    </references>
774    <dates>
775      <discovery>2007-11-20</discovery>
776      <entry>2007-11-21</entry>
777      <modified>2010-05-12</modified>
778    </dates>
779  </vuln>
780
781  <vuln vid="a63b15f9-97ff-11dc-9e48-0016179b2dd5">
782    <topic>samba -- multiple vulnerabilities</topic>
783    <affects>
784      <package>
785	<name>samba</name>
786	<name>samba3</name>
787	<name>ja-samba</name>
788	<range><lt>3.0.26a</lt></range>
789	<range><gt>*,1</gt><lt>3.0.26a_2,1</lt></range>
790      </package>
791    </affects>
792    <description>
793      <body xmlns="http://www.w3.org/1999/xhtml">
794	<p>The Samba Team reports:</p>
795	<blockquote cite="http://us1.samba.org/samba/security/CVE-2007-5398.html">
796	  <p>Secunia Research reported a vulnerability that allows for
797	    the execution of arbitrary code in nmbd.  This defect may
798	    only be exploited when the "wins support" parameter has
799	    been enabled in smb.conf.</p>
800	</blockquote>
801	<blockquote cite="http://us1.samba.org/samba/security/CVE-2007-4572.html">
802	  <p>Samba developers have discovered what is believed to be
803	  a non-exploitable buffer over in nmbd during the processing
804	  of GETDC logon server requests.  This code is only used
805	  when the Samba server is configured as a Primary or Backup
806	  Domain Controller.</p>
807	</blockquote>
808      </body>
809    </description>
810    <references>
811      <bid>26454</bid>
812      <cvename>CVE-2007-4572</cvename>
813      <cvename>CVE-2007-5398</cvename>
814      <url>http://secunia.com/advisories/27450/</url>
815      <url>http://us1.samba.org/samba/security/CVE-2007-4572.html</url>
816      <url>http://us1.samba.org/samba/security/CVE-2007-5398.html</url>
817    </references>
818    <dates>
819      <discovery>2007-11-15</discovery>
820      <entry>2007-11-21</entry>
821      <modified>2008-09-26</modified>
822    </dates>
823  </vuln>
824
825  <vuln vid="392b5b1d-9471-11dc-9db7-001c2514716c">
826    <topic>php -- multiple security vulnerabilities</topic>
827    <affects>
828      <package>
829	<name>php5</name>
830	<range><lt>5.2.5</lt></range>
831      </package>
832    </affects>
833    <description>
834      <body xmlns="http://www.w3.org/1999/xhtml">
835	<p>PHP project reports:</p>
836	<blockquote cite="http://www.php.net/releases/5_2_5.php">
837	  <p>Security Enhancements and Fixes in PHP 5.2.5:</p>
838	  <ul>
839	    <li>Fixed dl() to only accept filenames. Reported by Laurent
840	      Gaffie.</li>
841	    <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887).
842	      Reported by Laurent Gaffie.</li>
843	    <li>Fixed htmlentities/htmlspecialchars not to accept partial
844	      multibyte sequences. Reported by Rasmus Lerdorf</li>
845	    <li>Fixed possible triggering of buffer overflows inside glibc
846	      implementations of the fnmatch(), setlocale() and glob()
847	      functions.  Reported by Laurent Gaffie.</li>
848	    <li>Fixed "mail.force_extra_parameters" php.ini directive not to be
849	      modifiable in .htaccess due to the security implications. Reported
850	      by SecurityReason.</li>
851	    <li>Fixed bug #42869 (automatic session id insertion adds sessions
852	      id to non-local forms).</li>
853	    <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can
854	      be overwritten with ini_set()).</li>
855	  </ul>
856	</blockquote>
857      </body>
858    </description>
859    <references>
860      <bid>26403</bid>
861      <cvename>CVE-2007-4887</cvename>
862    </references>
863    <dates>
864      <discovery>2007-11-08</discovery>
865      <entry>2007-11-16</entry>
866    </dates>
867  </vuln>
868
869  <vuln vid="a7080c30-91a2-11dc-b2eb-00b0d07e6c7e">
870    <topic>mt-daapd -- denial of service vulnerability</topic>
871    <affects>
872      <package>
873	<name>mt-daapd</name>
874	<range><lt>0.2.4.1</lt></range>
875      </package>
876    </affects>
877    <description>
878      <body xmlns="http://www.w3.org/1999/xhtml">
879	<p>US-CERT reports:</p>
880	<blockquote cite="http://www.us-cert.gov/cas/bulletins/SB07-316.html">
881	  <p>webserver.c in mt-dappd in Firefly Media Server 0.2.4 and
882	    earlier allows remote attackers to cause a denial of service
883	    (NULL dereference and daemon crash) via a stats method action
884	    to /xml-rpc with (1) an empty Authorization header line, which
885	    triggers a crash in the ws_decodepassword function; or (2) a
886	    header line without a ':' character, which triggers a crash
887	    in the ws_getheaders function.</p>
888	</blockquote>
889      </body>
890    </description>
891    <references>
892      <cvename>CVE-2007-5824</cvename>
893    </references>
894    <dates>
895      <discovery>2007-11-05</discovery>
896      <entry>2007-11-12</entry>
897    </dates>
898  </vuln>
899
900  <vuln vid="92f86b93-923f-11dc-a2bf-02e081235dab">
901    <topic>net-snmp -- denial of service via GETBULK request</topic>
902    <affects>
903      <package>
904	<name>net-snmp</name>
905	<range><lt>5.3.1_7</lt></range>
906      </package>
907    </affects>
908    <description>
909      <body xmlns="http://www.w3.org/1999/xhtml">
910	<p>CVE reports:</p>
911	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846">
912	  <p>The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1
913	    allows remote attackers to cause a denial of service (CPU
914	    and memory consumption) via a GETBULK request with a large
915	    max-repeaters value.</p>
916	</blockquote>
917      </body>
918    </description>
919    <references>
920      <cvename>CVE-2007-5846</cvename>
921    </references>
922    <dates>
923      <discovery>2007-11-06</discovery>
924      <entry>2007-11-13</entry>
925      <modified>2007-11-14</modified>
926    </dates>
927  </vuln>
928
929  <vuln vid="ff65eecb-91e4-11dc-bd6c-0016179b2dd5">
930    <topic>flac -- media file processing integer overflow vulnerabilities</topic>
931    <affects>
932      <package>
933	<name>flac</name>
934	<range><lt>1.1.2_2</lt></range>
935      </package>
936    </affects>
937    <description>
938      <body xmlns="http://www.w3.org/1999/xhtml">
939	<p>iDefense Laps reports:</p>
940	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608">
941	  <p>Remote exploitation of multiple integer overflow vulnerabilities
942	    in libFLAC, as included with various vendor's software
943	    distributions, allows attackers to execute arbitrary code
944	    in the context of the currently logged in user.</p>
945	  <p>These vulnerabilities specifically exist in the handling of
946	    malformed FLAC media files. In each case, an integer overflow can
947	    occur while calculating the amount of memory to allocate. As such,
948	    insufficient memory is allocated for the data that is subsequently
949	    read in from the file, and a heap based buffer overflow occurs.</p>
950	</blockquote>
951      </body>
952    </description>
953    <references>
954      <cvename>CVE-2007-4619</cvename>
955      <url>http://secunia.com/advisories/27210/</url>
956      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608</url>
957    </references>
958    <dates>
959      <discovery>2007-10-11</discovery>
960      <entry>2007-11-13</entry>
961    </dates>
962  </vuln>
963
964  <vuln vid="2747fc39-915b-11dc-9239-001c2514716c">
965    <topic>xpdf -- multiple remote Stream.CC vulnerabilities</topic>
966    <affects>
967      <package>
968	<name>cups-base</name>
969	<range><lt>1.3.3_2</lt></range>
970      </package>
971      <package>
972	<name>gpdf</name>
973	<range><gt>0</gt></range>
974      </package>
975      <package>
976	<name>kdegraphics</name>
977	<range><lt>3.5.8_1</lt></range>
978      </package>
979      <package>
980	<name>koffice</name>
981	<range><lt>1.6.3_3,2</lt></range>
982      </package>
983      <package>
984	<name>poppler</name>
985	<range><lt>0.6</lt></range>
986      </package>
987      <package>
988	<name>xpdf</name>
989	<range><lt>3.02_5</lt></range>
990      </package>
991    </affects>
992    <description>
993      <body xmlns="http://www.w3.org/1999/xhtml">
994	<p>Secunia Research reports:</p>
995	<blockquote cite="http://www.securityfocus.com/archive/1/483372">
996	  <p>Secunia Research has discovered some vulnerabilities in Xpdf,
997	    which can be exploited by malicious people to compromise a user's
998	    system.</p>
999	  <ul>
1000	    <li>An array indexing error within the
1001	      "DCTStream::readProgressiveDataUnit()" method in xpdf/Stream.cc
1002	      can be exploited to corrupt memory via a specially crafted PDF
1003	      file.</li>
1004	    <li>An integer overflow error within the "DCTStream::reset()"
1005	      method in xpdf/Stream.cc can be exploited to cause a heap-based
1006	      buffer overflow via a specially crafted PDF file.</li>
1007	    <li>A boundary error within the "CCITTFaxStream::lookChar()" method
1008	      in xpdf/Stream.cc can be exploited to cause a heap-based buffer
1009	      overflow by tricking a user into opening a PDF file containing a
1010	      specially crafted "CCITTFaxDecode" filter.</li>
1011	  </ul>
1012	  <p>Successful exploitation may allow execution of arbitrary code.</p>
1013	</blockquote>
1014      </body>
1015    </description>
1016    <references>
1017      <bid>26367</bid>
1018      <cvename>CVE-2007-4352</cvename>
1019      <cvename>CVE-2007-5392</cvename>
1020      <cvename>CVE-2007-5393</cvename>
1021    </references>
1022    <dates>
1023      <discovery>2007-11-07</discovery>
1024      <entry>2007-11-12</entry>
1025      <modified>2007-11-14</modified>
1026    </dates>
1027  </vuln>
1028
1029  <vuln vid="ffba6ab0-90b5-11dc-9835-003048705d5a">
1030    <topic>plone -- unsafe data interpreted as pickles</topic>
1031    <affects>
1032      <package>
1033	<name>plone</name>
1034	<range><ge>2.5</ge><lt>2.5.5</lt></range>
1035	<range><ge>3.0</ge><lt>3.0.3</lt></range>
1036      </package>
1037    </affects>
1038    <description>
1039      <body xmlns="http://www.w3.org/1999/xhtml">
1040	<p>Plone projectreports:</p>
1041	<blockquote cite="http://plone.org/about/security/advisories/cve-2007-5741">
1042	  <p>This hotfix corrects a vulnerability in the statusmessages
1043	    and linkintegrity modules, where unsafe network data was
1044	    interpreted as python pickles. This allows an attacker to
1045	    run arbitrary python code within the Zope/Plone process.</p>
1046	</blockquote>
1047      </body>
1048    </description>
1049    <references>
1050      <bid>26354</bid>
1051      <cvename>CVE-2007-5741</cvename>
1052    </references>
1053    <dates>
1054      <discovery>2007-11-06</discovery>
1055      <entry>2007-11-12</entry>
1056    </dates>
1057  </vuln>
1058
1059  <vuln vid="2d2dcbb4-906c-11dc-a951-0016179b2dd5">
1060    <topic>phpmyadmin -- cross-site scripting vulnerability</topic>
1061    <affects>
1062      <package>
1063	<name>phpMyAdmin</name>
1064	<range><lt>2.11.2.1</lt></range>
1065      </package>
1066    </affects>
1067    <description>
1068      <body xmlns="http://www.w3.org/1999/xhtml">
1069	<p>The DigiTrust Group reports:</p>
1070	<blockquote cite="http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html">
1071	  <p>When creating a new database, a malicious user can use a
1072	    client-side Web proxy to place malicious code in the db parameter of
1073	    the POST request. Since db_create.php does not properly sanitize
1074	    user-supplied input, an administrator could face a persistent XSS
1075	    attack when the database names are displayed.</p>
1076	</blockquote>
1077      </body>
1078    </description>
1079    <references>
1080      <cvename>CVE-2007-5976</cvename>
1081      <cvename>CVE-2007-5977</cvename>
1082      <url>http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html</url>
1083      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-7</url>
1084    </references>
1085    <dates>
1086      <discovery>2007-11-11</discovery>
1087      <entry>2007-11-11</entry>
1088      <modified>2010-05-12</modified>
1089    </dates>
1090  </vuln>
1091
1092  <vuln vid="9b718b82-8ef5-11dc-8e42-001c2514716c">
1093    <topic>gallery2 -- multiple vulnerabilities</topic>
1094    <affects>
1095      <package>
1096	<name>gallery2</name>
1097	<range><lt>2.2.3</lt></range>
1098      </package>
1099    </affects>
1100    <description>
1101      <body xmlns="http://www.w3.org/1999/xhtml">
1102	<p>Gallery project reports:</p>
1103	<blockquote cite="http://gallery.menalto.com/gallery_2.2.3_released">
1104	  <p>Gallery 2.2.3 addresses the following security vulnerabilities:</p>
1105	  <ul>
1106	    <li>Unauthorized renaming of items possible with WebDAV (reported
1107	      by Merrick Manalastas)</li>
1108	    <li>Unauthorized modification and retrieval of item properties
1109	      possible with WebDAV</li>
1110	    <li>Unauthorized locking and replacing of items possible with
1111	      WebDAV</li>
1112	    <li>Unauthorized editing of data file possible via linked items with
1113	      Reupload and WebDAV (reported by Nicklous Roberts)</li>
1114	  </ul>
1115	</blockquote>
1116      </body>
1117    </description>
1118    <references>
1119      <cvename>CVE-2007-4650</cvename>
1120      <bid>25580</bid>
1121    </references>
1122    <dates>
1123      <discovery>2007-08-29</discovery>
1124      <entry>2007-11-09</entry>
1125    </dates>
1126  </vuln>
1127
1128  <vuln vid="20a4eb11-8ea3-11dc-a396-0016179b2dd5">
1129    <topic>tikiwiki -- multiple vulnerabilities</topic>
1130    <affects>
1131      <package>
1132	<name>tikiwik</name>
1133	<range><lt>1.9.8.2</lt></range>
1134      </package>
1135    </affects>
1136    <description>
1137      <body xmlns="http://www.w3.org/1999/xhtml">
1138	<p>Secunia reports:</p>
1139	<blockquote cite="http://secunia.com/advisories/26618/">
1140	  <p>Some vulnerabilities have been reported in TikiWiki, which
1141	    can be exploited by malicious people to conduct cross-site
1142	    scripting and script insertion attacks and disclose potentially
1143	    sensitive information.</p>
1144	  <p>Input passed to the username parameter in tiki-remind_password.php
1145	    (when remind is set to send me my password) is not properly
1146	    sanitised before being returned to the user. This can be exploited
1147	    to execute arbitrary HTML and script code (for example with meta
1148	    refreshes to a javascript: URL) in a user's browser session in
1149	    context of an affected site.</p>
1150	  <p>Input passed to the local_php and error_handler parameters in
1151	    tiki-index.php is not properly verified before being used to include
1152	    files. This can be exploited to include arbitrary files from local
1153	    resources.</p>
1154	  <p>Input passed to the imp_language parameter in
1155	    tiki-imexport_languages.php is not properly verified before being
1156	    used to include files.  This can be exploited to include arbitrary
1157	    files from local resources.</p>
1158	  <p>Certain img src elements are not properly santised before being
1159	    used.  This can be exploited to insert arbitrary HTML and script
1160	    code, which is executed in a user's browser session in context of an
1161	    affected site when the malicious data is viewed.</p>
1162	</blockquote>
1163      </body>
1164    </description>
1165    <references>
1166      <cvename>CVE-2007-4554</cvename>
1167      <cvename>CVE-2007-5683</cvename>
1168      <cvename>CVE-2007-5684</cvename>
1169      <url>http://secunia.com/advisories/26618/</url>
1170      <url>http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/changelog.txt?view=markup&amp;pathrev=REL-1-9-8-2</url>
1171    </references>
1172    <dates>
1173      <discovery>2007-08-27</discovery>
1174      <entry>2007-11-09</entry>
1175      <modified>2008-10-03</modified>
1176    </dates>
1177  </vuln>
1178
1179  <vuln vid="8dd9722c-8e97-11dc-b8f6-001c2514716c">
1180    <topic>cups -- off-by-one buffer overflow</topic>
1181    <affects>
1182      <package>
1183	<name>cups-base</name>
1184	<range><lt>1.3.3_1</lt></range>
1185      </package>
1186    </affects>
1187    <description>
1188      <body xmlns="http://www.w3.org/1999/xhtml">
1189	<p>Secunia reports:</p>
1190	<blockquote cite="http://secunia.com/advisories/27233">
1191	  <p>Secunia Research has discovered a vulnerability in CUPS, which can
1192	    be exploited by malicious people to compromise a vulnerable
1193	    system.</p>
1194	  <p>The vulnerability is caused due to a boundary error within the
1195	    "ippReadIO()" function in cups/ipp.c when processing IPP (Internet
1196	    Printing Protocol) tags.  This can be exploited to overwrite one
1197	    byte on the stack with a zero by sending an IPP request containing
1198	    specially crafted "textWithLanguage" or "nameWithLanguage" tags.</p>
1199	  <p>Successful exploitation allows execution of arbitrary code.</p>
1200	</blockquote>
1201      </body>
1202    </description>
1203    <references>
1204      <cvename>CVE-2007-4351</cvename>
1205      <url>http://secunia.com/secunia_research/2007-76/</url>
1206    </references>
1207    <dates>
1208      <discovery>2007-11-06</discovery>
1209      <entry>2007-11-09</entry>
1210      <modified>2007-11-12</modified>
1211    </dates>
1212  </vuln>
1213
1214  <vuln vid="5b47c279-8cb5-11dc-8878-0016179b2dd5">
1215    <topic>perl -- regular expressions unicode data buffer overflow</topic>
1216    <affects>
1217      <package>
1218	<name>perl</name>
1219	<name>perl-threaded</name>
1220	<range><gt>5.8.*</gt><lt>5.8.8_1</lt></range>
1221      </package>
1222    </affects>
1223    <description>
1224      <body xmlns="http://www.w3.org/1999/xhtml">
1225	<p>Red Hat reports:</p>
1226	<blockquote cite="https://rhn.redhat.com/errata/RHSA-2007-0966.html">
1227	  <p>A flaw was found in Perl's regular expression engine. Specially
1228	    crafted input to a regular expression can cause Perl to improperly
1229	    allocate memory, possibly resulting in arbitrary code running with
1230	    the permissions of the user running Perl.</p>
1231	</blockquote>
1232      </body>
1233    </description>
1234    <references>
1235      <cvename>CVE-2007-5116</cvename>
1236      <url>http://secunia.com/advisories/27546/</url>
1237    </references>
1238    <dates>
1239      <discovery>2007-11-05</discovery>
1240      <entry>2007-11-06</entry>
1241      <modified>2007-11-07</modified>
1242    </dates>
1243  </vuln>
1244
1245  <vuln vid="bfd6eef4-8c94-11dc-8c55-001c2514716c">
1246    <topic>pcre -- arbitrary code execution</topic>
1247    <affects>
1248      <package>
1249	<name>pcre</name>
1250	<name>pcre-utf8</name>
1251	<range><lt>7.3</lt></range>
1252      </package>
1253    </affects>
1254    <description>
1255      <body xmlns="http://www.w3.org/1999/xhtml">
1256	<p>Debian project reports:</p>
1257	<blockquote cite="http://www.debian.org/security/2007/dsa-1399">
1258	  <p>Tavis Ormandy of the Google Security Team has discovered
1259	    several security issues in PCRE, the Perl-Compatible Regular
1260	    Expression library, which potentially allow attackers to
1261	    execute arbitrary code by compiling specially crafted regular
1262	    expressions.</p>
1263	</blockquote>
1264      </body>
1265    </description>
1266    <references>
1267      <cvename>CVE-2007-1659</cvename>
1268      <cvename>CVE-2007-1660</cvename>
1269      <cvename>CVE-2007-1661</cvename>
1270      <cvename>CVE-2007-1662</cvename>
1271      <cvename>CVE-2007-4766</cvename>
1272      <cvename>CVE-2007-4767</cvename>
1273      <cvename>CVE-2007-4768</cvename>
1274      <url>http://www.pcre.org/changelog.txt</url>
1275    </references>
1276    <dates>
1277      <discovery>2007-11-05</discovery>
1278      <entry>2007-11-06</entry>
1279    </dates>
1280  </vuln>
1281
1282  <vuln vid="617a4021-8bf0-11dc-bffa-0016179b2dd5">
1283    <topic>perdition -- str_vwrite format string vulnerability</topic>
1284    <affects>
1285      <package>
1286	<name>perdition</name>
1287	<range><lt>1.17.1</lt></range>
1288      </package>
1289    </affects>
1290    <description>
1291      <body xmlns="http://www.w3.org/1999/xhtml">
1292	<p>SEC-Consult reports:</p>
1293	<blockquote cite="http://www.sec-consult.com/300.html">
1294	  <p>Perdition IMAP is affected by a format string bug in one of its
1295	    IMAP output-string formatting functions. The bug allows the
1296	    execution of arbitrary code on the affected server.
1297	    A successful exploit does not require prior authentication.</p>
1298	</blockquote>
1299      </body>
1300    </description>
1301    <references>
1302      <bid>26270</bid>
1303      <cvename>CVE-2007-5740</cvename>
1304      <url>http://www.sec-consult.com/300.html</url>
1305      <url>http://secunia.com/advisories/27458</url>
1306    </references>
1307    <dates>
1308      <discovery>2007-10-31</discovery>
1309      <entry>2007-11-05</entry>
1310    </dates>
1311  </vuln>
1312
1313  <vuln vid="f8b0f83c-8bb3-11dc-bffa-0016179b2dd5">
1314    <topic>gftp -- multiple vulnerabilities</topic>
1315    <affects>
1316      <package>
1317	<name>gftp</name>
1318	<range><lt>2.0.18_6</lt></range>
1319      </package>
1320    </affects>
1321    <description>
1322      <body xmlns="http://www.w3.org/1999/xhtml">
1323	<p>Gentoo reports:</p>
1324	<blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml">
1325	  <p>Kalle Olavi Niemitalo discovered two boundary errors in fsplib code
1326	    included in gFTP when processing overly long directory or file
1327	    names.</p>
1328	  <p>A remote attacker could trigger these vulnerabilities by enticing
1329	    a user to download a file with a specially crafted directory or file
1330	    name, possibly resulting in the execution of arbitrary code or a
1331	    Denial of Service.</p>
1332	</blockquote>
1333      </body>
1334    </description>
1335    <references>
1336     <cvename>CVE-2007-3961</cvename>
1337     <cvename>CVE-2007-3962</cvename>
1338     <url>http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml</url>
1339    </references>
1340    <dates>
1341      <discovery>2007-11-01</discovery>
1342      <entry>2007-11-05</entry>
1343      <modified>2007-11-11</modified>
1344    </dates>
1345  </vuln>
1346
1347  <vuln vid="a1ef3fc0-8ad0-11dc-9490-0016179b2dd5">
1348    <topic>dircproxy -- remote denial of service</topic>
1349    <affects>
1350      <package>
1351	<name>dircproxy</name>
1352	<range><lt>1.0.5_1</lt></range>
1353      </package>
1354      <package>
1355	<name>dircproxy-devel</name>
1356	<range><lt>1.2.0.b2_1</lt></range>
1357      </package>
1358    </affects>
1359    <description>
1360      <body xmlns="http://www.w3.org/1999/xhtml">
1361	<p>Securiweb reports:</p>
1362	<blockquote cite="http://dircproxy.securiweb.net/ticket/89">
1363	  <p>dircproxy allows remote attackers to cause a denial of
1364	    service (segmentation fault) via an ACTION command without a
1365	    parameter, which triggers a NULL pointer dereference, as
1366	    demonstrated using a blank /me message from irssi.</p>
1367	</blockquote>
1368      </body>
1369    </description>
1370    <references>
1371      <cvename>CVE-2007-5226</cvename>
1372      <url>http://dircproxy.securiweb.net/ticket/89</url>
1373      <url>https://bugzilla.redhat.com/show_bug.cgi?id=319301</url>
1374    </references>
1375    <dates>
1376      <discovery>2006-09-06</discovery>
1377      <entry>2007-11-04</entry>
1378       <modified>2008-01-31</modified>
1379    </dates>
1380  </vuln>
1381
1382  <vuln vid="a467d0f9-8875-11dc-b3ba-0016179b2dd5">
1383    <topic>wordpress -- cross-site scripting</topic>
1384    <affects>
1385      <package>
1386	<name>wordpress</name>
1387	<name>de-wordpress</name>
1388	<range><lt>2.3.1</lt></range>
1389      </package>
1390      <package>
1391	<name>zh-wordpress</name>
1392	<range><gt>0</gt></range>
1393      </package>
1394    </affects>
1395    <description>
1396      <body xmlns="http://www.w3.org/1999/xhtml">
1397	<p>A Secunia Advisory report:</p>
1398	<blockquote cite="http://secunia.com/advisories/27407">
1399	  <p>Input passed to the "posts_columns" parameter in
1400	    wp-admin/edit-post-rows.php is not properly sanitised before
1401	    being returned to the user. This can be exploited to execute
1402	    arbitrary HTML and script code in a user's browser session in
1403	    context of an affected site.</p>
1404	</blockquote>
1405      </body>
1406    </description>
1407    <references>
1408      <cvename>CVE-2007-5710</cvename>
1409      <url>http://secunia.com/advisories/27407</url>
1410      <url>http://wordpress.org/development/2007/10/wordpress-231/</url>
1411    </references>
1412    <dates>
1413      <discovery>2007-10-29</discovery>
1414      <entry>2007-11-01</entry>
1415    </dates>
1416  </vuln>
1417
1418  <vuln vid="db449245-870d-11dc-a3ec-001921ab2fa4">
1419    <topic>openldap -- multiple remote denial of service vulnerabilities</topic>
1420    <affects>
1421      <package>
1422	<name>openldap-server</name>
1423	<range><lt>2.3.39</lt></range>
1424	<range><gt>2.4.0</gt><lt>2.4.6</lt></range>
1425      </package>
1426    </affects>
1427    <description>
1428      <body xmlns="http://www.w3.org/1999/xhtml">
1429	<p>BugTraq reports:</p>
1430	<blockquote cite="http://www.securityfocus.com/bid/26245/">
1431	  <p>OpenLDAP is prone to multiple remote denial-of-service
1432	    vulnerabilities because of an incorrect NULL-termination
1433	    issue and a double-free issue.</p>
1434	</blockquote>
1435      </body>
1436    </description>
1437    <references>
1438      <bid>26245</bid>
1439      <cvename>CVE-2007-5707</cvename>
1440      <cvename>CVE-2007-5708</cvename>
1441    </references>
1442    <dates>
1443      <discovery>2007-10-29</discovery>
1444      <entry>2007-10-30</entry>
1445      <modified>2007-10-31</modified>
1446    </dates>
1447  </vuln>
1448
1449  <vuln vid="d2c2952d-85a1-11dc-bfff-003048705d5a">
1450    <topic>py-django -- denial of service vulnerability</topic>
1451    <affects>
1452      <package>
1453	<name>py23-django</name>
1454	<name>py24-django</name>
1455	<name>py25-django</name>
1456	<range><lt>0.96.1</lt></range>
1457      </package>
1458      <package>
1459	<name>py23-django-devel</name>
1460	<name>py24-django-devel</name>
1461	<name>py25-django-devel</name>
1462	<range><lt>20071026</lt></range>
1463      </package>
1464    </affects>
1465    <description>
1466      <body xmlns="http://www.w3.org/1999/xhtml">
1467	<p>Django project reports:</p>
1468	<blockquote cite="http://www.djangoproject.com/weblog/2007/oct/26/security-fix/">
1469	  <p>A per-process cache used by Django's internationalization
1470	    ("i18n") system to store the results of translation lookups
1471	    for particular values of the HTTP Accept-Language header
1472	    used the full value of that header as a key. An attacker
1473	    could take advantage of this by sending repeated requests
1474	    with extremely large strings in the Accept-Language header,
1475	    potentially causing a denial of service by filling available
1476	    memory.</p>
1477	  <p>Due to limitations imposed by Web server software on the
1478	    size of HTTP header fields, combined with reasonable limits
1479	    on the number of requests which may be handled by a single
1480	    server process over its lifetime, this vulnerability may be
1481	    difficult to exploit. Additionally, it is only present when
1482	    the "USE_I18N" setting in Django is "True" and the i18n
1483	    middleware component is enabled*. Nonetheless, all users of
1484	    affected versions of Django are encouraged to update.</p>
1485	</blockquote>
1486      </body>
1487    </description>
1488    <references>
1489      <url>http://www.djangoproject.com/weblog/2007/oct/26/security-fix/</url>
1490    </references>
1491    <dates>
1492      <discovery>2007-10-26</discovery>
1493      <entry>2007-10-27</entry>
1494    </dates>
1495  </vuln>
1496
1497  <vuln vid="44224e08-8306-11dc-9283-0016179b2dd5">
1498    <topic>opera -- multiple vulnerabilities</topic>
1499    <affects>
1500      <package>
1501	<name>opera</name>
1502	<name>opera-devel</name>
1503	<name>linux-opera</name>
1504	<range><lt>9.24</lt></range>
1505      </package>
1506    </affects>
1507    <description>
1508      <body xmlns="http://www.w3.org/1999/xhtml">
1509	<p>An advisory from Opera reports:</p>
1510	<blockquote cite="http://www.opera.com/support/search/view/866/">
1511	  <p>If a user has configured Opera to use an external newsgroup
1512	    client or e-mail application, specially crafted Web pages can
1513	    cause Opera to run that application incorrectly. In some cases
1514	    this can lead to execution of arbitrary code.</p>
1515	</blockquote>
1516	<blockquote cite="http://www.opera.com/support/search/view/867/">
1517	  <p>When accesing frames from different Web sites, specially crafted
1518	    scripts can bypass the same-origin policy, and overwrite functions
1519	    from those frames. If scripts on the page then run those functions,
1520	    this can cause the script of the attacker's choice to run in the
1521	    context of the target Web site.</p>
1522	</blockquote>
1523      </body>
1524    </description>
1525    <references>
1526      <cvename>CVE-2007-5540</cvename>
1527      <cvename>CVE-2007-5541</cvename>
1528      <url>http://www.opera.com/support/search/view/866/</url>
1529      <url>http://www.opera.com/support/search/view/867/</url>
1530      <url>http://secunia.com/advisories/27277/</url>
1531    </references>
1532    <dates>
1533      <discovery>2007-10-17</discovery>
1534      <entry>2007-10-25</entry>
1535    </dates>
1536  </vuln>
1537
1538  <vuln vid="9c00d446-8208-11dc-9283-0016179b2dd5">
1539    <topic>drupal --- multiple vulnerabilities</topic>
1540    <affects>
1541      <package>
1542	<name>drupal4</name>
1543	<range><lt>4.7.8</lt></range>
1544      </package>
1545      <package>
1546	<name>drupal5</name>
1547	<range><lt>5.3</lt></range>
1548      </package>
1549    </affects>
1550    <description>
1551      <body xmlns="http://www.w3.org/1999/xhtml">
1552	<p>The Drupal Project reports:</p>
1553	<blockquote cite="http://drupal.org/node/184315">
1554	  <p>In some circumstances Drupal allows user-supplied data to
1555	    become part of response headers. As this user-supplied data
1556	    is not always properly escaped, this can be exploited by
1557	    malicious users to execute HTTP response splitting attacks
1558	    which may lead to a variety of issues, among them cache
1559	    poisoning, cross-user defacement and injection of arbitrary
1560	    code.</p>
1561	</blockquote>
1562	<blockquote cite="http://drupal.org/node/184316">
1563	  <p>The Drupal installer allows any visitor to provide credentials
1564	    for a database when the site's own database is not reachable. This
1565	    allows attackers to run arbitrary code on the site's server.
1566	    An immediate workaround is the removal of the file install.php
1567	    in the Drupal root directory.</p>
1568	</blockquote>
1569	<blockquote cite="http://drupal.org/node/184320">
1570	  <p>The allowed extension list of the core Upload module contains
1571	    the extension HTML by default. Such files can be used to execute
1572	    arbitrary script code in the context of the affected site when a
1573	    user views the file. Revoking upload permissions or removing the
1574	    .html extension from the allowed extension list will stop uploads
1575	    of malicious files. but will do nothing to protect your site
1576	    againstfiles that are already present. Carefully inspect the file
1577	    system path for any HTML files. We recommend you remove any HTML
1578	    file you did not update yourself. You should look for , CSS
1579	    includes, Javascript includes, and onerror="" attributes if
1580	    you need to review files individually.</p>
1581	</blockquote>
1582	<blockquote cite="http://drupal.org/node/184348">
1583	  <p>The Drupal Forms API protects against cross site request
1584	    forgeries (CSRF), where a malicious site can cause a user
1585	    to unintentionally submit a form to a site where he is
1586	    authenticated. The user deletion form does not follow the
1587	    standard Forms API submission model and is therefore not
1588	    protected against this type of attack. A CSRF attack may
1589	    result in the deletion of users.</p>
1590	</blockquote>
1591	<blockquote cite="http://drupal.org/node/184354">
1592	  <p>The publication status of comments is not passed during the
1593	    hook_comments API operation, causing various modules that rely
1594	    on the publication status (such as Organic groups, or Subscriptions)
1595	    to mail out unpublished comments.</p>
1596	</blockquote>
1597      </body>
1598    </description>
1599    <references>
1600      <cvename>CVE-2007-5597</cvename>
1601      <cvename>CVE-2007-5596</cvename>
1602      <cvename>CVE-2007-5595</cvename>
1603      <cvename>CVE-2007-5594</cvename>
1604      <cvename>CVE-2007-5593</cvename>
1605      <url>http://drupal.org/node/184315</url>
1606      <url>http://drupal.org/node/184316</url>
1607      <url>http://drupal.org/node/184348</url>
1608      <url>http://drupal.org/node/184354</url>
1609      <url>http://drupal.org/node/184320</url>
1610      <url>http://secunia.com/advisories/27292</url>
1611      <url>http://secunia.com/advisories/27292</url>
1612      <url>http://secunia.com/advisories/27292</url>
1613      <url>http://secunia.com/advisories/27290</url>
1614      <url>http://secunia.com/advisories/27290</url>
1615    </references>
1616    <dates>
1617      <discovery>2007-10-17</discovery>
1618      <entry>2007-10-24</entry>
1619    </dates>
1620  </vuln>
1621
1622  <vuln vid="3a81017a-8154-11dc-9283-0016179b2dd5">
1623    <topic>ldapscripts -- Command Line User Credentials Disclosure</topic>
1624    <affects>
1625      <package>
1626	<name>ldapscripts</name>
1627	<range><lt>1.7.1</lt></range>
1628      </package>
1629    </affects>
1630    <description>
1631      <body xmlns="http://www.w3.org/1999/xhtml">
1632	<p>Ganael Laplanche reports:</p>
1633	<blockquote cite="http://sourceforge.net/project/shownotes.php?group_id=156483&amp;release_id=546600">
1634	  <p>Up to now, each ldap* command was called with the -w parameter,
1635	    which allows to specify the bind password on the command line.
1636	    Unfortunately, this could make the password appear to anybody
1637	    performing a `ps` during the call. This is now avoided by using
1638	    the -y parameter and a password file.</p>
1639	</blockquote>
1640      </body>
1641    </description>
1642    <references>
1643      <url>http://sourceforge.net/project/shownotes.php?group_id=156483&amp;release_id=546600</url>
1644      <url>http://secunia.com/advisories/27111</url>
1645      <cvename>CVE-2007-5373</cvename>
1646    </references>
1647    <dates>
1648      <discovery>2007-10-09</discovery>
1649      <entry>2007-10-23</entry>
1650    </dates>
1651  </vuln>
1652
1653  <vuln vid="e24797af-803d-11dc-b787-003048705d5a">
1654    <topic>firefox -- OnUnload Javascript browser entrapment vulnerability</topic>
1655    <affects>
1656      <package>
1657	<name>firefox</name>
1658	<range><lt>2.0.0.8,1</lt></range>
1659      </package>
1660      <package>
1661	<name>linux-firefox</name>
1662	<range><lt>2.0.0.8</lt></range>
1663      </package>
1664      <package>
1665	<name>seamonkey</name>
1666	<name>linux-seamonkey</name>
1667	<range><lt>1.1.5</lt></range>
1668      </package>
1669    </affects>
1670    <description>
1671      <body xmlns="http://www.w3.org/1999/xhtml">
1672	<p>RedHat reports:</p>
1673	<blockquote cite="https://rhn.redhat.com/errata/RHSA-2007-0979.html">
1674	  <p>Several flaws were found in the way in which Firefox
1675	    displayed malformed web content. A web page containing
1676	    specially-crafted content could potentially trick a user
1677	    into surrendering sensitive information.  (CVE-2007-1095,
1678	    CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)</p>
1679	</blockquote>
1680      </body>
1681    </description>
1682    <references>
1683      <cvename>CVE-2007-1095</cvename>
1684    </references>
1685    <dates>
1686      <discovery>2007-10-19</discovery>
1687      <entry>2007-10-22</entry>
1688      <modified>2007-10-23</modified>
1689    </dates>
1690  </vuln>
1691
1692  <vuln vid="498a8731-7cfc-11dc-96e6-0012f06707f0">
1693    <topic>phpmyadmin -- cross-site scripting vulnerability</topic>
1694    <affects>
1695      <package>
1696	<name>phpMyAdmin</name>
1697	<range><lt>2.11.1.2</lt></range>
1698      </package>
1699    </affects>
1700    <description>
1701      <body xmlns="http://www.w3.org/1999/xhtml">
1702	<p>The DigiTrust Group discovered serious XSS vulnerability in
1703	  the phpMyAdmin server_status.php script. According to their
1704	  report</p>
1705	<blockquote cite="http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html">
1706	  <p>vulnerability can be exploited to execute arbitrary HTML and
1707	    script code in a user's browser session in context of an affected
1708	    site.</p>
1709	</blockquote>
1710      </body>
1711    </description>
1712    <references>
1713      <cvename>CVE-2007-5589</cvename>
1714      <url>http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html</url>
1715      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-6</url>
1716    </references>
1717    <dates>
1718      <discovery>2007-10-17</discovery>
1719      <entry>2007-10-17</entry>
1720      <modified>2010-05-12</modified>
1721    </dates>
1722  </vuln>
1723
1724  <vuln vid="51b51d4a-7c0f-11dc-9e47-0011d861d5e2">
1725    <topic>phpmyadmin -- cross-site scripting vulnerability</topic>
1726    <affects>
1727      <package>
1728	<name>phpMyAdmin</name>
1729	<range><lt>2.11.1.1</lt></range>
1730      </package>
1731    </affects>
1732    <description>
1733      <body xmlns="http://www.w3.org/1999/xhtml">
1734	<p>SecurityFocus reports:</p>
1735	<blockquote cite="http://www.securityfocus.com/bid/26020/discuss">
1736	  <p>phpMyAdmin is prone to a cross-site scripting vulnerability
1737	    because it fails to properly sanitize user-supplied input.</p>
1738	  <p>An attacker may leverage this issue to execute arbitrary script
1739	    code in the browser of an unsuspecting user in the context of the
1740	    affected site. This may help the attacker steal potentially
1741	    sensitive information and launch other attacks.</p>
1742	</blockquote>
1743      </body>
1744    </description>
1745    <references>
1746      <cvename>CVE-2007-5386</cvename>
1747      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-5</url>
1748      <url>http://www.digitrustgroup.com/advisories/TDG-advisory071009a</url>
1749      <url>http://secunia.com/advisories/27173</url>
1750      <bid>26020</bid>
1751    </references>
1752    <dates>
1753      <discovery>2007-10-12</discovery>
1754      <entry>2007-10-16</entry>
1755      <modified>2007-10-20</modified>
1756    </dates>
1757  </vuln>
1758
1759  <vuln vid="7453c85d-7830-11dc-b4c8-0016179b2dd5">
1760    <topic>nagios-plugins -- Long Location Header Buffer Overflow Vulnerability</topic>
1761    <affects>
1762      <package>
1763	<name>nagios-plugins</name>
1764	<range><lt>1.4.10,1</lt></range>
1765      </package>
1766    </affects>
1767    <description>
1768      <body xmlns="http://www.w3.org/1999/xhtml">
1769	<p>A Secunia Advisory reports:</p>
1770	<blockquote cite="http://secunia.com/advisories/27124/">
1771	  <p>The vulnerability is caused due to a boundary error within the
1772	    redir() function in check_http.c when processing HTTP Location:
1773	    header information. This can be exploited to cause a buffer overflow
1774	    by returning an overly long string in the "Location:" header to a
1775	    vulnerable system.</p>
1776	</blockquote>
1777      </body>
1778    </description>
1779    <references>
1780      <url>http://sourceforge.net/forum/forum.php?forum_id=740172</url>
1781      <url>http://secunia.com/advisories/27124/</url>
1782      <cvename>CVE-2007-5198</cvename>
1783    </references>
1784    <dates>
1785      <discovery>2007-09-28</discovery>
1786      <entry>2007-10-11</entry>
1787    </dates>
1788  </vuln>
1789
1790  <vuln vid="172acf78-780c-11dc-b3f4-0016179b2dd5">
1791    <topic>png -- multiple vulnerabilities</topic>
1792    <affects>
1793      <package>
1794	<name>png</name>
1795	<range><lt>1.2.22</lt></range>
1796      </package>
1797    </affects>
1798    <description>
1799      <body xmlns="http://www.w3.org/1999/xhtml">
1800	<p>A Secunia Advisory reports:</p>
1801	<blockquote cite="http://secunia.com/advisories/27093/">
1802	  <p>Some vulnerabilities have been reported in libpng, which can be
1803	    exploited by malicious people to cause a DoS (Denial of
1804	    Service).</p>
1805	  <p>Certain errors within libpng, including a logical NOT instead of a
1806	    bitwise NOT in pngtrtran.c, an error in the 16bit cheap transparency
1807	    extension, and an incorrect use of sizeof() may be exploited to
1808	    crash an application using the library.</p>
1809	  <p>Various out-of-bounds read errors exist within the functions
1810	    png_handle_pCAL(), png_handle_sCAL(), png_push_read_tEXt(),
1811	    png_handle_iTXt(), and png_handle_ztXt(), which may be exploited by
1812	    exploited to crash an application using the library.</p>
1813	</blockquote>
1814	<blockquote cite="http://secunia.com/advisories/27130/">
1815	  <p>The vulnerability is caused due to an off-by-one error within
1816	     the ICC profile chunk handling, which potentially can be
1817	     exploited to crash an application using the library.</p>
1818	</blockquote>
1819      </body>
1820    </description>
1821    <references>
1822      <url>http://secunia.com/advisories/27093/</url>
1823      <url>http://secunia.com/advisories/27130/</url>
1824      <cvename>CVE-2007-5267</cvename>
1825      <cvename>CVE-2007-5266</cvename>
1826      <cvename>CVE-2007-5268</cvename>
1827      <cvename>CVE-2007-5269</cvename>
1828    </references>
1829    <dates>
1830      <discovery>2007-10-08</discovery>
1831      <entry>2007-10-11</entry>
1832    </dates>
1833  </vuln>
1834
1835  <vuln vid="f5b29ec0-71f9-11dc-8c6a-00304881ac9a">
1836    <topic>ImageMagick -- multiple vulnerabilities</topic>
1837    <affects>
1838      <package>
1839	<name>ImageMagick</name>
1840	<name>ImageMagick-nox11</name>
1841	<range><lt>6.3.5.9</lt></range>
1842      </package>
1843    </affects>
1844    <description>
1845      <body xmlns="http://www.w3.org/1999/xhtml">
1846	<p>Multiple vulnerabilities have been discovered in ImageMagick.</p>
1847	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4985">
1848	  <p>ImageMagick before 6.3.5-9 allows context-dependent attackers
1849	    to cause a denial of service via a crafted image file that
1850	    triggers (1) an infinite loop in the ReadDCMImage function,
1851	    related to ReadBlobByte function calls; or (2) an infinite
1852	    loop in the ReadXCFImage function, related to ReadBlobMSBLong
1853	    function calls.</p>
1854	</blockquote>
1855	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4986">
1856	  <p>Multiple integer overflows in ImageMagick before 6.3.5-9
1857	    allow context-dependent attackers to execute arbitrary code
1858	    via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5)
1859	    .xwd image file, which triggers a heap-based buffer overflow.</p>
1860	</blockquote>
1861	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4987">
1862	  <p>Off-by-one error in the ReadBlobString function in blob.c in
1863	    ImageMagick before 6.3.5-9 allows context-dependent attackers
1864	    to execute arbitrary code via a crafted image file, which
1865	    triggers the writing of a '\0' character to an out-of-bounds
1866	    address.</p>
1867	</blockquote>
1868	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4988">
1869	  <p>Sign extension error in the ReadDIBImage function in
1870	    ImageMagick before 6.3.5-9 allows context-dependent attackers
1871	    to execute arbitrary code via a crafted width value in an
1872	    image file, which triggers an integer overflow and a
1873	    heap-based buffer overflow.</p>
1874	</blockquote>
1875      </body>
1876    </description>
1877    <references>
1878      <cvename>CVE-2007-4985</cvename>
1879      <cvename>CVE-2007-4986</cvename>
1880      <cvename>CVE-2007-4987</cvename>
1881      <cvename>CVE-2007-4988</cvename>
1882      <url>http://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.html</url>
1883    </references>
1884    <dates>
1885      <discovery>2007-09-19</discovery>
1886      <entry>2007-10-10</entry>
1887    </dates>
1888  </vuln>
1889
1890  <vuln vid="c93e4d41-75c5-11dc-b903-0016179b2dd5">
1891    <topic>jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented</topic>
1892    <affects>
1893      <package>
1894	<name>jdk</name>
1895	<range><ge>1.3.0</ge><lt>1.6.0.3p3</lt></range>
1896	<range><ge>1.5.0,1</ge><lt>1.5.0.13p7,1</lt></range>
1897      </package>
1898      <package>
1899	<name>linux-blackdown-jdk</name>
1900	<range><ge>1.3.0</ge></range>
1901      </package>
1902      <package>
1903	<name>linux-sun-jdk</name>
1904	<range><ge>1.3.0</ge><lt>1.3.1.20</lt></range>
1905	<range><ge>1.4.0</ge><lt>1.4.2.16</lt></range>
1906	<range><eq>1.5.0.b1</eq></range>
1907	<range><eq>1.5.0.b1,1</eq></range>
1908	<range><ge>1.5.0,2</ge><lt>1.5.0.13,2</lt></range>
1909	<range><ge>1.6.0</ge><lt>1.6.0.03</lt></range>
1910      </package>
1911    </affects>
1912    <description>
1913      <body xmlns="http://www.w3.org/1999/xhtml">
1914	<p>SUN reports:</p>
1915	<blockquote cite="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1">
1916	  <p>A vulnerability in the Java Runtime Environment (JRE) with applet
1917	    caching may allow an untrusted applet that is downloaded from a
1918	    malicious website to make network connections to network services
1919	    on machines other than the one that the applet was downloaded from.
1920	    This may allow network resources (such as web pages) and
1921	    vulnerabilities (that exist on these network services) which are not
1922	    otherwise normally accessible to be accessed or exploited.</p>
1923	</blockquote>
1924      </body>
1925    </description>
1926    <references>
1927      <url>http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1</url>
1928      <cvename>CVE-2007-5232</cvename>
1929    </references>
1930    <dates>
1931      <discovery>2007-10-03</discovery>
1932      <entry>2007-10-08</entry>
1933      <modified>2007-11-16</modified>
1934    </dates>
1935  </vuln>
1936
1937  <vuln vid="a5f667db-7596-11dc-8b7a-0019b944b34e">
1938    <topic>xfs -- multiple vulnerabilities</topic>
1939    <affects>
1940      <package>
1941	<name>xfs</name>
1942	<range><lt>1.0.5,1</lt></range>
1943      </package>
1944    </affects>
1945    <description>
1946      <body xmlns="http://www.w3.org/1999/xhtml">
1947	<p>Matthieu Herrb reports:</p>
1948	<blockquote cite="http://lists.freedesktop.org/archives/xorg/2007-October/028899.html">
1949	  <h1>Problem Description:</h1>
1950	  <p>Several vulnerabilities have been identified in xfs, the X font
1951	    server.  The QueryXBitmaps and QueryXExtents protocol requests
1952	    suffer from lack of validation of their 'length' parameters.</p>
1953	  <h1>Impact:</h1>
1954	  <p>On most modern systems, the font server is accessible only for
1955	    local clients and runs with reduced privileges, but on some
1956	    systems it may still be accessible from remote clients and
1957	    possibly running with root privileges, creating an opportunity
1958	    for remote privilege escalation.</p>
1959	</blockquote>
1960      </body>
1961    </description>
1962    <references>
1963      <cvename>CVE-2007-4568</cvename>
1964      <url>http://lists.freedesktop.org/archives/xorg/2007-October/028899.html</url>
1965    </references>
1966    <dates>
1967      <discovery>2007-10-02</discovery>
1968      <entry>2007-10-08</entry>
1969    </dates>
1970  </vuln>
1971
1972  <vuln vid="a058d6fa-7325-11dc-ae10-0016179b2dd5">
1973    <topic>tcl/tk -- buffer overflow in ReadImage function</topic>
1974    <affects>
1975      <package>
1976	<name>tk</name>
1977	<name>tk-threads</name>
1978	<range><gt>8.2.*</gt><lt>8.2.3_11</lt></range>
1979	<range><gt>8.3.*</gt><lt>8.3.5_10</lt></range>
1980	<range><gt>8.4.*,2</gt><lt>8.4.16,2</lt></range>
1981      </package>
1982    </affects>
1983    <description>
1984      <body xmlns="http://www.w3.org/1999/xhtml">
1985	<p>A Buffer overflow in the ReadImage function in generic/tkImgGIF.c
1986	  in Tcl/Tk, allows remote attackers to execute arbitrary code via
1987	  multi-frame interlaced GIF files in which later frames are smaller
1988	  than the first.</p>
1989      </body>
1990    </description>
1991    <references>
1992      <url>http://secunia.com/advisories/26942</url>
1993      <url>http://sourceforge.net/project/shownotes.php?release_id=541207</url>
1994      <cvename>CVE-2007-5137</cvename>
1995    </references>
1996    <dates>
1997      <discovery>2007-09-27</discovery>
1998      <entry>2007-10-05</entry>
1999      <modified>2011-09-04</modified>
2000    </dates>
2001  </vuln>
2002
2003  <vuln vid="91ed69f9-72c7-11dc-981a-001921ab2fa4">
2004    <topic>firebird -- multiple remote buffer overflow vulnerabilities</topic>
2005    <affects>
2006      <package>
2007	<name>firebird-server</name>
2008	<range><ge>1.*</ge><lt>1.5.5</lt></range>
2009	<range><ge>2.0.*</ge><lt>2.0.3</lt></range>
2010      </package>
2011    </affects>
2012    <description>
2013      <body xmlns="http://www.w3.org/1999/xhtml">
2014	<p>RISE Security reports:</p>
2015	<blockquote cite="http://risesecurity.org/advisory/RISE-2007003/">
2016	  <p>There exists multiple vulnerabilities within functions
2017	    of Firebird Relational Database, which when properly
2018	    exploited can lead to remote compromise of the vulnerable
2019	    system.</p>
2020	</blockquote>
2021      </body>
2022    </description>
2023    <references>
2024      <bid>25925</bid>
2025    </references>
2026    <dates>
2027      <discovery>2007-10-03</discovery>
2028      <entry>2007-10-04</entry>
2029    </dates>
2030  </vuln>
2031
2032  <vuln vid="15ec9123-7061-11dc-b372-001921ab2fa4">
2033    <topic>id3lib -- insecure temporary file creation</topic>
2034    <affects>
2035      <package>
2036	<name>id3lib</name>
2037	<range><lt>3.8.3_4</lt></range>
2038      </package>
2039    </affects>
2040    <description>
2041      <body xmlns="http://www.w3.org/1999/xhtml">
2042	<p>Debian Bug report log reports:</p>
2043	<blockquote cite="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=438540">
2044	  <p>When tagging file $foo, a temporary copy of the file is
2045	    created, and for some reason, libid3 doesn't use mkstemp
2046	    but just creates $foo.XXXXXX literally, without any checking.</p>
2047	  <p>This would silently truncate and overwrite an existing
2048	    $foo.XXXXXX.</p>
2049	</blockquote>
2050      </body>
2051    </description>
2052    <references>
2053      <bid>25372</bid>
2054      <cvename>CVE-2007-4460</cvename>
2055    </references>
2056    <dates>
2057      <discovery>2007-08-20</discovery>
2058      <entry>2007-10-01</entry>
2059      <modified>2007-10-01</modified>
2060    </dates>
2061  </vuln>
2062
2063  <vuln vid="c9c14242-6843-11dc-82b6-02e0185f8d72">
2064    <topic>mediawiki -- cross site scripting vulnerability</topic>
2065    <affects>
2066      <package>
2067	<name>mediawiki</name>
2068	<range><gt>1.10.0</gt><lt>1.10.2</lt></range>
2069	<range><gt>1.9.0</gt><lt>1.9.4</lt></range>
2070	<range><gt>1.8.0</gt><lt>1.8.5</lt></range>
2071      </package>
2072    </affects>
2073    <description>
2074      <body xmlns="http://www.w3.org/1999/xhtml">
2075	<p>The MediaWiki development team reports:</p>
2076	<blockquote cite="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html">
2077	  <p>A possible HTML/XSS injection vector in the API
2078	    pretty-printing mode has been found and fixed.</p>
2079	  <p>The vulnerability may be worked around in an unfixed version
2080	    by simply disabling the API interface if it is not in use, by
2081	    adding this to LocalSettings.php:</p>
2082	  <p>$wgEnableAPI = false;</p>
2083	  <p>(This is the default setting in 1.8.x.)</p>
2084	</blockquote>
2085      </body>
2086    </description>
2087    <references>
2088      <cvename>CVE-2007-4828</cvename>
2089      <url>http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html</url>
2090    </references>
2091    <dates>
2092      <discovery>2007-09-10</discovery>
2093      <entry>2007-09-21</entry>
2094      <modified>2007-10-10</modified>
2095    </dates>
2096  </vuln>
2097
2098  <vuln vid="63347ee7-6841-11dc-82b6-02e0185f8d72">
2099    <topic>wordpress -- remote sql injection vulnerability</topic>
2100    <affects>
2101      <package>
2102	<name>wordpress</name>
2103	<range><lt>2.2.3,1</lt></range>
2104      </package>
2105      <package>
2106	<name>de-wordpress</name>
2107	<name>zh-wordpress</name>
2108	<range><lt>2.2.3</lt></range>
2109      </package>
2110      <package>
2111	<name>wordpress-mu</name>
2112	<range><lt>1.2.4,2</lt></range>
2113      </package>
2114    </affects>
2115    <description>
2116      <body xmlns="http://www.w3.org/1999/xhtml">
2117	<p>Alexander Concha reports:</p>
2118	<blockquote cite="http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html">
2119	  <p>While testing WordPress, it has been discovered a SQL
2120	    Injection vulnerability that allows an attacker to retrieve
2121	    remotely any user credentials from a vulnerable site, this
2122	    bug is caused because of early database escaping and the
2123	    lack of validation in query string like parameters.</p>
2124	</blockquote>
2125      </body>
2126    </description>
2127    <references>
2128      <cvename>CVE-2007-4894</cvename>
2129      <url>http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html</url>
2130    </references>
2131    <dates>
2132      <discovery>2007-09-10</discovery>
2133      <entry>2007-09-21</entry>
2134    </dates>
2135  </vuln>
2136
2137  <vuln vid="2bc96f18-683f-11dc-82b6-02e0185f8d72">
2138    <topic>samba -- nss_info plugin privilege escalation vulnerability</topic>
2139    <affects>
2140      <package>
2141	<name>samba</name>
2142	<range><lt>3.0.26a</lt></range>
2143	<range><gt>*,1</gt><lt>3.0.26a,1</lt></range>
2144      </package>
2145    </affects>
2146    <description>
2147      <body xmlns="http://www.w3.org/1999/xhtml">
2148	<p>The Samba development team reports:</p>
2149	<blockquote cite="http://www.samba.org/samba/security/CVE-2007-4138.html">
2150	  <p>The idmap_ad.so library provides an nss_info extension to
2151	    Winbind for retrieving a user's home directory path, login
2152	    shell and primary group id from an Active Directory domain
2153	    controller.  This functionality is enabled by defining the
2154	    "winbind nss info" smb.conf option to either "sfu" or
2155	    "rfc2307".</p>
2156	  <p>Both the Windows "Identity Management for Unix" and
2157	    "Services for Unix" MMC plug-ins allow a user to be assigned
2158	    a primary group for Unix clients that differs from the user's
2159	    Windows primary group.  When the rfc2307 or sfu nss_info plugin
2160	    has been enabled, in the absence of either the RFC2307 or SFU
2161	    primary group attribute, Winbind will assign a primary group ID
2162	    of 0 to the domain user queried using the getpwnam() C library
2163	    call.</p>
2164	</blockquote>
2165      </body>
2166    </description>
2167    <references>
2168      <cvename>CVE-2007-4138</cvename>
2169      <url>http://www.samba.org/samba/security/CVE-2007-4138.html</url>
2170    </references>
2171    <dates>
2172      <discovery>2007-09-11</discovery>
2173      <entry>2007-09-21</entry>
2174      <modified>2008-09-26</modified>
2175    </dates>
2176  </vuln>
2177
2178  <vuln vid="75231c63-f6a2-499d-8e27-787773bda284">
2179    <topic>bugzilla -- multiple vulnerabilities</topic>
2180    <affects>
2181      <package>
2182	<name>bugzilla</name>
2183	<name>ja-bugzilla</name>
2184	<range><ge>2.20.*</ge><lt>2.22.3</lt></range>
2185	<range><ge>3.*</ge><lt>3.0.1</lt></range>
2186      </package>
2187    </affects>
2188    <description>
2189      <body xmlns="http://www.w3.org/1999/xhtml">
2190	<p>A Bugzilla Security Advisory reports:</p>
2191	<blockquote cite="http://www.bugzilla.org/security/2.20.4/">
2192	  <p>This advisory covers three security issues that have recently been
2193	    fixed in the Bugzilla code:</p>
2194	  <ul>
2195	    <li>A possible cross-site scripting (XSS) vulnerability when filing
2196	      bugs using the guided form.</li>
2197	    <li>When using email_in.pl, insufficiently escaped data may be
2198	      passed to sendmail.</li>
2199	    <li>Users using the WebService interface may access Bugzilla's
2200	      time-tracking fields even if they normally cannot see them.</li>
2201	  </ul>
2202	  <p>We strongly advise that 2.20.x and 2.22.x users should upgrade to
2203	    2.20.5 and 2.22.3 respectively. 3.0 users, and users of 2.18.x or
2204	    below, should upgrade to 3.0.1.</p>
2205	</blockquote>
2206      </body>
2207    </description>
2208    <references>
2209      <bid>25425</bid>
2210      <cvename>CVE-2007-4538</cvename>
2211      <cvename>CVE-2007-4539</cvename>
2212      <cvename>CVE-2007-4543</cvename>
2213      <url>http://www.bugzilla.org/security/2.20.4/</url>
2214    </references>
2215    <dates>
2216      <discovery>2007-08-23</discovery>
2217      <entry>2007-09-21</entry>
2218    </dates>
2219  </vuln>
2220
2221  <vuln vid="b6f6da57-680a-11dc-b350-001921ab2fa4">
2222    <topic>clamav -- multiple remote Denial of Service vulnerabilities</topic>
2223    <affects>
2224      <package>
2225	<name>clamav</name>
2226	<range><lt>0.91.2</lt></range>
2227      </package>
2228    </affects>
2229    <description>
2230      <body xmlns="http://www.w3.org/1999/xhtml">
2231	<p>BugTraq reports:</p>
2232	<blockquote cite="http://www.securityfocus.com/bid/25398">
2233	  <p>ClamAV is prone to multiple denial-of-service vulnerabilities.</p>
2234	  <p>A successful attack may allow an attacker to crash the
2235	    application and deny service to users.</p>
2236	</blockquote>
2237      </body>
2238    </description>
2239    <references>
2240      <bid>25398</bid>
2241      <cvename>CVE-2007-4510</cvename>
2242    </references>
2243    <dates>
2244      <discovery>2007-08-21</discovery>
2245      <entry>2007-09-21</entry>
2246    </dates>
2247  </vuln>
2248
2249  <vuln vid="12488805-6773-11dc-8be8-02e0185f8d72">
2250    <topic>coppermine -- multiple vulnerabilities</topic>
2251    <affects>
2252      <package>
2253	<name>coppermine</name>
2254	<range><lt>1.4.13</lt></range>
2255      </package>
2256    </affects>
2257    <description>
2258      <body xmlns="http://www.w3.org/1999/xhtml">
2259	<p>The coppermine development team reports two vulnerabilities
2260	  with the coppermine application.  These vulnerabilities are
2261	  caused by improper checking of the log variable in "viewlog.php"
2262	  and improper checking of the referer variable in "mode.php".
2263	  This could allow local file inclusion, potentially disclosing
2264	  valuable information and could lead to an attacker conducting
2265	  a cross site scripting attack against the targeted site.</p>
2266      </body>
2267    </description>
2268    <references>
2269      <cvename>CVE-2007-4976</cvename>
2270      <cvename>CVE-2007-4977</cvename>
2271      <url>http://coppermine-gallery.net/forum/index.php?topic=46847.0</url>
2272    </references>
2273    <dates>
2274      <discovery>2007-09-14</discovery>
2275      <entry>2007-09-20</entry>
2276      <modified>2010-05-12</modified>
2277    </dates>
2278  </vuln>
2279
2280  <vuln vid="e595e170-6771-11dc-8be8-02e0185f8d72">
2281    <topic>openoffice -- arbitrary command execution vulnerability</topic>
2282    <affects>
2283      <package>
2284	<name>openoffice</name>
2285	<range><gt>0</gt></range>
2286      </package>
2287    </affects>
2288    <description>
2289      <body xmlns="http://www.w3.org/1999/xhtml">
2290	<p>iDefense reports:</p>
2291	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593">
2292	  <p>Remote exploitation of multiple integer overflow
2293	    vulnerabilities within OpenOffice, as included in various
2294	    vendors' operating system distributions, allows attackers to
2295	    execute arbitrary code.</p>
2296	  <p>These vulnerabilities exist within the TIFF parsing code of
2297	    the OpenOffice suite.  When parsing the TIFF directory entries
2298	    for certain tags, the parser uses untrusted values from the
2299	    file to calculate the amount of memory to allocate.  By
2300	    providing specially crafted values, an integer overflow occurs
2301	    in this calculation.  This results in the allocation of a
2302	    buffer of insufficient size, which in turn leads to a heap
2303	    overflow.</p>
2304	</blockquote>
2305      </body>
2306    </description>
2307    <references>
2308      <cvename>CVE-2007-2834</cvename>
2309      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593</url>
2310    </references>
2311    <dates>
2312      <discovery>2007-09-19</discovery>
2313      <entry>2007-09-20</entry>
2314    </dates>
2315  </vuln>
2316
2317  <vuln vid="f8d3689e-6770-11dc-8be8-02e0185f8d72">
2318    <topic>bugzilla -- "createmailregexp" security bypass vulnerability</topic>
2319    <affects>
2320      <package>
2321	<name>bugzilla</name>
2322	<range><ge>3.*</ge><lt>3.0.2</lt></range>
2323      </package>
2324    </affects>
2325    <description>
2326      <body xmlns="http://www.w3.org/1999/xhtml">
2327	<p>The Bugzilla development team reports:</p>
2328	<blockquote cite="http://www.bugzilla.org/security/3.0.1/">
2329	  <p>Bugzilla::WebService::User::offer_account_by_email does
2330	    not check the "createemailregexp" parameter, and thus
2331	    allows users to create accounts who would normally be
2332	    denied account creation.  The "emailregexp" parameter is
2333	    still checked.  If you do not have the SOAP::Lite Perl
2334	    module installed on your Bugzilla system, your system is
2335	    not vulnerable (because the Bugzilla WebService will not
2336	    be enabled).</p>
2337	</blockquote>
2338      </body>
2339    </description>
2340    <references>
2341      <cvename>CVE-2007-5038</cvename>
2342      <url>http://www.bugzilla.org/security/3.0.1/</url>
2343    </references>
2344    <dates>
2345      <discovery>2007-09-18</discovery>
2346      <entry>2007-09-20</entry>
2347      <modified>2010-05-12</modified>
2348    </dates>
2349  </vuln>
2350
2351  <vuln vid="14ad2a28-66d2-11dc-b25f-02e0185f8d72">
2352    <topic>konquerer -- address bar spoofing</topic>
2353    <affects>
2354      <package>
2355	<name>kdebase</name>
2356	<range><lt>3.5.7_3</lt></range>
2357      </package>
2358      <package>
2359	<name>kdelibs</name>
2360	<range><lt>3.5.7_2</lt></range>
2361      </package>
2362    </affects>
2363    <description>
2364      <body xmlns="http://www.w3.org/1999/xhtml">
2365	<p>The KDE development team reports:</p>
2366	<blockquote cite="http://www.kde.org/info/security/advisory-20070914-1.txt">
2367	  <p>The Konqueror address bar is vulnerable to spoofing attacks
2368	    that are based on embedding white spaces in the url. In addition
2369	    the address bar could be tricked to show an URL which it is
2370	    intending to visit for a short amount of time instead of the
2371	    current URL.</p>
2372	</blockquote>
2373      </body>
2374    </description>
2375    <references>
2376      <cvename>CVE-2007-3820</cvename>
2377      <cvename>CVE-2007-4224</cvename>
2378      <cvename>CVE-2007-4225</cvename>
2379      <url>http://www.kde.org/info/security/advisory-20070914-1.txt</url>
2380    </references>
2381    <dates>
2382      <discovery>2007-09-14</discovery>
2383      <entry>2007-09-19</entry>
2384    </dates>
2385  </vuln>
2386
2387  <vuln vid="79b616d0-66d1-11dc-b25f-02e0185f8d72">
2388    <topic>kdm -- passwordless login vulnerability</topic>
2389    <affects>
2390      <package>
2391	<name>kdebase3</name>
2392	<range><lt>3.5.7_3</lt></range>
2393      </package>
2394    </affects>
2395    <description>
2396      <body xmlns="http://www.w3.org/1999/xhtml">
2397	<p>The KDE development team reports:</p>
2398	<blockquote cite="http://www.kde.org/info/security/advisory-20070919-1.txt">
2399	  <p>KDM can be tricked into performing a password-less login
2400	    even for accounts with a password set under certain
2401	    circumstances, namely autologin to be configured and
2402	   "shutdown with password" enabled.</p>
2403	</blockquote>
2404      </body>
2405    </description>
2406    <references>
2407      <cvename>CVE-2007-4569</cvename>
2408      <url>http://www.kde.org/info/security/advisory-20070919-1.txt</url>
2409    </references>
2410    <dates>
2411      <discovery>2007-09-19</discovery>
2412      <entry>2007-09-19</entry>
2413    </dates>
2414  </vuln>
2415
2416  <vuln vid="209f0d75-4b5c-11dc-a6cd-000fb5066b20">
2417    <topic>flyspray -- authentication bypass</topic>
2418    <affects>
2419      <package>
2420	<name>flyspray</name>
2421	<range><lt>0.9.9.2</lt></range>
2422      </package>
2423    </affects>
2424    <description>
2425      <body xmlns="http://www.w3.org/1999/xhtml">
2426	<p>The Flyspray Project reports:</p>
2427	<blockquote cite="http://www.flyspray.org/fsa:1">
2428	  <p>Flyspray authentication system can be bypassed by sending a
2429	    carefully crafted post request.</p>
2430	  <p>To be vulnerable, PHP configuration directive output_buffering
2431	    has to be disabled or set to a low value.</p>
2432	</blockquote>
2433      </body>
2434    </description>
2435    <references>
2436      <cvename>CVE-2007-1788</cvename>
2437      <url>http://www.flyspray.org/fsa:1</url>
2438    </references>
2439    <dates>
2440      <discovery>2007-03-13</discovery>
2441      <entry>2007-09-19</entry>
2442    </dates>
2443  </vuln>
2444
2445  <vuln vid="3ce8c7e2-66cf-11dc-b25f-02e0185f8d72">
2446    <topic>mozilla -- code execution via Quicktime media-link files</topic>
2447    <affects>
2448      <package>
2449	<name>firefox</name>
2450	<range><lt>2.0.0.7,1</lt></range>
2451      </package>
2452      <package>
2453	<name>linux-firefox</name>
2454	<range><lt>2.0.0.7</lt></range>
2455      </package>
2456      <!-- Packages which probably will be upgraded -->
2457      <package>
2458	<name>seamonkey</name>
2459	<name>linux-seamonkey</name>
2460	<range><lt>1.1.5</lt></range>
2461      </package>
2462      <package>
2463	<name>linux-firefox-devel</name>
2464	<range><lt>3.0.a2007.12.12</lt></range>
2465      </package>
2466      <package>
2467	<name>linux-seamonkey-devel</name>
2468	<range><lt>2.0.a2007.12.12</lt></range>
2469      </package>
2470      <!-- Deprecated/old names -->
2471      <package>
2472	<name>firefox-ja</name>
2473	<name>linux-mozilla-devel</name>
2474	<name>linux-mozilla</name>
2475	<name>mozilla</name>
2476	<range><gt>0</gt></range>
2477      </package>
2478    </affects>
2479    <description>
2480      <body xmlns="http://www.w3.org/1999/xhtml">
2481	<p>The Mozilla Foundation reports a vulnerability within the
2482	  mozilla browser.  This vulnerability also affects various
2483	  other browsers like firefox and seamonkey.  The vulnerability
2484	  is caused by QuickTime Media-Link files that contain a qtnext
2485	  attribute.  This could allow an attacker to start the browser
2486	  with arbitrary command-line options.	This could allow the
2487	  attacker to install malware, steal local data and possibly
2488	  execute and/or do other arbitrary things within the users
2489	  context.</p>
2490      </body>
2491    </description>
2492    <references>
2493      <cvename>CVE-2006-4965</cvename>
2494      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-28.html</url>
2495    </references>
2496    <dates>
2497      <discovery>2007-09-18</discovery>
2498      <entry>2007-09-19</entry>
2499      <modified>2007-12-14</modified>
2500    </dates>
2501  </vuln>
2502
2503  <vuln vid="71d903fc-602d-11dc-898c-001921ab2fa4">
2504    <topic>php -- multiple vulnerabilities</topic>
2505    <affects>
2506      <package>
2507	<name>php5</name>
2508	<range><lt>5.2.4</lt></range>
2509      </package>
2510      <package>
2511	<name>php4</name>
2512	<range><lt>4.4.8</lt></range>
2513      </package>
2514    </affects>
2515    <description>
2516      <body xmlns="http://www.w3.org/1999/xhtml">
2517	<p>The PHP development team reports:</p>
2518	<blockquote cite="http://www.php.net/releases/5_2_4.php">
2519	  <p>Security Enhancements and Fixes in PHP 5.2.4:</p>
2520	  <ul>
2521	    <li>Fixed a floating point exception inside wordwrap() (Reported
2522	    by Mattias Bengtsson)</li>
2523	    <li>Fixed several integer overflows inside the GD extension
2524	    (Reported by Mattias Bengtsson)</li>
2525	    <li>Fixed size calculation in chunk_split() (Reported by Gerhard
2526	    Wagner)</li>
2527	    <li>Fixed integer overflow in str[c]spn(). (Reported by Mattias
2528	    Bengtsson)</li>
2529	    <li>Fixed money_format() not to accept multiple %i or %n tokens.
2530	    (Reported by Stanislav Malyshev)</li>
2531	    <li>Fixed zend_alter_ini_entry() memory_limit interruption
2532	    vulnerability. (Reported by Stefan Esser)</li>
2533	    <li>Fixed INFILE LOCAL option handling with MySQL extensions not
2534	    to be allowed when open_basedir or safe_mode is active. (Reported
2535	    by Mattias Bengtsson)</li>
2536	    <li>Fixed session.save_path and error_log values to be checked
2537	    against open_basedir and safe_mode (CVE-2007-3378) (Reported by
2538	    Maksymilian Arciemowicz)</li>
2539	    <li>Fixed a possible invalid read in glob() win32 implementation
2540	    (CVE-2007-3806) (Reported by shinnai)</li>
2541	    <li>Fixed a possible buffer overflow in php_openssl_make_REQ
2542	    (Reported by zatanzlatan at hotbrev dot com)</li>
2543	    <li>Fixed an open_basedir bypass inside glob() function (Reported
2544	    by dr at peytz dot dk)</li>
2545	    <li>Fixed a possible open_basedir bypass inside session extension
2546	    when the session file is a symlink (Reported by c dot i dot morris
2547	    at durham dot ac dot uk)</li>
2548	    <li>Improved fix for MOPB-03-2007.</li>
2549	    <li>Corrected fix for CVE-2007-2872.</li>
2550	  </ul>
2551	</blockquote>
2552      </body>
2553    </description>
2554    <references>
2555      <cvename>CVE-2007-2872</cvename>
2556      <cvename>CVE-2007-3378</cvename>
2557      <cvename>CVE-2007-3806</cvename>
2558      <cvename>CVE-2007-3996</cvename>
2559      <cvename>CVE-2007-3997</cvename>
2560      <cvename>CVE-2007-3998</cvename>
2561      <cvename>CVE-2007-4652</cvename>
2562      <cvename>CVE-2007-4657</cvename>
2563      <cvename>CVE-2007-4658</cvename>
2564      <cvename>CVE-2007-4659</cvename>
2565      <cvename>CVE-2007-4660</cvename>
2566      <cvename>CVE-2007-4661</cvename>
2567      <cvename>CVE-2007-4662</cvename>
2568      <cvename>CVE-2007-4663</cvename>
2569      <cvename>CVE-2007-4670</cvename>
2570      <url>http://www.php.net/releases/4_4_8.php</url>
2571      <url>http://www.php.net/releases/5_2_4.php</url>
2572      <url>http://secunia.com/advisories/26642</url>
2573    </references>
2574    <dates>
2575      <discovery>2007-08-30</discovery>
2576      <entry>2007-09-11</entry>
2577      <modified>2008-01-14</modified>
2578    </dates>
2579  </vuln>
2580
2581  <vuln vid="c115271d-602b-11dc-898c-001921ab2fa4">
2582    <topic>apache -- multiple vulnerabilities</topic>
2583    <affects>
2584      <package>
2585	<name>apache</name>
2586	<range><gt>2.2.0</gt><lt>2.2.6</lt></range>
2587	<range><gt>2.0.0</gt><lt>2.0.61</lt></range>
2588      </package>
2589    </affects>
2590    <description>
2591      <body xmlns="http://www.w3.org/1999/xhtml">
2592	<p>Apache HTTP server project reports:</p>
2593	<blockquote cite="http://www.apache.org/dist/httpd/Announcement2.2.html">
2594	  <p>The following potential security flaws are addressed:</p>
2595	  <ul>
2596	    <li>CVE-2007-3847: mod_proxy: Prevent reading past the end of a
2597	      buffer when parsing date-related headers.</li>
2598	    <li>CVE-2007-1863: mod_cache: Prevent a segmentation fault if
2599	      attributes are listed in a Cache-Control header without any
2600	      value.</li>
2601	    <li>CVE-2007-3304: prefork, worker, event MPMs: Ensure that the
2602	      parent process cannot be forced to kill processes outside its
2603	      process group.</li>
2604	    <li>CVE-2006-5752: mod_status: Fix a possible XSS attack against
2605	      a site with a public server-status page and ExtendedStatus
2606	      enabled, for browsers which perform charset "detection".
2607	      Reported by Stefan Esser.</li>
2608	    <li>CVE-2006-1862: mod_mem_cache: Copy headers into longer lived
2609	      storage; header names and values could previously point to
2610	      cleaned up storage.</li>
2611	  </ul>
2612	</blockquote>
2613      </body>
2614    </description>
2615    <references>
2616      <cvename>CVE-2007-3847</cvename>
2617      <cvename>CVE-2007-1863</cvename>
2618      <cvename>CVE-2006-5752</cvename>
2619      <cvename>CVE-2007-3304</cvename>
2620    </references>
2621    <dates>
2622      <discovery>2007-09-07</discovery>
2623      <entry>2007-09-11</entry>
2624    </dates>
2625  </vuln>
2626
2627  <vuln vid="4b673ae7-5f9a-11dc-84dd-000102cc8983">
2628    <topic>lighttpd -- FastCGI header overrun in mod_fastcgi</topic>
2629    <affects>
2630      <package>
2631	<name>lighttpd</name>
2632	<range><lt>1.4.18</lt></range>
2633      </package>
2634    </affects>
2635    <description>
2636      <body xmlns="http://www.w3.org/1999/xhtml">
2637	<p>lighttpd maintainer reports:</p>
2638	<blockquote cite="http://www.lighttpd.net/assets/2007/9/9/lighttpd_sa_2007_12.txt">
2639	  <p>Lighttpd is prone to a header overflow when using the mod_fastcgi
2640	    extension, this can lead to arbitrary code execution in the fastcgi
2641	    application. For a detailed description of the bug see the external
2642	    reference.</p>
2643	  <p>This bug was found by Mattias Bengtsson and Philip Olausson</p>
2644	</blockquote>
2645      </body>
2646    </description>
2647    <references>
2648      <url>http://www.lighttpd.net/assets/2007/9/9/lighttpd_sa_2007_12.txt</url>
2649      <url>http://secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/</url>
2650      <cvename>CVE-2007-4727</cvename>
2651    </references>
2652    <dates>
2653      <discovery>2007-09-09</discovery>
2654      <entry>2007-09-10</entry>
2655    </dates>
2656  </vuln>
2657
2658  <vuln vid="f14ad681-5b88-11dc-812d-0011098b2f36">
2659    <topic>rkhunter -- insecure temporary file creation</topic>
2660    <affects>
2661      <package>
2662	<name>rkhunter</name>
2663	<range><lt>1.2.5</lt></range>
2664      </package>
2665    </affects>
2666    <description>
2667      <body xmlns="http://www.w3.org/1999/xhtml">
2668	<p>Gentoo reports:</p>
2669	<blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml">
2670	  <p>Sune Kloppenborg Jeppesen and Tavis Ormandy of the Gentoo Linux
2671	    Security Team have reported that the check_update.sh script and
2672	    the main rkhunter script insecurely creates several temporary
2673	    files with predictable filenames.</p>
2674	  <p>A local attacker could create symbolic links in the temporary
2675	    files directory, pointing to a valid file somewhere on the
2676	    filesystem.  When rkhunter or the check_update.sh script runs,
2677	    this would result in the file being overwritten with the rights of
2678	    the user running the utility, which could be the root user.</p>
2679	</blockquote>
2680      </body>
2681    </description>
2682    <references>
2683      <bid>13399</bid>
2684      <cvename>CVE-2005-1270</cvename>
2685      <url>http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml</url>
2686    </references>
2687    <dates>
2688      <discovery>2005-04-26</discovery>
2689      <entry>2007-09-05</entry>
2690    </dates>
2691  </vuln>
2692
2693  <vuln vid="72cdf2ab-5b87-11dc-812d-0011098b2f36">
2694    <topic>lsh -- multiple vulnerabilities</topic>
2695    <affects>
2696      <package>
2697	<name>lsh</name>
2698	<range><lt>2.0.1</lt></range>
2699      </package>
2700    </affects>
2701    <description>
2702      <body xmlns="http://www.w3.org/1999/xhtml">
2703	<p>Secunia reports:</p>
2704	<blockquote cite="http://secunia.com/advisories/14609">
2705	  <p>A vulnerability has been reported in LSH, which potentially
2706	    can be exploited by malicious people to cause a DoS (Denial
2707	    of Service).</p>
2708	</blockquote>
2709      </body>
2710    </description>
2711    <references>
2712      <cvename>CVE-2003-0826</cvename>
2713      <cvename>CVE-2005-0814</cvename>
2714      <url>http://secunia.com/advisories/14609</url>
2715    </references>
2716    <dates>
2717      <discovery>2005-03-17</discovery>
2718      <entry>2007-09-05</entry>
2719      <modified>2008-01-07</modified>
2720    </dates>
2721  </vuln>
2722
2723  <vuln vid="45500f74-5947-11dc-87c1-000e2e5785ad">
2724    <topic>fetchmail -- denial of service on reject of local warning message</topic>
2725    <affects>
2726      <package>
2727	<name>fetchmail</name>
2728	<range><ge>4.6.8</ge><lt>6.3.8_4</lt></range>
2729      </package>
2730    </affects>
2731    <description>
2732      <body xmlns="http://www.w3.org/1999/xhtml">
2733	<p>Matthias Andree reports:</p>
2734	<blockquote cite="http://www.fetchmail.info/fetchmail-SA-2007-02.txt">
2735	  <p>fetchmail will generate warning messages in certain
2736	    circumstances (for instance, when leaving oversized messages
2737	    on the server or login to the upstream fails) and send them
2738	    to the local postmaster or the user running it.</p>
2739	  <p>If this warning message is then refused by the SMTP listener
2740	    that fetchmail is forwarding the message to, fetchmail
2741	    crashes and does not collect further messages until it is
2742	    restarted.</p>
2743	</blockquote>
2744      </body>
2745    </description>
2746    <references>
2747      <cvename>CVE-2007-4565</cvename>
2748      <url>http://www.fetchmail.info/fetchmail-SA-2007-02.txt</url>
2749    </references>
2750    <dates>
2751      <discovery>2007-07-29</discovery>
2752      <entry>2007-09-02</entry>
2753    </dates>
2754  </vuln>
2755
2756  <vuln vid="d944719e-42f4-4864-89ed-f045b541919f">
2757    <topic>gtar -- Directory traversal vulnerability</topic>
2758    <affects>
2759      <package>
2760	<name>gtar</name>
2761	<range><lt>1.18_1</lt></range>
2762      </package>
2763    </affects>
2764    <description>
2765      <body xmlns="http://www.w3.org/1999/xhtml">
2766	<p>Red Hat reports:</p>
2767	<blockquote cite="http://rhn.redhat.com/errata/RHSA-2007-0860.html">
2768	  <p>A path traversal flaw was discovered in the way GNU
2769	  tar extracted archives.  A malicious user could create a
2770	  tar archive that could write to arbitrary files to which
2771	  the user running GNU tar had write access.</p>
2772	</blockquote>
2773	<p>Red Hat credits Dmitry V. Levin for reporting the issue.</p>
2774      </body>
2775    </description>
2776    <references>
2777      <bid>25417</bid>
2778      <cvename>CVE-2007-4131</cvename>
2779      <url>http://rhn.redhat.com/errata/RHSA-2007-0860.html</url>
2780      <url>https://bugzilla.redhat.com/show_bug.cgi?id=251921</url>
2781    </references>
2782    <dates>
2783      <discovery>2007-08-23</discovery>
2784      <entry>2007-09-01</entry>
2785    </dates>
2786  </vuln>
2787
2788  <vuln vid="d9867f50-54d0-11dc-b80b-0016179b2dd5">
2789    <topic>claws-mail -- POP3 Format String Vulnerability</topic>
2790    <affects>
2791      <package>
2792	<name>claws-mail</name>
2793	<name>sylpheed-claws</name>
2794	<range><lt>2.10.0_3</lt></range>
2795      </package>
2796      <package>
2797	<name>sylpheed2</name>
2798	<range><lt>2.4.4_1</lt></range>
2799      </package>
2800    </affects>
2801    <description>
2802      <body xmlns="http://www.w3.org/1999/xhtml">
2803	<p>A Secunia Advisory reports:</p>
2804	<blockquote cite="http://secunia.com/advisories/26550/">
2805	  <p>A format string error in the "inc_put_error()" function in
2806	    src/inc.c when displaying a POP3 server's error response can
2807	    be exploited via specially crafted POP3 server replies containing
2808	    format specifiers.</p>
2809	  <p>Successful exploitation may allow execution of arbitrary code,
2810	    but requires that the user is tricked into connecting to a malicious
2811	    POP3 server.</p>
2812	</blockquote>
2813      </body>
2814    </description>
2815    <references>
2816      <cvename>CVE-2007-2958</cvename>
2817      <url>http://secunia.com/advisories/26550/</url>
2818      <url>http://secunia.com/secunia_research/2007-70/advisory/</url>
2819    </references>
2820    <dates>
2821      <discovery>2007-08-24</discovery>
2822      <entry>2007-08-27</entry>
2823      <modified>2010-05-12</modified>
2824    </dates>
2825  </vuln>
2826
2827  <vuln vid="af8e3a0c-5009-11dc-8a43-003048705d5a">
2828    <topic>rsync -- off by one stack overflow</topic>
2829    <affects>
2830      <package>
2831	<name>rsync</name>
2832	<range><lt>2.6.9_1</lt></range>
2833      </package>
2834    </affects>
2835    <description>
2836      <body xmlns="http://www.w3.org/1999/xhtml">
2837	<p>BugTraq reports:</p>
2838	<blockquote cite="http://www.securityfocus.com/bid/25336/discuss">
2839	  <p>The rsync utility is prone to an off-by-one buffer-overflow
2840	    vulnerability. This issue is due to a failure of the application
2841	    to properly bounds-check user-supplied input.</p>
2842	  <p>Successfully exploiting this issue may allow arbitrary
2843	    code-execution in the context of the affected utility.</p>
2844	</blockquote>
2845      </body>
2846    </description>
2847    <references>
2848      <bid>25336</bid>
2849      <cvename>CVE-2007-4091</cvename>
2850    </references>
2851    <dates>
2852      <discovery>2007-08-15</discovery>
2853      <entry>2007-08-21</entry>
2854      <modified>2007-08-23</modified>
2855    </dates>
2856  </vuln>
2857
2858  <vuln vid="df4a7d21-4b17-11dc-9fc2-001372ae3ab9">
2859    <topic>opera -- Vulnerability in javascript handling</topic>
2860    <affects>
2861      <package>
2862	<name>opera</name>
2863	<name>opera-devel</name>
2864	<name>linux-opera</name>
2865	<range><lt>9.23.20070809</lt></range>
2866      </package>
2867    </affects>
2868    <description>
2869      <body xmlns="http://www.w3.org/1999/xhtml">
2870	<p>An advisory from Opera reports:</p>
2871	<blockquote cite="http://www.opera.com/support/search/view/865/">
2872	  <p>A specially crafted JavaScript can make Opera execute
2873	    arbitrary code.</p>
2874	</blockquote>
2875      </body>
2876    </description>
2877    <references>
2878      <url>http://www.opera.com/support/search/view/865/</url>
2879    </references>
2880    <dates>
2881      <discovery>2007-08-03</discovery>
2882      <entry>2007-08-15</entry>
2883      <modified>2007-08-25</modified>
2884    </dates>
2885  </vuln>
2886
2887  <vuln vid="4a338d17-412d-11dc-bdb0-0016179b2dd5">
2888    <topic>fsplib -- multiple vulnerabilities</topic>
2889    <affects>
2890      <package>
2891	<name>fsplib</name>
2892	<range><lt>0.9</lt></range>
2893      </package>
2894    </affects>
2895    <description>
2896      <body xmlns="http://www.w3.org/1999/xhtml">
2897	<p>A Secunia Advisory reports:</p>
2898	<blockquote cite="http://secunia.com/advisories/26184/">
2899	  <p>fsplib can be exploited to compromise an application using
2900	    the library.</p>
2901	  <p>A boundary error exists in the processing of file names in
2902	    fsp_readdir_native, which can be exploited to cause a stack-based
2903	    buffer overflow if the defined MAXNAMLEN is bigger than 256.</p>
2904	  <p>A boundary error exists in the processing of directory entries in
2905	    fsp_readdir, which can be exploited to cause a stack-based buffer
2906	    overflow on systems with an insufficient size allocated for the
2907	    d_name field of directory entries.</p>
2908	</blockquote>
2909      </body>
2910    </description>
2911    <references>
2912      <cvename>CVE-2007-3961</cvename>
2913      <cvename>CVE-2007-3962</cvename>
2914      <url>http://secunia.com/advisories/26184/</url>
2915    </references>
2916    <dates>
2917      <discovery>2007-07-24</discovery>
2918      <entry>2007-08-02</entry>
2919    </dates>
2920  </vuln>
2921
2922  <vuln vid="4872d9a7-4128-11dc-bdb0-0016179b2dd5">
2923    <topic>joomla -- multiple vulnerabilities</topic>
2924    <affects>
2925      <package>
2926	<name>joomla</name>
2927	<range><lt>1.0.13</lt></range>
2928      </package>
2929    </affects>
2930    <description>
2931      <body xmlns="http://www.w3.org/1999/xhtml">
2932	<p>A Secunia Advisory reports:</p>
2933	  <p>joomla can be exploited to conduct session fixation
2934	    attacks, cross-site scripting attacks or HTTP response
2935	    splitting attacks.</p>
2936	  <p>Certain unspecified input passed in com_search, com_content and
2937	    mod_login is not properly sanitised before being returned to a
2938	    user.  This can be exploited to execute arbitrary HTML and script
2939	    code in a user's browser session in context of an affected
2940	    site.</p>
2941	  <p>Input passed to the url parameter is not properly sanitised
2942	    before being returned to the user.	This can be exploited to insert
2943	    arbitrary HTTP headers, which will be included in a response sent
2944	    to the user, allowing for execution of arbitrary HTML and script
2945	    code in a user's browser session in context of an affected
2946	    site.</p>
2947	  <p>An error exists in the handling of sessions and can be exploited
2948	    to hijack another user's session by tricking the user into logging
2949	    in after following a specially crafted link.</p>
2950      </body>
2951    </description>
2952    <references>
2953      <cvename>CVE-2007-4188</cvename>
2954      <cvename>CVE-2007-4189</cvename>
2955      <cvename>CVE-2007-4190</cvename>
2956      <cvename>CVE-2007-5577</cvename>
2957      <url>http://www.joomla.org/content/view/3677/1/</url>
2958      <url>http://secunia.com/advisories/26239/</url>
2959    </references>
2960    <dates>
2961      <discovery>2007-07-30</discovery>
2962      <entry>2007-08-02</entry>
2963      <modified>2010-05-12</modified>
2964    </dates>
2965  </vuln>
2966
2967  <vuln vid="2dc764fa-40c0-11dc-aeac-02e0185f8d72">
2968    <topic>FreeBSD -- Buffer overflow in tcpdump(1)</topic>
2969    <affects>
2970      <package>
2971	<name>tcpdump</name>
2972	<range><lt>3.9.6</lt></range>
2973      </package>
2974      <package>
2975	<name>FreeBSD</name>
2976	<range><ge>6.2</ge><lt>6.2_7</lt></range>
2977	<range><ge>6.1</ge><lt>6.1_19</lt></range>
2978	<range><ge>5.5</ge><lt>5.5_15</lt></range>
2979      </package>
2980    </affects>
2981    <description>
2982      <body xmlns="http://www.w3.org/1999/xhtml">
2983	<h1>Problem Description:</h1>
2984	<p>An un-checked return value in the BGP dissector code can
2985	  result in an integer overflow.  This value is used in
2986	  subsequent buffer management operations, resulting in a stack
2987	  based buffer overflow under certain circumstances.</p>
2988	<h1>Impact:</h1>
2989	<p>By crafting malicious BGP packets, an attacker could exploit
2990	  this vulnerability to execute code or crash the tcpdump
2991	  process on the target system.  This code would be executed in
2992	  the context of the user running tcpdump(1).  It should be
2993	  noted that tcpdump(1) requires privileges in order to open live
2994	  network interfaces.</p>
2995	<h1>Workaround:</h1>
2996	<p>No workaround is available.</p>
2997      </body>
2998    </description>
2999    <references>
3000      <cvename>CVE-2007-3798</cvename>
3001      <freebsdsa>SA-07:06.tcpdump</freebsdsa>
3002    </references>
3003    <dates>
3004      <discovery>2007-08-01</discovery>
3005      <entry>2007-08-02</entry>
3006      <modified>2016-08-09</modified>
3007    </dates>
3008  </vuln>
3009
3010  <vuln vid="3de342fb-40be-11dc-aeac-02e0185f8d72">
3011    <topic>FreeBSD -- Predictable query ids in named(8)</topic>
3012    <affects>
3013      <package>
3014	<name>named</name>
3015	<range><ge>9.4</ge><lt>9.4.1.1</lt></range>
3016	<range><ge>9.3</ge><lt>9.3.4.1</lt></range>
3017      </package>
3018      <package>
3019	<name>FreeBSD</name>
3020	<range><ge>6.2</ge><lt>6.2_7</lt></range>
3021	<range><ge>6.1</ge><lt>6.1_19</lt></range>
3022	<range><ge>5.5</ge><lt>5.5_15</lt></range>
3023      </package>
3024    </affects>
3025    <description>
3026      <body xmlns="http://www.w3.org/1999/xhtml">
3027	<h1>Problem Description:</h1>
3028	<p>When named(8) is operating as a recursive DNS server or
3029	  sending NOTIFY requests to slave DNS servers, named(8)
3030	  uses a predictable query id.</p>
3031	<h1>Impact:</h1>
3032	<p>An attacker who can see the query id for some request(s)
3033	  sent by named(8) is likely to be able to perform DNS cache
3034	  poisoning by predicting the query id for other request(s).</p>
3035	<h1>Workaround:</h1>
3036	<p>No workaround is available.</p>
3037      </body>
3038    </description>
3039    <references>
3040      <cvename>CVE-2007-2926</cvename>
3041      <freebsdsa>SA-07:07.bind</freebsdsa>
3042    </references>
3043    <dates>
3044      <discovery>2007-07-24</discovery>
3045      <entry>2007-08-02</entry>
3046      <modified>2016-08-09</modified>
3047    </dates>
3048  </vuln>
3049
3050  <vuln vid="0e43a14d-3f3f-11dc-a79a-0016179b2dd5">
3051    <topic>xpdf -- stack based buffer overflow</topic>
3052    <affects>
3053      <package>
3054	<name>xpdf</name>
3055	<range><lt>3.02_2</lt></range>
3056      </package>
3057      <package>
3058	<name>kdegraphics</name>
3059	<range><lt>3.5.7_1</lt></range>
3060      </package>
3061      <package>
3062	<name>cups-base</name>
3063	<range><lt>1.2.11_3</lt></range>
3064      </package>
3065      <package>
3066	<name>gpdf</name>
3067	<range><gt>0</gt></range>
3068      </package>
3069      <package>
3070	<name>pdftohtml</name>
3071	<range><lt>0.39_3</lt></range>
3072      </package>
3073      <package>
3074	<name>poppler</name>
3075	<range><lt>0.5.9_4</lt></range>
3076      </package>
3077    </affects>
3078    <description>
3079      <body xmlns="http://www.w3.org/1999/xhtml">
3080	<p>The KDE Team reports:</p>
3081	<blockquote cite="http://www.kde.org/info/security/advisory-20070730-1.txt">
3082	  <p>kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains
3083	    a vulnerability that can cause a stack based buffer overflow
3084	    via a PDF file that exploits an integer overflow in
3085	    StreamPredictor::StreamPredictor(). Remotely supplied
3086	    pdf files can be used to disrupt the kpdf  viewer on
3087	    the client machine and possibly execute arbitrary code.</p>
3088	</blockquote>
3089      </body>
3090    </description>
3091    <references>
3092      <bid>25124</bid>
3093      <cvename>CVE-2007-3387</cvename>
3094      <url>http://www.kde.org/info/security/advisory-20070730-1.txt</url>
3095    </references>
3096    <dates>
3097      <discovery>2007-07-30</discovery>
3098      <entry>2007-07-31</entry>
3099      <modified>2009-04-29</modified>
3100    </dates>
3101  </vuln>
3102
3103  <vuln vid="ff284bf0-3f32-11dc-a79a-0016179b2dd5">
3104    <cancelled superseded="2dc764fa-40c0-11dc-aeac-02e0185f8d72"/>
3105  </vuln>
3106
3107  <vuln vid="863f95d3-3df1-11dc-b3d3-0016179b2dd5">
3108    <topic>mutt -- buffer overflow vulnerability</topic>
3109    <affects>
3110      <package>
3111	<name>mutt</name>
3112	<name>mutt-lite</name>
3113	<name>ja-mutt</name>
3114	<name>zh-mutt</name>
3115	<range><lt>1.4.2.3</lt></range>
3116      </package>
3117    </affects>
3118    <description>
3119      <body xmlns="http://www.w3.org/1999/xhtml">
3120	<p>Securityfocus reports:</p>
3121	<blockquote cite="http://www.securityfocus.com/bid/24192/">
3122	  <p>Mutt is prone to a local buffer-overflow vulnerability
3123	    because it fails to properly bounds-check user-supplied
3124	    input before using it in a memory copy operation.
3125	    An attacker can exploit this issue to execute arbitrary
3126	    code with the with the privileges of the victim.  Failed
3127	    exploit attempts will result in a denial of service.</p>
3128	</blockquote>
3129      </body>
3130    </description>
3131    <references>
3132      <bid>24192</bid>
3133      <cvename>CVE-2007-2683</cvename>
3134      <url>http://www.redhat.com/support/errata/RHSA-2007-0386.html</url>
3135    </references>
3136    <dates>
3137      <discovery>2007-05-28</discovery>
3138      <entry>2007-07-29</entry>
3139    </dates>
3140  </vuln>
3141
3142  <vuln vid="d2b8a963-3d59-11dc-b3d3-0016179b2dd5">
3143    <topic>p5-Net-DNS -- multiple Vulnerabilities</topic>
3144    <affects>
3145      <package>
3146	<name>p5-Net-DNS</name>
3147	<range><lt>0.60</lt></range>
3148      </package>
3149    </affects>
3150    <description>
3151      <body xmlns="http://www.w3.org/1999/xhtml">
3152	<p>A Secunia Advisory reports:</p>
3153	<blockquote cite="http://secunia.com/advisories/25829/">
3154	  <p>An error exists in the handling of DNS queries where IDs are
3155	    incremented with a fixed value and are additionally used for
3156	    child processes in a forking server. This can be exploited to
3157	    poison the DNS cache of an application using the module if a
3158	    valid ID is guessed.</p>
3159	  <p>An error in the PP implementation within the "dn_expand()"
3160	    function can be exploited to cause a stack overflow due to an
3161	    endless loop via a specially crafted DNS packet.</p>
3162	</blockquote>
3163      </body>
3164    </description>
3165    <references>
3166      <cvename>CVE-2007-3377</cvename>
3167      <cvename>CVE-2007-3409</cvename>
3168      <url>http://secunia.com/advisories/25829/</url>
3169    </references>
3170    <dates>
3171      <discovery>2007-06-27</discovery>
3172      <entry>2007-07-28</entry>
3173    </dates>
3174  </vuln>
3175
3176  <vuln vid="88260dfe-3d21-11dc-b3d3-0016179b2dd5">
3177    <topic>phpsysinfo -- url Cross-Site Scripting</topic>
3178    <affects>
3179      <package>
3180	<name>phpSysInfo</name>
3181	<range><lt>2.5.3_1</lt></range>
3182      </package>
3183    </affects>
3184    <description>
3185      <body xmlns="http://www.w3.org/1999/xhtml">
3186	<p>Doz reports:</p>
3187	<blockquote cite="http://secunia.com/advisories/26248/">
3188	  <p>A Input passed in the URL to index.php is not properly
3189	    sanitised before being returned to the user.  This can be
3190	    exploited to execute arbitrary HTML and script code in a
3191	    user's browser session in context of an affected site.</p>
3192	</blockquote>
3193      </body>
3194    </description>
3195    <references>
3196      <url>http://secunia.com/advisories/26248/</url>
3197    </references>
3198    <dates>
3199      <discovery>2007-07-27</discovery>
3200      <entry>2007-07-28</entry>
3201      <modified>2007-08-01</modified>
3202    </dates>
3203  </vuln>
3204
3205  <vuln vid="98dd7788-3d13-11dc-b3d3-0016179b2dd5">
3206    <topic>drupal -- Cross site request forgeries</topic>
3207    <affects>
3208      <package>
3209	<name>drupal5</name>
3210	<range><lt>5.2</lt></range>
3211      </package>
3212    </affects>
3213    <description>
3214      <body xmlns="http://www.w3.org/1999/xhtml">
3215	<p>The Drupal Project reports:</p>
3216	<blockquote cite="http://drupal.org/node/162360">
3217	  <p>Several parts in Drupal core are not protected against cross
3218	    site request forgeries due to inproper use of the Forms API,
3219	    or by taking action solely on GET requests. Malicious users are
3220	    able to delete comments and content revisions and disable menu
3221	    items by enticing a privileged users to visit certain URLs while
3222	    the victim is logged-in to the targeted site.</p>
3223	</blockquote>
3224      </body>
3225    </description>
3226    <references>
3227      <url>http://drupal.org/node/162360</url>
3228      <url>http://secunia.com/advisories/26224/</url>
3229    </references>
3230    <dates>
3231      <discovery>2007-07-26</discovery>
3232      <entry>2007-07-28</entry>
3233    </dates>
3234  </vuln>
3235
3236  <vuln vid="1f5b711b-3d0e-11dc-b3d3-0016179b2dd5">
3237    <topic>drupal -- Multiple cross-site scripting vulnerabilities</topic>
3238    <affects>
3239      <package>
3240	<name>drupal4</name>
3241	<range><lt>4.7.7</lt></range>
3242      </package>
3243      <package>
3244	<name>drupal5</name>
3245	<range><lt>5.2</lt></range>
3246      </package>
3247    </affects>
3248    <description>
3249      <body xmlns="http://www.w3.org/1999/xhtml">
3250	<p>The Drupal Project reports:</p>
3251	<blockquote cite="http://drupal.org/node/162361">
3252	  <p>Some server variables are not escaped consistently. When
3253	    a malicious user is able to entice a victim to visit a specially
3254	    crafted link or webpage, arbitrary HTML and script code can be
3255	    injected and executed in the context of the victim's session on
3256	    the targeted website.</p>
3257	  <p>Custom content type names are not escaped consistently. A
3258	    malicious user with the 'administer content types' permission
3259	    would be able to inject and execute arbitrary HTML and script
3260	    code on the website. Revoking the 'administer content types'
3261	    permission provides an immediate workaround.</p>
3262	</blockquote>
3263      </body>
3264    </description>
3265    <references>
3266      <url>http://drupal.org/node/162361</url>
3267      <url>http://secunia.com/advisories/26224/</url>
3268    </references>
3269    <dates>
3270      <discovery>2007-07-26</discovery>
3271      <entry>2007-07-28</entry>
3272    </dates>
3273  </vuln>
3274
3275  <vuln vid="1ed03222-3c65-11dc-b3d3-0016179b2dd5">
3276    <topic>vim -- Command Format String Vulnerability</topic>
3277    <affects>
3278      <package>
3279	<name>vim</name>
3280	<name>vim-console</name>
3281	<name>vim-lite</name>
3282	<name>vim-ruby</name>
3283	<name>vim6</name>
3284	<name>vim6-ruby</name>
3285	<range><lt>7.1.39</lt></range>
3286      </package>
3287    </affects>
3288    <description>
3289      <body xmlns="http://www.w3.org/1999/xhtml">
3290	<p>A Secunia Advisory reports:</p>
3291	<blockquote cite="http://secunia.com/advisories/25941/">
3292	  <p>A format string error in the "helptags_one()" function in
3293	    src/ex_cmds.c when running the "helptags" command can be exploited
3294	    to execute arbitrary code via specially crafted help files.</p>
3295	</blockquote>
3296      </body>
3297    </description>
3298    <references>
3299      <cvename>CVE-2007-2953</cvename>
3300      <url>http://secunia.com/advisories/25941/</url>
3301    </references>
3302    <dates>
3303      <discovery>2007-07-27</discovery>
3304      <entry>2007-07-27</entry>
3305    </dates>
3306  </vuln>
3307
3308  <vuln vid="b73335a5-3bbe-11dc-8e83-0016179b2dd5">
3309    <topic>libvorbis -- Multiple memory corruption flaws</topic>
3310    <affects>
3311      <package>
3312	<name>libvorbis</name>
3313	<range><lt>1.2.0,3</lt></range>
3314      </package>
3315    </affects>
3316    <description>
3317      <body xmlns="http://www.w3.org/1999/xhtml">
3318	<p>isecpartners reports:</p>
3319	<blockquote cite="http://www.isecpartners.com/advisories/2007-003-libvorbis.txt">
3320	  <p>libvorbis contains several vulnerabilities
3321	    allowing heap overwrite, read violations and a function
3322	    pointer overwrite. These bugs cause a at least a denial
3323	    of service, and potentially code execution.</p>
3324	</blockquote>
3325      </body>
3326    </description>
3327    <references>
3328      <url>http://www.isecpartners.com/advisories/2007-003-libvorbis.txt</url>
3329      <cvename>CVE-2007-3106</cvename>
3330    </references>
3331    <dates>
3332      <discovery>2007-06-05</discovery>
3333      <entry>2007-07-26</entry>
3334    </dates>
3335  </vuln>
3336
3337  <vuln vid="ab2575d6-39f0-11dc-b8cc-000fea449b8a">
3338    <topic>tomcat -- XSS vulnerability in sample applications</topic>
3339    <affects>
3340      <package>
3341	<name>apache-tomcat</name>
3342	<range><gt>6.0.0</gt><lt>6.0.11</lt></range>
3343      </package>
3344      <package>
3345	<name>tomcat</name>
3346	<range><gt>5.0.0</gt><lt>5.5.24</lt></range>
3347      </package>
3348      <package>
3349	<name>jakarta-tomcat</name>
3350	<range><gt>5.0.0</gt><lt>5.5.24</lt></range>
3351      </package>
3352    </affects>
3353    <description>
3354      <body xmlns="http://www.w3.org/1999/xhtml">
3355	<p>The Apache Project reports:</p>
3356	<blockquote cite="http://tomcat.apache.org/security-5.html">
3357	  <p>The JSP and Servlet included in the sample application within
3358	    the Tomcat documentation webapp did not escape user provided
3359	    data before including it in the output. This enabled a XSS
3360	    attack. These pages have been simplified not to use any user
3361	    provided data in the output.</p>
3362	</blockquote>
3363      </body>
3364    </description>
3365    <references>
3366      <cvename>CVE-2007-1355</cvename>
3367      <bid>24058</bid>
3368    </references>
3369    <dates>
3370      <discovery>2007-05-19</discovery>
3371      <entry>2007-07-24</entry>
3372    </dates>
3373  </vuln>
3374
3375  <vuln vid="872623af-39ec-11dc-b8cc-000fea449b8a">
3376    <topic>tomcat -- multiple vulnerabilities</topic>
3377    <affects>
3378      <package>
3379	<name>apache-tomcat</name>
3380	<range><ge>4.1.0</ge><lt>4.1.36</lt></range>
3381	<range><gt>6.0.0</gt><lt>6.0.11</lt></range>
3382      </package>
3383      <package>
3384	<name>tomcat</name>
3385	<range><gt>5.0.0</gt><lt>5.5.23</lt></range>
3386      </package>
3387      <package>
3388	<name>jakarta-tomcat</name>
3389	<range><ge>4.0.0</ge><lt>4.1.0</lt></range>
3390	<range><gt>5.0.0</gt><lt>5.5.23</lt></range>
3391      </package>
3392    </affects>
3393    <description>
3394      <body xmlns="http://www.w3.org/1999/xhtml">
3395	<p>Apache Project reports:</p>
3396	<blockquote cite="http://www.mail-archive.com/dev@tomcat.apache.org/msg16385.html">
3397	  <p>The Apache Tomcat team is proud to announce the immediate
3398	    availability of Tomcat 4.1.36 stable. This build contains
3399	    numerous library updates,  A small number of bug fixes and
3400	    two important security fixes.</p>
3401	</blockquote>
3402      </body>
3403    </description>
3404    <references>
3405      <cvename>CVE-2005-2090</cvename>
3406      <cvename>CVE-2007-0450</cvename>
3407      <cvename>CVE-2007-1358</cvename>
3408    </references>
3409    <dates>
3410      <discovery>2007-04-27</discovery>
3411      <entry>2007-07-24</entry>
3412    </dates>
3413  </vuln>
3414
3415  <vuln vid="cddde37a-39b5-11dc-b3da-001921ab2fa4">
3416    <topic>dokuwiki -- XSS vulnerability in spellchecker backend</topic>
3417    <affects>
3418      <package>
3419	<name>dokuwiki</name>
3420	<range><lt>20070626_1</lt></range>
3421      </package>
3422      <package>
3423	<name>dokuwiki-devel</name>
3424	<range><lt>20070524_1</lt></range>
3425      </package>
3426    </affects>
3427    <description>
3428      <body xmlns="http://www.w3.org/1999/xhtml">
3429	<p>DokuWiki reports:</p>
3430	<blockquote cite="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1195">
3431	  <p>The spellchecker tests the UTF-8 capabilities of the used browser
3432	    by sending an UTF-8 string to the backend, which will send it back
3433	    unfiltered.  By comparing string length the spellchecker can work
3434	    around broken implementations. An attacker could construct a form to
3435	    let users send JavaScript to the spellchecker backend, resulting in
3436	    malicious JavaScript being executed in their browser.</p>
3437	  <p>Affected are all versions up to and including 2007-06-26 even when
3438	    the spell checker is disabled.</p>
3439	</blockquote>
3440      </body>
3441    </description>
3442    <references>
3443      <url>http://xforce.iss.net/xforce/xfdb/35501</url>
3444      <cvename>CVE-2007-3930</cvename>
3445    </references>
3446    <dates>
3447      <discovery>2007-06-26</discovery>
3448      <entry>2007-07-24</entry>
3449    </dates>
3450  </vuln>
3451
3452  <vuln vid="fc9c217e-3791-11dc-bb1a-000fea449b8a">
3453    <topic>lighttpd -- multiple vulnerabilities</topic>
3454    <affects>
3455      <package>
3456	<name>lighttpd</name>
3457	<range><lt>1.4.15_1</lt></range>
3458      </package>
3459    </affects>
3460    <description>
3461      <body xmlns="http://www.w3.org/1999/xhtml">
3462	<p>Secunia Advisory reports:</p>
3463	<blockquote cite="http://secunia.com/advisories/26130/">
3464	  <p>Some vulnerabilities have been reported in lighttpd,
3465	    which can be exploited by malicious people to bypass
3466	    certain security restrictions or cause a DoS (Denial
3467	    of Service).</p>
3468	</blockquote>
3469      </body>
3470    </description>
3471    <references>
3472      <cvename>CVE-2007-3947</cvename>
3473      <cvename>CVE-2007-3948</cvename>
3474      <cvename>CVE-2007-3949</cvename>
3475      <cvename>CVE-2007-3950</cvename>
3476      <url>http://trac.lighttpd.net/trac/ticket/1216</url>
3477      <url>http://trac.lighttpd.net/trac/ticket/1232</url>
3478      <url>http://trac.lighttpd.net/trac/ticket/1230</url>
3479      <url>http://trac.lighttpd.net/trac/ticket/1263</url>
3480    </references>
3481    <dates>
3482      <discovery>2007-07-20</discovery>
3483      <entry>2007-07-21</entry>
3484      <modified>2010-05-12</modified>
3485    </dates>
3486  </vuln>
3487
3488  <vuln vid="12d266b6-363f-11dc-b6c9-000c6ec775d9">
3489    <topic>opera -- multiple vulnerabilities</topic>
3490    <affects>
3491      <package>
3492	<name>opera</name>
3493	<name>opera-devel</name>
3494	<name>linux-opera</name>
3495	<range><lt>9.22</lt></range>
3496      </package>
3497    </affects>
3498    <description>
3499      <body xmlns="http://www.w3.org/1999/xhtml">
3500	<p>Opera Software ASA reports of multiple security fixes in
3501	  Opera, including an arbitrary code execute
3502	  vulnerability:</p>
3503	<blockquote cite="http://www.opera.com/support/search/view/861/">
3504	  <p>Opera for Linux, FreeBSD, and Solaris has a flaw in the
3505	    createPattern function that leaves old data that was in
3506	    the memory before Opera allocated it in the new
3507	    pattern. The pattern can be read and analyzed by
3508	    JavaScript, so an attacker can get random samples of the
3509	    user's memory, which may contain data.</p>
3510	</blockquote>
3511	<blockquote cite="http://www.opera.com/support/search/view/862/">
3512	  <p>Removing a specially crafted torrent from the download
3513	    manager can crash Opera. The crash is caused by an
3514	    erroneous memory access.</p>
3515	  <p>An attacker needs to entice the user to accept the
3516	    malicious BitTorrent download, and later remove it from
3517	    Opera's download manager. To inject code, additional means
3518	    will have to be employed.</p>
3519	  <p>Users clicking a BitTorrent link and rejecting the
3520	    download are not affected.</p>
3521	</blockquote>
3522	<blockquote cite="http://www.opera.com/support/search/view/863/">
3523	  <p>data: URLs embed data inside them, instead of linking to
3524	    an external resource. Opera can mistakenly display the end
3525	    of a data URL instead of the beginning. This allows an
3526	    attacker to spoof the URL of a trusted site.</p>
3527	</blockquote>
3528	<blockquote cite="http://www.opera.com/support/search/view/864/">
3529	  <p>Opera's HTTP authentication dialog is displayed when the
3530	    user enters a Web page that requires a login name and a
3531	    password. To inform the user which server it was that
3532	    asked for login credentials, the dialog displays the
3533	    server name.</p>
3534	  <p>The user has to see the entire server name. A truncated
3535	    name can be misleading. Opera's authentication dialog cuts
3536	    off the long server names at the right hand side, adding
3537	    an ellipsis (...) to indicate that it has been cut off.</p>
3538	  <p>The dialog has a predictable size, allowing an attacker
3539	    to create a server name which will look almost like a
3540	    trusted site, because the real domain name has been cut
3541	    off. The three dots at the end will not be obvious to all
3542	    users.</p>
3543	  <p>This flaw can be exploited by phishers who can set up
3544	    custom sub-domains, for example by hosting their own
3545	    public DNS.</p>
3546	</blockquote>
3547      </body>
3548    </description>
3549    <references>
3550      <cvename>CVE-2007-3929</cvename>
3551      <cvename>CVE-2007-4944</cvename>
3552      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=564</url>
3553      <url>http://www.opera.com/support/search/view/861/</url>
3554      <url>http://www.opera.com/support/search/view/862/</url>
3555      <url>http://www.opera.com/support/search/view/863/</url>
3556      <url>http://www.opera.com/support/search/view/864/</url>
3557      <url>http://www.opera.com/docs/changelogs/freebsd/922/</url>
3558    </references>
3559    <dates>
3560      <discovery>2007-07-19</discovery>
3561      <entry>2007-07-19</entry>
3562      <modified>2010-05-12</modified>
3563    </dates>
3564  </vuln>
3565
3566  <vuln vid="e190ca65-3636-11dc-a697-000c6ec775d9">
3567    <topic>mozilla -- multiple vulnerabilities</topic>
3568    <affects>
3569      <package>
3570	<name>firefox</name>
3571	<range><lt>2.0.0.5,1</lt></range>
3572	<range><gt>3.*,1</gt><lt>3.0.a2_3,1</lt></range>
3573      </package>
3574      <package>
3575	<name>linux-firefox</name>
3576	<name>linux-thunderbird</name>
3577	<name>mozilla-thunderbird</name>
3578	<name>thunderbird</name>
3579	<range><lt>2.0.0.5</lt></range>
3580      </package>
3581      <!-- Packages which probably will be upgraded -->
3582      <package>
3583	<name>seamonkey</name>
3584	<name>linux-seamonkey</name>
3585	<range><lt>1.1.3</lt></range>
3586      </package>
3587      <package>
3588	<name>linux-firefox-devel</name>
3589	<range><lt>3.0.a2007.12.12</lt></range>
3590      </package>
3591      <package>
3592	<name>linux-seamonkey-devel</name>
3593	<range><lt>2.0.a2007.12.12</lt></range>
3594      </package>
3595      <!-- Deprecated/old names -->
3596      <package>
3597	<name>firefox-ja</name>
3598	<name>linux-mozilla-devel</name>
3599	<name>linux-mozilla</name>
3600	<name>mozilla</name>
3601	<range><gt>0</gt></range>
3602      </package>
3603    </affects>
3604    <description>
3605      <body xmlns="http://www.w3.org/1999/xhtml">
3606	<p>The Mozilla Foundation reports of multiple security issues
3607	  in Firefox, Seamonkey, and Thunderbird.  Several of these
3608	  issues can probably be used to run arbitrary code with the
3609	  privilege of the user running the program.</p>
3610	<blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.5">
3611	  <ul>
3612	    <li>MFSA 2007-25 XPCNativeWrapper pollution</li>
3613	    <li>MFSA 2007-24 Unauthorized access to wyciwyg:// documents</li>
3614	    <li>MFSA 2007-21 Privilege escalation using an event
3615	      handler attached to an element not in the document</li>
3616	    <li>MFSA 2007-20 Frame spoofing while window is loading</li>
3617	    <li>MFSA 2007-19 XSS using addEventListener and setTimeout</li>
3618	    <li>MFSA 2007-18 Crashes with evidence of memory corruption</li>
3619	  </ul>
3620	</blockquote>
3621      </body>
3622    </description>
3623    <references>
3624      <cvename>CVE-2007-3089</cvename>
3625      <cvename>CVE-2007-3734</cvename>
3626      <cvename>CVE-2007-3735</cvename>
3627      <cvename>CVE-2007-3737</cvename>
3628      <cvename>CVE-2007-3738</cvename>
3629      <url>http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.5</url>
3630      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-18.html</url>
3631      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-19.html</url>
3632      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-20.html</url>
3633      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-21.html</url>
3634      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-24.html</url>
3635      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-25.html</url>
3636      <uscertta>TA07-199A</uscertta>
3637    </references>
3638    <dates>
3639      <discovery>2007-07-17</discovery>
3640      <entry>2007-07-19</entry>
3641      <modified>2008-06-21</modified>
3642    </dates>
3643  </vuln>
3644
3645  <vuln vid="b42e8c32-34f6-11dc-9bc9-001921ab2fa4">
3646    <topic>linux-flashplugin -- critical vulnerabilities</topic>
3647    <affects>
3648      <package>
3649	<name>linux-flashplugin</name>
3650	<range><gt>9.0</gt><le>9.0r45</le></range>
3651	<range><gt>8.0</gt><le>8.0r34</le></range>
3652	<range><le>7.0r69</le></range>
3653      </package>
3654    </affects>
3655    <description>
3656      <body xmlns="http://www.w3.org/1999/xhtml">
3657	<p>Adobe reports:</p>
3658	<blockquote cite="http://www.adobe.com/support/security/bulletins/apsb07-12.html">
3659	  <p>Critical vulnerabilities have been identified in
3660	    Adobe Flash Player that could allow an attacker who
3661	    successfully exploits these potential vulnerabilities
3662	    to take control of the affected system. A malicious
3663	    SWF must be loaded in Flash Player by the user for
3664	    an attacker to exploit these potential vulnerabilities.</p>
3665	</blockquote>
3666      </body>
3667    </description>
3668    <references>
3669      <cvename>CVE-2007-2022</cvename>
3670      <cvename>CVE-2007-3456</cvename>
3671      <cvename>CVE-2007-3457</cvename>
3672    </references>
3673    <dates>
3674      <discovery>2007-07-10</discovery>
3675      <entry>2007-07-18</entry>
3676    </dates>
3677  </vuln>
3678
3679  <vuln vid="7fadc049-2ba0-11dc-9377-0016179b2dd5">
3680    <topic>wireshark -- Multiple problems</topic>
3681    <affects>
3682      <package>
3683	<name>wireshark</name>
3684	<name>wireshark-lite</name>
3685	<name>ethereal</name>
3686	<name>ethereal-lite</name>
3687	<name>tethereal</name>
3688	<name>tethereal-lite</name>
3689	<range><ge>0.8.20</ge><lt>0.99.6</lt></range>
3690      </package>
3691    </affects>
3692    <description>
3693      <body xmlns="http://www.w3.org/1999/xhtml">
3694	<p>wireshark Team reports:</p>
3695	<blockquote cite="http://www.wireshark.org/security/wnpa-sec-2007-02.html">
3696	  <p>It may be possible to make Wireshark or Ethereal crash or use up
3697	    available memory by injecting a purposefully malformed packet onto
3698	    the wire or by convincing someone to read a malformed packet trace
3699	    file.</p>
3700	</blockquote>
3701      </body>
3702    </description>
3703    <references>
3704      <cvename>CVE-2007-3389</cvename>
3705      <cvename>CVE-2007-3390</cvename>
3706      <cvename>CVE-2007-3391</cvename>
3707      <cvename>CVE-2007-3392</cvename>
3708      <cvename>CVE-2007-3393</cvename>
3709      <url>http://secunia.com/advisories/25833/</url>
3710      <url>http://www.wireshark.org/security/wnpa-sec-2007-02.html</url>
3711    </references>
3712    <dates>
3713      <discovery>2007-06-29</discovery>
3714      <entry>2007-07-06</entry>
3715      <modified>2010-05-12</modified>
3716    </dates>
3717  </vuln>
3718
3719  <vuln vid="2c4f4688-298b-11dc-a197-0011098b2f36">
3720    <topic>typespeed -- arbitrary code execution</topic>
3721    <affects>
3722      <package>
3723	<name>typespeed</name>
3724	<range><le>0.4.1</le></range>
3725      </package>
3726    </affects>
3727    <description>
3728      <body xmlns="http://www.w3.org/1999/xhtml">
3729	<p>Debian reports:</p>
3730	<blockquote cite="http://www.debian.org/security/2005/dsa-684">
3731	  <p>Ulf Härnhammar from the Debian Security Audit Project
3732	    discovered a problem in typespeed, a touch-typist trainer
3733	    disguised as game.	This could lead to a local attacker
3734	    executing arbitrary code.</p>
3735	</blockquote>
3736      </body>
3737    </description>
3738    <references>
3739      <cvename>CVE-2005-0105</cvename>
3740      <url>http://www.debian.org/security/2005/dsa-684</url>
3741    </references>
3742    <dates>
3743      <discovery>2005-02-16</discovery>
3744      <entry>2007-07-03</entry>
3745      <modified>2007-07-09</modified>
3746    </dates>
3747  </vuln>
3748
3749  <vuln vid="7128fb45-2633-11dc-94da-0016179b2dd5">
3750    <topic>vlc -- format string vulnerability and integer overflow</topic>
3751    <affects>
3752      <package>
3753	<name>vlc</name>
3754	<range><lt>0.8.6c</lt></range>
3755      </package>
3756    </affects>
3757    <description>
3758      <body xmlns="http://www.w3.org/1999/xhtml">
3759	<p>isecpartners reports:</p>
3760	<blockquote cite="http://www.isecpartners.com/advisories/2007-001-vlc.txt">
3761	  <p>VLC is vulnerable to a format string attack in the parsing
3762	    of Vorbis comments in Ogg Vorbis and Ogg Theora files, CDDA
3763	    data or SAP/SDP service discovery messages. Additionally,
3764	    there are two errors in the handling of wav files, one a
3765	    denial of service due to an uninitialized variable, and one
3766	    integer overflow in sampling frequency calculations.</p>
3767	</blockquote>
3768      </body>
3769    </description>
3770    <references>
3771      <cvename>CVE-2007-3316</cvename>
3772      <cvename>CVE-2007-3468</cvename>
3773      <cvename>CVE-2007-3467</cvename>
3774      <url>http://www.isecpartners.com/advisories/2007-001-vlc.txt</url>
3775    </references>
3776    <dates>
3777      <discovery>2007-06-05</discovery>
3778      <entry>2007-06-18</entry>
3779      <modified>2010-05-12</modified>
3780    </dates>
3781  </vuln>
3782
3783  <vuln vid="32d38cbb-2632-11dc-94da-0016179b2dd5">
3784    <topic>flac123 -- stack overflow in comment parsing</topic>
3785    <affects>
3786      <package>
3787	<name>flac123</name>
3788	<range><lt>0.0.10</lt></range>
3789      </package>
3790    </affects>
3791    <description>
3792      <body xmlns="http://www.w3.org/1999/xhtml">
3793	<p>isecpartners reports:</p>
3794	<blockquote cite="http://www.isecpartners.com/advisories/2007-002-flactools.txt">
3795	  <p>flac123, also known as flac-tools, is vulnerable
3796	    to a buffer overflow in vorbis comment parsing.
3797	    This allows for the execution of arbitrary code.</p>
3798	</blockquote>
3799      </body>
3800    </description>
3801    <references>
3802      <cvename>CVE-2007-3507</cvename>
3803      <url>http://sourceforge.net/forum/forum.php?forum_id=710314</url>
3804      <url>http://www.isecpartners.com/advisories/2007-002-flactools.txt</url>
3805    </references>
3806    <dates>
3807      <discovery>2007-06-05</discovery>
3808      <entry>2007-06-28</entry>
3809      <modified>2007-08-10</modified>
3810    </dates>
3811  </vuln>
3812
3813  <vuln vid="6e099997-25d8-11dc-878b-000c29c5647f">
3814    <topic>gd -- multiple vulnerabilities</topic>
3815    <affects>
3816      <package>
3817	<name>gd</name>
3818	<range><lt>2.0.35,1</lt></range>
3819      </package>
3820    </affects>
3821    <description>
3822      <body xmlns="http://www.w3.org/1999/xhtml">
3823	<p>gd had been reported vulnerable to several
3824	  vulnerabilities:</p>
3825	<ul>
3826	  <li>CVE-2007-3472: Integer overflow in gdImageCreateTrueColor
3827	    function in the GD Graphics Library (libgd) before 2.0.35
3828	    allows user-assisted remote attackers has unspecified attack
3829	    vectors and impact.</li>
3830	  <li>CVE-2007-3473: The gdImageCreateXbm function in the GD
3831	    Graphics Library (libgd) before 2.0.35 allows user-assisted
3832	    remote attackers to cause a denial of service (crash) via
3833	    unspecified vectors involving a gdImageCreate failure.</li>
3834	  <li>CVE-2007-3474: Multiple unspecified vulnerabilities in the GIF
3835	    reader in the GD Graphics Library (libgd) before 2.0.35 allow
3836	    user-assisted remote attackers to have unspecified attack vectors
3837	    and impact.</li>
3838	  <li>CVE-2007-3475: The GD Graphics Library (libgd) before 2.0.35
3839	    allows user-assisted remote attackers to cause a denial of service
3840	    (crash) via a GIF image that has no global color map.</li>
3841	  <li>CVE-2007-3476: Array index error in gd_gif_in.c in the GD Graphics
3842	    Library (libgd) before 2.0.35 allows user-assisted remote attackers
3843	    to cause a denial of service (crash and heap corruption) via large
3844	    color index values in crafted image data, which results in a
3845	    segmentation fault.</li>
3846	  <li>CVE-2007-3477: The (a) imagearc and (b) imagefilledarc functions
3847	    in GD Graphics Library (libgd) before 2.0.35 allows attackers to
3848	    cause a denial of service (CPU consumption) via a large (1) start or
3849	    (2) end angle degree value.</li>
3850	  <li>CVE-2007-3478: Race condition in gdImageStringFTEx
3851	    (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd)
3852	    before 2.0.35 allows user-assisted remote attackers to cause a
3853	    denial of service (crash) via unspecified vectors, possibly
3854	    involving truetype font (TTF) support.</li>
3855	</ul>
3856      </body>
3857    </description>
3858    <references>
3859      <cvename>CVE-2007-3472</cvename>
3860      <cvename>CVE-2007-3473</cvename>
3861      <cvename>CVE-2007-3474</cvename>
3862      <cvename>CVE-2007-3475</cvename>
3863      <cvename>CVE-2007-3476</cvename>
3864      <cvename>CVE-2007-3477</cvename>
3865      <cvename>CVE-2007-3478</cvename>
3866      <url>http://www.libgd.org/ReleaseNote020035</url>
3867      <url>http://www.frsirt.com/english/advisories/2007/2336</url>
3868      <url>http://bugs.libgd.org/?do=details&amp;task_id=89</url>
3869      <url>http://bugs.libgd.org/?do=details&amp;task_id=94</url>
3870      <url>http://bugs.libgd.org/?do=details&amp;task_id=70</url>
3871      <url>http://bugs.libgd.org/?do=details&amp;task_id=87</url>
3872      <url>http://bugs.libgd.org/?do=details&amp;task_id=92</url>
3873      <url>http://bugs.libgd.org/?do=details&amp;task_id=74</url>
3874      <url>http://bugs.libgd.org/?do=details&amp;task_id=48</url>
3875      <url>http://bugs.php.net/bug.php?id=40578</url>
3876    </references>
3877    <dates>
3878      <discovery>2007-06-21</discovery>
3879      <entry>2007-06-29</entry>
3880    </dates>
3881  </vuln>
3882
3883  <vuln vid="b1b5c125-2308-11dc-b91a-001921ab2fa4">
3884    <topic>evolution-data-server -- remote execution of arbitrary code vulnerability</topic>
3885    <affects>
3886      <package>
3887	<name>evolution-data-server</name>
3888	<range><lt>1.10.2_1</lt></range>
3889	<range><gt>1.11.*</gt><lt>1.11.4</lt></range>
3890      </package>
3891    </affects>
3892    <description>
3893      <body xmlns="http://www.w3.org/1999/xhtml">
3894	<p>Debian project reports:</p>
3895	<blockquote cite="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00082.html">
3896	  <p>It was discovered that the IMAP code in the Evolution
3897	    Data Server performs insufficient sanitising of a value
3898	    later used an array index, which can lead to the execution
3899	    of arbitrary code.</p>
3900	</blockquote>
3901      </body>
3902    </description>
3903    <references>
3904      <cvename>CVE-2007-3257</cvename>
3905      <url>http://secunia.com/advisories/25766/</url>
3906      <url>http://bugzilla.gnome.org/show_bug.cgi?id=447414</url>
3907    </references>
3908    <dates>
3909      <discovery>2007-06-23</discovery>
3910      <entry>2007-06-25</entry>
3911      <modified>2007-06-28</modified>
3912    </dates>
3913  </vuln>
3914
3915  <vuln vid="d337b206-200f-11dc-a197-0011098b2f36">
3916    <topic>xpcd -- buffer overflow</topic>
3917    <affects>
3918      <package>
3919	<name>xpcd</name>
3920	<range><gt>0</gt></range>
3921      </package>
3922    </affects>
3923    <description>
3924      <body xmlns="http://www.w3.org/1999/xhtml">
3925	<p>Debian Project reports:</p>
3926	<blockquote cite="http://www.debian.org/security/2005/dsa-676">
3927	  <p>Erik Sjolund discovered a buffer overflow in pcdsvgaview,
3928	    an SVGA PhotoCD viewer.  xpcd-svga is part of xpcd and uses
3929	    svgalib to display graphics on the Linux console for which
3930	    root permissions are required.  A malicious user could
3931	    overflow a fixed-size buffer and may cause the program to
3932	    execute arbitrary code with elevated privileges.</p>
3933	</blockquote>
3934      </body>
3935    </description>
3936    <references>
3937      <bid>12523</bid>
3938      <cvename>CVE-2005-0074</cvename>
3939      <url>http://www.debian.org/security/2005/dsa-676</url>
3940    </references>
3941    <dates>
3942      <discovery>2005-02-11</discovery>
3943      <entry>2007-06-21</entry>
3944    </dates>
3945  </vuln>
3946
3947  <vuln vid="903654bd-1927-11dc-b8a0-02e0185f8d72">
3948    <topic>clamav -- multiple vulnerabilities</topic>
3949    <affects>
3950      <package>
3951	<name>clamav</name>
3952	<range><lt>0.90.3</lt></range>
3953      </package>
3954    </affects>
3955    <description>
3956      <body xmlns="http://www.w3.org/1999/xhtml">
3957	<p>Clamav had been found vulnerable to multiple vulnerabilities:</p>
3958	<ul>
3959	  <li>Improper checking for the end of an buffer causing an
3960	    unspecified attack vector.</li>
3961	  <li>Insecure temporary file handling, which could be exploited
3962	    to read sensitive information.</li>
3963	  <li>A flaw in the parser engine which could allow a remote
3964	    attacker to bypass the scanning of RAR files.</li>
3965	  <li>A flaw in libclamav/unrar.c which could cause a remote
3966	    Denial of Service (DoS) by sending a specially crafted
3967	    RAR file with a modified vm_codesize.</li>
3968	  <li>A flaw in the OLE2 parser which could cause a remote
3969	    Denial of Service (DoS).</li>
3970	</ul>
3971      </body>
3972    </description>
3973    <references>
3974      <cvename>CVE-2007-2650</cvename>
3975      <cvename>CVE-2007-3023</cvename>
3976      <cvename>CVE-2007-3024</cvename>
3977      <cvename>CVE-2007-3122</cvename>
3978      <cvename>CVE-2007-3123</cvename>
3979      <url>http://news.gmane.org/gmane.comp.security.virus.clamav.devel/cutoff=2853</url>
3980    </references>
3981    <dates>
3982      <discovery>2007-04-18</discovery>
3983      <entry>2007-06-19</entry>
3984    </dates>
3985  </vuln>
3986
3987  <vuln vid="8092b820-1d6f-11dc-a0b2-001921ab2fa4">
3988    <topic>p5-Mail-SpamAssassin -- local user symlink-attack DoS vulnerability</topic>
3989    <affects>
3990      <package>
3991	<name>p5-Mail-SpamAssassin</name>
3992	<range><lt>3.2.1</lt></range>
3993      </package>
3994    </affects>
3995    <description>
3996      <body xmlns="http://www.w3.org/1999/xhtml">
3997	<p>SpamAssassin website reports:</p>
3998	<blockquote cite="http://spamassassin.apache.org/advisories/cve-2007-2873.txt">
3999	  <p>A local user symlink-attack DoS vulnerability in
4000	    SpamAssassin has been found, affecting versions 3.1.x,
4001	    3.2.0, and SVN trunk.</p>
4002	</blockquote>
4003      </body>
4004    </description>
4005    <references>
4006      <url>http://spamassassin.apache.org/advisories/cve-2007-2873.txt</url>
4007      <cvename>CVE-2007-2873</cvename>
4008    </references>
4009    <dates>
4010      <discovery>2007-06-11</discovery>
4011      <entry>2007-06-18</entry>
4012    </dates>
4013  </vuln>
4014
4015  <vuln vid="39988ee8-1918-11dc-b6bd-0016179b2dd5">
4016    <topic>cups -- Incomplete SSL Negotiation Denial of Service</topic>
4017    <affects>
4018      <package>
4019	<name>cups-base</name>
4020	<range><lt>1.2.11</lt></range>
4021      </package>
4022    </affects>
4023    <description>
4024      <body xmlns="http://www.w3.org/1999/xhtml">
4025	<p>Secunia reports:</p>
4026	<blockquote cite="http://secunia.com/advisories/24517/">
4027	  <p>CUPS is not using multiple workers to handle connections.
4028	    This can be exploited to stop CUPS from accepting new connections
4029	    by starting but never completing an SSL negotiation.</p>
4030	</blockquote>
4031      </body>
4032    </description>
4033    <references>
4034      <url>http://secunia.com/advisories/24517/</url>
4035      <url>http://security.gentoo.org/glsa/glsa-200703-28.xml</url>
4036      <cvename>CVE-2007-0720</cvename>
4037    </references>
4038    <dates>
4039      <discovery>2007-05-05</discovery>
4040      <entry>2007-06-12</entry>
4041    </dates>
4042  </vuln>
4043
4044  <vuln vid="70ae62b0-16b0-11dc-b803-0016179b2dd5">
4045    <topic>c-ares -- DNS Cache Poisoning Vulnerability</topic>
4046    <affects>
4047      <package>
4048	<name>c-ares</name>
4049	<range><lt>1.4.0</lt></range>
4050      </package>
4051    </affects>
4052    <description>
4053      <body xmlns="http://www.w3.org/1999/xhtml">
4054	<p>Secunia reports:</p>
4055	<blockquote cite="http://secunia.com/advisories/25579/">
4056	  <p>The vulnerability is caused due to predictable
4057	    DNS "Transaction ID" field in DNS queries and can
4058	    be exploited to poison the DNS cache of an application
4059	    using the library if a valid ID is guessed.</p>
4060	</blockquote>
4061      </body>
4062    </description>
4063    <references>
4064      <cvename>CVE-2007-3152</cvename>
4065      <cvename>CVE-2007-3153</cvename>
4066      <url>http://secunia.com/advisories/25579/</url>
4067      <url>http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&amp;content-type=text/vnd.viewcvs-markup</url>
4068    </references>
4069    <dates>
4070      <discovery>2007-06-08</discovery>
4071      <entry>2007-06-09</entry>
4072      <modified>2010-05-12</modified>
4073    </dates>
4074  </vuln>
4075
4076  <vuln vid="0838733d-1698-11dc-a197-0011098b2f36">
4077    <topic>wordpress -- XMLRPC SQL Injection</topic>
4078    <affects>
4079      <package>
4080	<name>wordpress</name>
4081	<name>de-wordpress</name>
4082	<name>zh-wordpress</name>
4083	<range><lt>2.2.1</lt></range>
4084      </package>
4085    </affects>
4086    <description>
4087      <body xmlns="http://www.w3.org/1999/xhtml">
4088	<p>Secunia reports:</p>
4089	<blockquote cite="http://secunia.com/advisories/25552/">
4090	  <p>Slappter has discovered a vulnerability in WordPress, which can
4091	    be exploited by malicious users to conduct SQL injection
4092	    attacks.</p>
4093	  <p>Input passed to the "wp.suggestCategories" method in xmlrpc.php
4094	    is not properly sanitised before being used in SQL queries.  This
4095	    can be exploited to manipulate SQL queries by injecting arbitrary
4096	    SQL code.</p>
4097	  <p>Successful exploitation allows e.g. retrieving usernames and
4098	    password hashes, but requires valid user credentials and knowledge
4099	    of the database table prefix.</p>
4100	</blockquote>
4101      </body>
4102    </description>
4103    <references>
4104      <bid>24344</bid>
4105      <url>http://secunia.com/advisories/25552/</url>
4106    </references>
4107    <dates>
4108      <discovery>2007-06-06</discovery>
4109      <entry>2007-06-09</entry>
4110      <modified>2007-06-24</modified>
4111    </dates>
4112  </vuln>
4113
4114  <vuln vid="6a31cbe3-1695-11dc-a197-0011098b2f36">
4115    <topic>wordpress -- unmoderated comments disclosure</topic>
4116    <affects>
4117      <package>
4118	<name>wordpress</name>
4119	<name>de-wordpress</name>
4120	<name>zh-wordpress</name>
4121	<range><lt>2.2.2</lt></range>
4122      </package>
4123    </affects>
4124    <description>
4125      <body xmlns="http://www.w3.org/1999/xhtml">
4126	<p>Blogsecurity reports:</p>
4127	<blockquote cite="http://blogsecurity.net/news/news-310507/">
4128	  <p>An attacker can read comments on posts that have not been
4129	    moderated.	This can be a real security risk if blog admins
4130	    are using unmoderated comments (comments that have not been
4131	    made public) to hide sensitive notes regarding posts, future
4132	    work, passwords etc.  So please be careful if you are one of
4133	    these blog admins.</p>
4134	</blockquote>
4135      </body>
4136    </description>
4137    <references>
4138      <url>http://blogsecurity.net/news/news-310507/</url>
4139    </references>
4140    <dates>
4141      <discovery>2007-06-01</discovery>
4142      <entry>2007-06-09</entry>
4143      <modified>2007-08-16</modified>
4144    </dates>
4145  </vuln>
4146
4147  <vuln vid="12b7286f-16a2-11dc-b803-0016179b2dd5">
4148    <topic>webmin -- cross site scripting vulnerability</topic>
4149    <affects>
4150      <package>
4151	<name>webmin</name>
4152	<range><lt>1.350</lt></range>
4153      </package>
4154    </affects>
4155    <description>
4156      <body xmlns="http://www.w3.org/1999/xhtml">
4157	<p>Secunia reports:</p>
4158	<blockquote cite="http://secunia.com/advisories/25580/">
4159	  <p>Input passed to unspecified parameters in pam_login.cgi
4160	    is not properly sanitised before being returned to the
4161	    user. This can be exploited to execute arbitrary HTML and
4162	    script code in a user's browser session in context of an
4163	    affected site.</p>
4164	</blockquote>
4165      </body>
4166    </description>
4167    <references>
4168      <bid>24381</bid>
4169      <cvename>CVE-2007-3156</cvename>
4170      <url>http://secunia.com/advisories/25580/</url>
4171      <url>http://www.webmin.com/changes-1.350.html</url>
4172    </references>
4173    <dates>
4174      <discovery>2007-06-01</discovery>
4175      <entry>2007-06-09</entry>
4176      <modified>2010-05-12</modified>
4177    </dates>
4178  </vuln>
4179
4180  <vuln vid="3ac80dd2-14df-11dc-bcfc-0016179b2dd5">
4181    <topic>mplayer -- cddb stack overflow</topic>
4182    <affects>
4183      <package>
4184	<name>mplayer</name>
4185	<name>mplayer-esound</name>
4186	<name>mplayer-gtk</name>
4187	<name>mplayer-gtk2</name>
4188	<name>mplayer-gtk-esound</name>
4189	<name>mplayer-gtk2-esound</name>
4190	<range><lt>0.99.10_10</lt></range>
4191      </package>
4192    </affects>
4193    <description>
4194      <body xmlns="http://www.w3.org/1999/xhtml">
4195	<p>Mplayer Team reports:</p>
4196	<blockquote cite="http://www.mplayerhq.hu/design7/news.html">
4197	  <p>A stack overflow was found in the code used to handle
4198	    cddb queries.  When copying the album title and category,
4199	    no checking was performed on the size of the strings
4200	    before storing them in a fixed-size array.	A malicious
4201	    entry in the database could trigger a stack overflow in
4202	    the program, leading to arbitrary code execution with the
4203	    uid of the user running MPlayer.</p>
4204	</blockquote>
4205      </body>
4206    </description>
4207    <references>
4208      <bid>24302</bid>
4209      <cvename>CVE-2007-2948</cvename>
4210    </references>
4211    <dates>
4212      <discovery>2007-06-06</discovery>
4213      <entry>2007-06-07</entry>
4214    </dates>
4215  </vuln>
4216
4217  <vuln vid="d9405748-1342-11dc-a35c-001485ab073e">
4218    <topic>mod_jk -- information disclosure</topic>
4219    <affects>
4220      <package>
4221	<name>mod_jk</name>
4222	<range><lt>1.2.23,1</lt></range>
4223      </package>
4224      <package>
4225	<name>mod_jk-ap2</name>
4226	<range><lt>1.2.23</lt></range>
4227      </package>
4228    </affects>
4229    <description>
4230      <body xmlns="http://www.w3.org/1999/xhtml">
4231	<p>Kazu Nambo reports:</p>
4232	<blockquote cite="http://tomcat.apache.org/security-jk.html">
4233	  <p>URL decoding the the Apache webserver prior to
4234	    decoding in the Tomcat server could pypass access
4235	    control rules and give access to pages on a different
4236	    AJP by sending a crafted URL.</p>
4237	</blockquote>
4238      </body>
4239    </description>
4240    <references>
4241      <cvename>CVE-2007-1860</cvename>
4242      <url>http://secunia.com/advisories/25383/</url>
4243      <url>http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1</url>
4244      <url>http://tomcat.apache.org/security-jk.html</url>
4245    </references>
4246    <dates>
4247      <discovery>2007-05-18</discovery>
4248      <entry>2007-06-05</entry>
4249      <modified>2007-10-31</modified>
4250    </dates>
4251  </vuln>
4252
4253  <vuln vid="62b8f253-12d9-11dc-a35c-001485ab073e">
4254    <topic>typo3 -- email header injection</topic>
4255    <affects>
4256      <package>
4257	<name>typo3</name>
4258	<range><gt>3.0</gt><lt>4.0.5</lt></range>
4259	<range><gt>4.1</gt><lt>4.1.1</lt></range>
4260      </package>
4261    </affects>
4262    <description>
4263      <body xmlns="http://www.w3.org/1999/xhtml">
4264	<p>Olivier Dobberkau, Andreas Otto, and Thorsten Kahler report:</p>
4265	<blockquote cite="http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/">
4266	  <p>An unspecified error in the internal form engine can be used for
4267	    sending arbitrary mail headers, using it for purposes which it
4268	    is not meant for, e.g. sending spam messages.</p>
4269	</blockquote>
4270      </body>
4271    </description>
4272    <references>
4273      <cvename>CVE-2007-1081</cvename>
4274      <url>http://secunia.com/advisories/24207/</url>
4275      <url>http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/</url>
4276    </references>
4277    <dates>
4278      <discovery>2007-02-21</discovery>
4279      <entry>2007-06-04</entry>
4280    </dates>
4281  </vuln>
4282
4283  <vuln vid="3d0e724e-129b-11dc-9f79-0016179b2dd5">
4284    <topic>phppgadmin -- cross site scripting vulnerability</topic>
4285    <affects>
4286      <package>
4287	<name>phppgadmin</name>
4288	<range><lt>4.1.1</lt></range>
4289      </package>
4290    </affects>
4291    <description>
4292      <body xmlns="http://www.w3.org/1999/xhtml">
4293	<p>SecurityFocus reports about phppgadmin:</p>
4294	<blockquote cite="http://www.securityfocus.com/bid/24115/info">
4295	  <p>Exploiting this vulnerability may allow an attacker to perform
4296	    cross-site scripting attacks on unsuspecting users in the context
4297	    of the affected website. As a result, the attacker may be able to
4298	    steal cookie-based authentication credentials and to launch other
4299	    attacks.</p>
4300	</blockquote>
4301      </body>
4302    </description>
4303    <references>
4304      <bid>24115</bid>
4305      <cvename>CVE-2007-5728</cvename>
4306      <url>http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html</url>
4307      <url>http://secunia.com/advisories/25446/</url>
4308    </references>
4309    <dates>
4310      <discovery>2007-05-27</discovery>
4311      <entry>2007-06-04</entry>
4312      <modified>2010-05-12</modified>
4313    </dates>
4314  </vuln>
4315
4316  <vuln vid="7ca2a709-103b-11dc-8e82-00001cd613f9">
4317    <topic>findutils -- GNU locate heap buffer overrun</topic>
4318    <affects>
4319      <package>
4320	<name>findutils</name>
4321	<range><lt>4.2.31</lt></range>
4322      </package>
4323    </affects>
4324    <description>
4325      <body xmlns="http://www.w3.org/1999/xhtml">
4326	<p>James Youngman reports:</p>
4327	<blockquote cite="http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html">
4328	  <p>When GNU locate reads filenames from an old-format locate database,
4329	    they are read into a fixed-length buffer allocated on the heap.
4330	    Filenames longer than the 1026-byte buffer can cause a buffer
4331	    overrun.  The overrunning data can be chosen by any person able to
4332	    control the names of filenames created on the local system.  This
4333	    will normally include all local users, but in many cases also remote
4334	    users (for example in the case of FTP servers allowing uploads).</p>
4335	</blockquote>
4336      </body>
4337    </description>
4338    <references>
4339      <cvename>CVE-2007-2452</cvename>
4340      <mlist>http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html</mlist>
4341    </references>
4342    <dates>
4343      <discovery>2007-05-30</discovery>
4344      <entry>2007-06-01</entry>
4345    </dates>
4346  </vuln>
4347
4348  <vuln vid="de2fab2d-0a37-11dc-aae2-00304881ac9a">
4349    <topic>FreeType 2 -- Heap overflow vulnerability</topic>
4350    <affects>
4351      <package>
4352	<name>freetype2</name>
4353	<range><lt>2.2.1_2</lt></range>
4354      </package>
4355    </affects>
4356    <description>
4357      <body xmlns="http://www.w3.org/1999/xhtml">
4358  <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2754">
4359    <p>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and
4360      earlier might allow remote attackers to execute arbitrary code via a
4361      crafted TTF image with a negative n_points value, which leads to an
4362      integer overflow and heap-based buffer overflow.</p>
4363  </blockquote>
4364      </body>
4365    </description>
4366    <references>
4367      <cvename>CVE-2007-2754</cvename>
4368      <mlist>http://lists.gnu.org/archive/html/freetype-devel/2007-04/msg00041.html</mlist>
4369      <url>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2754</url>
4370      <url>https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240200</url>
4371      <freebsdpr>ports/112769</freebsdpr>
4372    </references>
4373    <dates>
4374      <discovery>2007-04-27</discovery>
4375      <entry>2007-05-24</entry>
4376    </dates>
4377  </vuln>
4378
4379  <vuln vid="8e01ab5b-0949-11dc-8163-000e0c2e438a">
4380    <topic>FreeBSD -- heap overflow in file(1)</topic>
4381    <affects>
4382      <package>
4383	<name>file</name>
4384	<range><lt>4.21</lt></range>
4385      </package>
4386      <package>
4387	<name>FreeBSD</name>
4388	<range><ge>6.2</ge><lt>6.2_5</lt></range>
4389	<range><ge>6.1</ge><lt>6.1_17</lt></range>
4390	<range><ge>5.5</ge><lt>5.5_13</lt></range>
4391      </package>
4392    </affects>
4393    <description>
4394      <body xmlns="http://www.w3.org/1999/xhtml">
4395	<h1>Problem Description:</h1>
4396	<p>When writing data into a buffer in the file_printf function,
4397	  the length of the unused portion of the buffer is not
4398	  correctly tracked, resulting in a buffer overflow when
4399	  processing certain files.</p>
4400	<h1>Impact:</h1>
4401	<p>An attacker who can cause file(1) to be run on a maliciously
4402	  constructed input can cause file(1) to crash.  It may be
4403	  possible for such an attacker to execute arbitrary code with
4404	  the privileges of the user running file(1).</p>
4405	<p>The above also applies to any other applications using the
4406	  libmagic(3) library.</p>
4407	<h1>Workaround:</h1>
4408	<p>No workaround is available, but systems where file(1) and
4409	  other libmagic(3)-using applications are never run on
4410	  untrusted input are not vulnerable.</p>
4411      </body>
4412    </description>
4413    <references>
4414      <cvename>CVE-2007-1536</cvename>
4415      <freebsdsa>SA-07:04.file</freebsdsa>
4416    </references>
4417    <dates>
4418      <discovery>2007-05-23</discovery>
4419      <entry>2007-05-23</entry>
4420      <modified>2016-08-09</modified>
4421    </dates>
4422  </vuln>
4423
4424  <vuln vid="0e575ed3-0764-11dc-a80b-0016179b2dd5">
4425    <topic>squirrelmail -- Cross site scripting in HTML filter</topic>
4426    <affects>
4427      <package>
4428	<name>squirrelmail</name>
4429	<range><ge>1.4.0</ge><lt>1.4.9a</lt></range>
4430      </package>
4431    </affects>
4432    <description>
4433      <body xmlns="http://www.w3.org/1999/xhtml">
4434	<p>The SquirrelMail developers report:</p>
4435	<blockquote cite="http://www.squirrelmail.org/security/issue/2007-05-09">
4436	  <p>Multiple cross-site scripting (XSS) vulnerabilities in the HTML
4437	    filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers
4438	    to inject arbitrary web script or HTML via the (1) data: URI in an
4439	    HTML e-mail attachment or (2) various non-ASCII character sets that
4440	    are not properly filtered when viewed with Microsoft Internet
4441	    Explorer.</p>
4442	</blockquote>
4443      </body>
4444    </description>
4445    <references>
4446     <cvename>CVE-2007-1262</cvename>
4447     <url>http://www.squirrelmail.org/security/issue/2007-05-09</url>
4448    </references>
4449    <dates>
4450      <discovery>2007-05-09</discovery>
4451      <entry>2007-05-21</entry>
4452    </dates>
4453  </vuln>
4454
4455  <vuln vid="4cb9c513-03ef-11dc-a51d-0019b95d4f14">
4456    <topic>png -- DoS crash vulnerability</topic>
4457    <affects>
4458      <package>
4459	<name>png</name>
4460	<range><lt>1.2.17</lt></range>
4461      </package>
4462    </affects>
4463    <description>
4464      <body xmlns="http://www.w3.org/1999/xhtml">
4465	<p>A Libpng Security Advisory reports:</p>
4466	<blockquote cite="http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt">
4467	  <p>A grayscale PNG image with a malformed (bad CRC) tRNS
4468	    chunk will crash some libpng applications.</p>
4469	  <p>This vulnerability could be used to crash a browser when
4470	    a user tries to view such a malformed PNG file.  It is not
4471	    known whether the vulnerability could be exploited
4472	    otherwise.</p>
4473	</blockquote>
4474      </body>
4475    </description>
4476    <references>
4477      <cvename>CVE-2007-2445</cvename>
4478      <certvu>684664</certvu>
4479      <url>http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt</url>
4480    </references>
4481    <dates>
4482      <discovery>2007-05-15</discovery>
4483      <entry>2007-05-16</entry>
4484    </dates>
4485  </vuln>
4486
4487  <vuln vid="3546a833-03ea-11dc-a51d-0019b95d4f14">
4488    <topic>samba -- multiple vulnerabilities</topic>
4489    <affects>
4490      <package>
4491	<name>samba</name>
4492	<name>ja-samba</name>
4493	<range><gt>3.*</gt><lt>3.0.25</lt></range>
4494	<range><gt>3.*,1</gt><lt>3.0.25,1</lt></range>
4495      </package>
4496    </affects>
4497    <description>
4498      <body xmlns="http://www.w3.org/1999/xhtml">
4499	<p>The Samba Team reports:</p>
4500	<blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2444.html">
4501	  <p>A bug in the local SID/Name translation routines may
4502	    potentially result in a user being able to issue SMB/CIFS
4503	    protocol operations as root.</p>
4504	  <p>When translating SIDs to/from names using Samba local
4505	    list of user and group accounts, a logic error in the smbd
4506	    daemon's internal security stack may result in a
4507	    transition to the root user id rather than the non-root
4508	    user.  The user is then able to temporarily issue SMB/CIFS
4509	    protocol operations as the root user.  This window of
4510	    opportunity may allow the attacker to establish additional
4511	    means of gaining root access to the server.</p>
4512	</blockquote>
4513	<blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2446.html">
4514	  <p>Various bugs in Samba's NDR parsing can allow a user to
4515	    send specially crafted MS-RPC requests that will overwrite
4516	    the heap space with user defined data.</p>
4517	</blockquote>
4518	<blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2447.html">
4519	  <p>Unescaped user input parameters are passed as arguments
4520	    to /bin/sh allowing for remote command execution.</p>
4521	  <p>This bug was originally reported against the anonymous
4522	    calls to the SamrChangePassword() MS-RPC function in
4523	    combination with the "username map script" smb.conf option
4524	    (which is not enabled by default).</p>
4525	  <p>After further investigation by Samba developers, it was
4526	    determined that the problem was much broader and impacts
4527	    remote printer and file share management as well.  The
4528	    root cause is passing unfiltered user input provided via
4529	    MS-RPC calls to /bin/sh when invoking externals scripts
4530	    defined in smb.conf.  However, unlike the "username map
4531	    script" vulnerability, the remote file and printer
4532	    management scripts require an authenticated user
4533	    session.</p>
4534	</blockquote>
4535      </body>
4536    </description>
4537    <references>
4538      <cvename>CVE-2007-2444</cvename>
4539      <cvename>CVE-2007-2446</cvename>
4540      <cvename>CVE-2007-2447</cvename>
4541      <url>http://de5.samba.org/samba/security/CVE-2007-2444.html</url>
4542      <url>http://de5.samba.org/samba/security/CVE-2007-2446.html</url>
4543      <url>http://de5.samba.org/samba/security/CVE-2007-2447.html</url>
4544    </references>
4545    <dates>
4546      <discovery>2007-05-14</discovery>
4547      <entry>2007-05-16</entry>
4548      <modified>2008-09-26</modified>
4549    </dates>
4550  </vuln>
4551
4552  <vuln vid="f5e52bf5-fc77-11db-8163-000e0c2e438a">
4553    <topic>php -- multiple vulnerabilities</topic>
4554    <affects>
4555      <package>
4556	<name>php5-imap</name>
4557	<name>php5-odbc</name>
4558	<name>php5-session</name>
4559	<name>php5-shmop</name>
4560	<name>php5-sqlite</name>
4561	<name>php5-wddx</name>
4562	<name>php5</name>
4563	<range><lt>5.2.2</lt></range>
4564      </package>
4565      <package>
4566	<name>php4-odbc</name>
4567	<name>php4-session</name>
4568	<name>php4-shmop</name>
4569	<name>php4-wddx</name>
4570	<name>php4</name>
4571	<range><lt>4.4.7</lt></range>
4572      </package>
4573      <package>
4574	<name>mod_php4-twig</name>
4575	<name>mod_php4</name>
4576	<name>mod_php5</name>
4577	<name>mod_php</name>
4578	<name>php4-cgi</name>
4579	<name>php4-cli</name>
4580	<name>php4-dtc</name>
4581	<name>php4-horde</name>
4582	<name>php4-nms</name>
4583	<name>php5-cgi</name>
4584	<name>php5-cli</name>
4585	<name>php5-dtc</name>
4586	<name>php5-horde</name>
4587	<name>php5-nms</name>
4588	<range><ge>4</ge><lt>4.4.7</lt></range>
4589	<range><ge>5</ge><lt>5.2.2</lt></range>
4590      </package>
4591    </affects>
4592    <description>
4593      <body xmlns="http://www.w3.org/1999/xhtml">
4594	<p>The PHP development team reports:</p>
4595	<blockquote cite="http://www.php.net/releases/5_2_2.php">
4596	  <p>Security Enhancements and Fixes in PHP 5.2.2 and PHP
4597	    4.4.7:</p>
4598	  <ul>
4599	    <li>Fixed CVE-2007-1001, GD wbmp used with invalid image
4600	      size</li>
4601	    <li>Fixed asciiz byte truncation inside mail()</li>
4602	    <li>Fixed a bug in mb_parse_str() that can be used to
4603	      activate register_globals</li>
4604	    <li>Fixed unallocated memory access/double free in in
4605	      array_user_key_compare()</li>
4606	    <li>Fixed a double free inside session_regenerate_id()</li>
4607	    <li>Added missing open_basedir &amp; safe_mode checks to zip://
4608	      and bzip:// wrappers.</li>
4609	    <li>Limit nesting level of input variables with
4610	      max_input_nesting_level as fix for.</li>
4611	    <li>Fixed CRLF injection inside ftp_putcmd().</li>
4612	    <li>Fixed a possible super-global overwrite inside
4613	      import_request_variables().</li>
4614	    <li>Fixed a remotely trigger-able buffer overflow inside
4615	      bundled libxmlrpc library.</li>
4616	  </ul>
4617	  <p>Security Enhancements and Fixes in PHP 5.2.2 only:</p>
4618	  <ul>
4619	    <li>Fixed a header injection via Subject and To parameters
4620	      to the mail() function</li>
4621	    <li>Fixed wrong length calculation in unserialize S
4622	      type.</li>
4623	    <li>Fixed substr_compare and substr_count information
4624	      leak.</li>
4625	    <li>Fixed a remotely trigger-able buffer overflow inside
4626	      make_http_soap_request().</li>
4627	    <li>Fixed a buffer overflow inside
4628	      user_filter_factory_create().</li>
4629	  </ul>
4630	  <p>Security Enhancements and Fixes in PHP 4.4.7 only:</p>
4631	  <ul>
4632	    <li>XSS in phpinfo()</li>
4633	  </ul>
4634	</blockquote>
4635      </body>
4636    </description>
4637    <references>
4638      <cvename>CVE-2007-1001</cvename>
4639      <url>http://www.php.net/releases/4_4_7.php</url>
4640      <url>http://www.php.net/releases/5_2_2.php</url>
4641    </references>
4642    <dates>
4643      <discovery>2007-05-03</discovery>
4644      <entry>2007-05-07</entry>
4645      <modified>2014-04-01</modified>
4646    </dates>
4647  </vuln>
4648
4649  <vuln vid="0ac89b39-f829-11db-b55c-000e0c6d38a9">
4650    <topic>qemu -- several vulnerabilities</topic>
4651    <affects>
4652      <package>
4653	<name>qemu</name>
4654	<name>qemu-devel</name>
4655	<range><lt>0.9.0_1</lt></range>
4656	<range><ge>0.9.0s.20070101*</ge><lt>0.9.0s.20070405_3</lt></range>
4657      </package>
4658    </affects>
4659    <description>
4660      <body xmlns="http://www.w3.org/1999/xhtml">
4661	<p>The Debian Security Team reports:</p>
4662	<blockquote cite="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html">
4663	  <p>Several vulnerabilities have been discovered in the QEMU processor
4664	    emulator, which may lead to the execution of arbitrary code or
4665	    denial of service. The Common Vulnerabilities and Exposures project
4666	    identifies the following problems:</p>
4667	  <p>CVE-2007-1320<br/>Tavis Ormandy discovered that a memory management
4668	    routine of the Cirrus video driver performs insufficient bounds
4669	    checking, which might allow the execution of arbitrary code through
4670	    a heap overflow.</p>
4671	  <p>CVE-2007-1321<br/>Tavis Ormandy discovered that the NE2000 network
4672	    driver and the socket code perform insufficient input validation,
4673	    which might allow the execution of arbitrary code through a heap
4674	    overflow.</p>
4675	  <p>CVE-2007-1322<br/>Tavis Ormandy discovered that the "icebp"
4676	    instruction can be abused to terminate the emulation, resulting in
4677	    denial of service.</p>
4678	  <p>CVE-2007-1323<br/>Tavis Ormandy discovered that the NE2000 network
4679	    driver and the socket code perform insufficient input validation,
4680	    which might allow the execution of arbitrary code through a heap
4681	    overflow.</p>
4682	  <p>CVE-2007-1366<br/>Tavis Ormandy discovered that the "aam"
4683	    instruction can be abused to crash qemu through a division by zero,
4684	    resulting in denial of service.</p>
4685	</blockquote>
4686      </body>
4687    </description>
4688    <references>
4689      <cvename>CVE-2007-1320</cvename>
4690      <cvename>CVE-2007-1321</cvename>
4691      <cvename>CVE-2007-1322</cvename>
4692      <cvename>CVE-2007-1323</cvename>
4693      <cvename>CVE-2007-1366</cvename>
4694      <mlist msgid="20070501100313.GA4074@galadriel.inutil.org">http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html</mlist>
4695    </references>
4696    <dates>
4697      <discovery>2007-05-01</discovery>
4698      <entry>2007-05-01</entry>
4699      <modified>2007-05-02</modified>
4700    </dates>
4701  </vuln>
4702
4703  <vuln vid="632c98be-aad2-4af2-849f-41a6862afd6a">
4704    <topic>p5-Imager -- possibly exploitable buffer overflow</topic>
4705    <affects>
4706      <package>
4707	<name>p5-Imager</name>
4708	<range><lt>0.57</lt></range>
4709      </package>
4710    </affects>
4711    <description>
4712      <body xmlns="http://www.w3.org/1999/xhtml">
4713	<p>Imager 0.56 and all earlier versions with BMP support have
4714	  a security issue when reading compressed 8-bit per pixel BMP
4715	  files where either a compressed run of data or a literal run
4716	  of data overflows the scan-line.</p>
4717	<p>Such an overflow causes a buffer overflow in a malloc()
4718	  allocated memory buffer, possibly corrupting the memory arena
4719	  headers.</p>
4720	<p>The effect depends on your system memory allocator, with glibc
4721	  this typically results in an abort, but with other memory
4722	  allocators it may be possible to cause local code execution.</p>
4723      </body>
4724    </description>
4725    <references>
4726      <cvename>CVE-2007-1942</cvename>
4727      <cvename>CVE-2007-1943</cvename>
4728      <cvename>CVE-2007-1946</cvename>
4729      <cvename>CVE-2007-1948</cvename>
4730      <url>https://rt.cpan.org/Public/Bug/Display.html?id=26811</url>
4731      <url>http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</url>
4732    </references>
4733    <dates>
4734      <discovery>2007-04-04</discovery>
4735      <entry>2007-04-30</entry>
4736      <modified>2010-05-12</modified>
4737    </dates>
4738  </vuln>
4739
4740  <vuln vid="275b845e-f56c-11db-8163-000e0c2e438a">
4741    <topic>FreeBSD -- IPv6 Routing Header 0 is dangerous</topic>
4742    <affects>
4743      <package>
4744	<name>FreeBSD</name>
4745	<range><ge>6.2</ge><lt>6.2_4</lt></range>
4746	<range><ge>6.1</ge><lt>6.1_16</lt></range>
4747	<range><ge>5.5</ge><lt>5.5_12</lt></range>
4748      </package>
4749    </affects>
4750    <description>
4751      <body xmlns="http://www.w3.org/1999/xhtml">
4752	<h1>Problem Description</h1>
4753	<p>There is no mechanism for preventing IPv6 routing headers
4754	  from being used to route packets over the same link(s) many
4755	  times.</p>
4756	<h1>Impact</h1>
4757	<p>An attacker can "amplify" a denial of service attack against
4758	  a link between two vulnerable hosts; that is, by sending a
4759	  small volume of traffic the attacker can consume a much larger
4760	  amount of bandwidth between the two vulnerable hosts.</p>
4761	<p>An attacker can use vulnerable hosts to "concentrate" a
4762	  denial of service attack against a victim host or network;
4763	  that is, a set of packets sent over a period of 30 seconds
4764	  or more could be constructed such that they all arrive at
4765	  the victim within a period of 1 second or less  over a
4766	  period of 30 seconds or more could be constructed such that
4767	  they all arrive at the victim within a period of 1 second or
4768	  less.</p>
4769	<p>Other attacks may also be possible.</p>
4770	<h1>Workaround</h1>
4771	<p>No workaround is available.</p>
4772      </body>
4773    </description>
4774    <references>
4775      <cvename>CVE-2007-2242</cvename>
4776      <freebsdsa>SA-07:03.ipv6</freebsdsa>
4777    </references>
4778    <dates>
4779      <discovery>2007-04-26</discovery>
4780      <entry>2007-04-28</entry>
4781      <modified>2016-08-09</modified>
4782    </dates>
4783  </vuln>
4784
4785  <vuln vid="ef2ffb03-f2b0-11db-ad25-0010b5a0a860">
4786    <topic>mod_perl -- remote DoS in PATH_INFO parsing</topic>
4787    <affects>
4788      <package>
4789	<name>mod_perl</name>
4790	<range><lt>1.30</lt></range>
4791      </package>
4792      <package>
4793	<name>mod_perl2</name>
4794	<range><lt>2.0.3_2,3</lt></range>
4795      </package>
4796    </affects>
4797    <description>
4798      <body xmlns="http://www.w3.org/1999/xhtml">
4799	<p>Mandriva reports:</p>
4800	<blockquote cite="http://www.mandriva.com/security/advisories?name=MDKSA-2007:083">
4801	  <p>PerlRun.pm in Apache mod_perl 1.29 and earlier, and
4802	    RegistryCooker.pm in mod_perl 2.x, does not properly escape
4803	    PATH_INFO before use in a regular expression, which allows remote
4804	    attackers to cause a denial of service (resource consumption) via a
4805	    crafted URI.</p>
4806	</blockquote>
4807      </body>
4808    </description>
4809    <references>
4810      <cvename>CVE-2007-1349</cvename>
4811      <url>http://www.mandriva.com/security/advisories?name=MDKSA-2007:083</url>
4812      <url>http://secunia.com/advisories/24839</url>
4813    </references>
4814    <dates>
4815      <discovery>2007-03-29</discovery>
4816      <entry>2007-04-24</entry>
4817      <modified>2007-06-27</modified>
4818    </dates>
4819  </vuln>
4820
4821  <vuln vid="c389d06d-ee57-11db-bd51-0016179b2dd5">
4822    <topic>claws-mail -- APOP vulnerability</topic>
4823    <affects>
4824      <package>
4825	<name>claws-mail</name>
4826	<range><lt>2.9.0</lt></range>
4827      </package>
4828    </affects>
4829    <description>
4830      <body xmlns="http://www.w3.org/1999/xhtml">
4831	<p>CVE reports:</p>
4832	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558">
4833	  <p>The APOP protocol allows remote attackers to guess the first 3
4834	    characters of a password via man-in-the-middle (MITM) attacks
4835	    that use crafted message IDs and MD5 collisions.</p>
4836	</blockquote>
4837      </body>
4838    </description>
4839    <references>
4840      <cvename>CVE-2007-1558</cvename>
4841      <url>http://www.claws-mail.org/news.php</url>
4842    </references>
4843    <dates>
4844      <discovery>2007-04-02</discovery>
4845      <entry>2007-04-19</entry>
4846    </dates>
4847  </vuln>
4848
4849  <vuln vid="5678da43-ea99-11db-a802-000fea2763ce">
4850    <topic>lighttpd -- DOS when access files with mtime 0</topic>
4851    <affects>
4852      <package>
4853	<name>lighttpd</name>
4854	<range><lt>1.4.15</lt></range>
4855      </package>
4856    </affects>
4857    <description>
4858      <body xmlns="http://www.w3.org/1999/xhtml">
4859	<p>Lighttpd SA:</p>
4860	<blockquote cite="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt">
4861	  <p>Lighttpd caches the rendered string for mtime. The cache key has
4862	    as a default value 0.  At that point the pointer to the string are
4863	    still NULL. If a file with an mtime of 0 is requested it tries to
4864	    access the pointer and crashes.</p>
4865	  <p>The bug requires that a malicious user can either upload files or
4866	    manipulate the mtime of the files.</p>
4867	  <p>The bug was reported by cubiq and fixed by Marcus Rueckert.</p>
4868	</blockquote>
4869      </body>
4870    </description>
4871    <references>
4872      <cvename>CVE-2007-1870</cvename>
4873      <url>http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt</url>
4874    </references>
4875    <dates>
4876      <discovery>2007-01-14</discovery>
4877      <entry>2007-04-14</entry>
4878    </dates>
4879  </vuln>
4880
4881  <vuln vid="d2b48d30-ea97-11db-a802-000fea2763ce">
4882    <topic>lighttpd -- Remote DOS in CRLF parsing</topic>
4883    <affects>
4884      <package>
4885	<name>lighttpd</name>
4886	<range><gt>1.4.11</gt><lt>1.4.13_2</lt></range>
4887      </package>
4888    </affects>
4889    <description>
4890      <body xmlns="http://www.w3.org/1999/xhtml">
4891	<p>Lighttpd SA:</p>
4892	<blockquote cite="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt">
4893	  <p>If the connection aborts during parsing "\r\n\r\n" the server
4894	    might get into a infinite loop and use 100% of the CPU time.
4895	    lighttpd still responses to other requests. This can be repeated
4896	    until either the server limit for concurrent connections or file
4897	    descriptors is reached.</p>
4898	  <p>The bug was reported and fixed by Robert Jakabosky.</p>
4899	</blockquote>
4900      </body>
4901    </description>
4902    <references>
4903      <cvename>CVE-2007-1869</cvename>
4904      <url>http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt</url>
4905    </references>
4906    <dates>
4907      <discovery>2006-12-15</discovery>
4908      <entry>2007-04-14</entry>
4909    </dates>
4910  </vuln>
4911
4912  <vuln vid="c110eda2-e995-11db-a944-0012f06707f0">
4913    <topic>freeradius -- EAP-TTLS Tunnel Memory Leak Remote DOS Vulnerability</topic>
4914    <affects>
4915      <package>
4916	<name>freeradius</name>
4917	<name>freeradius-mysql</name>
4918	<range><le>1.1.5</le></range>
4919      </package>
4920    </affects>
4921    <description>
4922      <body xmlns="http://www.w3.org/1999/xhtml">
4923	<p>The freeradius development team reports:</p>
4924	<blockquote cite="http://www.freeradius.org/security.html">
4925	  <p>A malicious 802.1x supplicant could send malformed Diameter format
4926	     attributes inside of an EAP-TTLS tunnel. The server would reject
4927	     the authentication request, but would leak one VALUE_PAIR data
4928	     structure, of approximately 300 bytes. If an attacker performed
4929	     the attack many times (e.g. thousands or more over a period of
4930	     minutes to hours), the server could leak megabytes of memory,
4931	     potentially leading to an "out of memory" condition, and early
4932	     process exit.</p>
4933	</blockquote>
4934      </body>
4935    </description>
4936    <references>
4937      <bid>23466</bid>
4938      <cvename>CVE-2005-1455</cvename>
4939      <cvename>CVE-2005-1454</cvename>
4940      <cvename>CVE-2007-2028</cvename>
4941      <cvename>CVE-2005-4745</cvename>
4942      <url>http://www.freeradius.org/security.html</url>
4943    </references>
4944    <dates>
4945      <discovery>2007-04-10</discovery>
4946      <entry>2007-04-13</entry>
4947      <modified>2010-05-12</modified>
4948    </dates>
4949  </vuln>
4950
4951  <vuln vid="f1c4d133-e6d3-11db-99ea-0060084a00e5">
4952    <topic>fetchmail -- insecure APOP authentication</topic>
4953    <affects>
4954      <package>
4955	<name>fetchmail</name>
4956	<range><lt>6.3.8</lt></range>
4957      </package>
4958    </affects>
4959    <description>
4960      <body xmlns="http://www.w3.org/1999/xhtml">
4961	<p>Matthias Andree reports:</p>
4962	<blockquote cite="http://www.fetchmail.info/fetchmail-SA-2007-01.txt">
4963	  <p>The POP3 standard, currently RFC-1939, has specified an optional,
4964	    MD5-based authentication scheme called "APOP" which no longer
4965	    should be considered secure.</p>
4966	  <p>Additionally, fetchmail's POP3 client implementation has been
4967	    validating the APOP challenge too lightly and accepted random
4968	    garbage as a POP3 server's APOP challenge. This made it easier
4969	    than necessary for man-in-the-middle attackers to retrieve by
4970	    several probing and guessing the first three characters of the
4971	    APOP secret, bringing brute forcing the remaining characters well
4972	    within reach.</p>
4973	</blockquote>
4974      </body>
4975    </description>
4976    <references>
4977      <cvename>CVE-2007-1558</cvename>
4978      <url>http://www.fetchmail.info/fetchmail-SA-2007-01.txt</url>
4979    </references>
4980    <dates>
4981      <discovery>2007-04-06</discovery>
4982      <entry>2007-04-09</entry>
4983    </dates>
4984  </vuln>
4985
4986  <vuln vid="84d3fbb2-e607-11db-8a32-000c76189c4c">
4987    <topic>mcweject -- exploitable buffer overflow</topic>
4988    <affects>
4989      <package>
4990	<name>mcweject</name>
4991	<range><le>0.9</le></range>
4992      </package>
4993    </affects>
4994    <description>
4995      <body xmlns="http://www.w3.org/1999/xhtml">
4996	<p>CVE reports:</p>
4997	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1719">
4998	  <p>Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on
4999	    FreeBSD, and possibly other versions, allows local users to execute
5000	    arbitrary code via a long command line argument, possibly involving
5001	    the device name.</p>
5002	</blockquote>
5003      </body>
5004    </description>
5005    <references>
5006      <cvename>CVE-2007-1719</cvename>
5007      <freebsdpr>ports/111365</freebsdpr>
5008      <url>http://www.milw0rm.com/exploits/3578</url>
5009    </references>
5010    <dates>
5011      <discovery>2007-03-27</discovery>
5012      <entry>2007-04-08</entry>
5013    </dates>
5014  </vuln>
5015
5016  <vuln vid="72999d57-d6f6-11db-961b-005056847b26">
5017    <topic>WebCalendar -- "noSet" variable overwrite vulnerability</topic>
5018    <affects>
5019      <package>
5020	<name>WebCalendar</name>
5021	<range><lt>1.0.5</lt></range>
5022      </package>
5023    </affects>
5024    <description>
5025      <body xmlns="http://www.w3.org/1999/xhtml">
5026	<p>Secunia reports:</p>
5027	<blockquote cite="http://secunia.com/advisories/24403/">
5028	  <p>A vulnerability has been discovered in WebCalendar,
5029	    which can be exploited by malicious people to compromise
5030	    a vulnerable system.</p>
5031	  <p>Input passed to unspecified parameters is not properly
5032	    verified before being used with the "noSet" parameter set.
5033	    This can be exploited to overwrite certain variables, and
5034	    allows e.g. the inclusion of arbitrary PHP files from internal
5035	    or external resources.</p>
5036	</blockquote>
5037      </body>
5038    </description>
5039    <references>
5040      <cvename>CVE-2007-1343</cvename>
5041      <bid>22834</bid>
5042      <url>http://sourceforge.net/project/shownotes.php?release_id=491130</url>
5043      <url>http://xforce.iss.net/xforce/xfdb/32832</url>
5044    </references>
5045    <dates>
5046      <discovery>2007-03-04</discovery>
5047      <entry>2007-04-08</entry>
5048    </dates>
5049  </vuln>
5050
5051  <vuln vid="34414a1e-e377-11db-b8ab-000c76189c4c">
5052    <topic>zope -- cross-site scripting vulnerability</topic>
5053    <affects>
5054      <package>
5055	<name>zope</name>
5056	<range><lt>2.7.9_2</lt></range>
5057	<range><ge>2.8.0</ge><le>2.8.8</le></range>
5058	<range><ge>2.9.0</ge><le>2.9.6</le></range>
5059	<range><ge>2.10.0</ge><le>2.10.2</le></range>
5060      </package>
5061      <package>
5062	<name>plone</name>
5063	<range><lt>2.5.3</lt></range>
5064      </package>
5065    </affects>
5066    <description>
5067      <body xmlns="http://www.w3.org/1999/xhtml">
5068	<p>The Zope Team reports:</p>
5069	<blockquote cite="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view">
5070	  <p>A vulnerability has been discovered in Zope, where by certain types
5071	    of misuse of HTTP GET, an attacker could gain elevated privileges.
5072	    All Zope versions up to and including 2.10.2 are affected.</p>
5073	</blockquote>
5074      </body>
5075    </description>
5076    <references>
5077      <bid>23084</bid>
5078      <cvename>CVE-2007-0240</cvename>
5079      <freebsdpr>ports/111119</freebsdpr>
5080      <url>http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view</url>
5081      <url>http://plone.org/products/plone/releases/2.5.3</url>
5082    </references>
5083    <dates>
5084      <discovery>2007-01-16</discovery>
5085      <entry>2007-04-05</entry>
5086      <modified>2009-03-22</modified>
5087    </dates>
5088  </vuln>
5089
5090  <vuln vid="c27bc173-d7aa-11db-b141-0016179b2dd5">
5091    <topic>Squid -- TRACE method handling denial of service</topic>
5092    <affects>
5093      <package>
5094	<name>squid</name>
5095	<range><ge>2.6.*</ge><lt>2.6.12</lt></range>
5096      </package>
5097    </affects>
5098    <description>
5099      <body xmlns="http://www.w3.org/1999/xhtml">
5100	<p>Squid advisory 2007:1 notes:</p>
5101	<blockquote cite="http://www.squid-cache.org/Advisories/SQUID-2007_1.txt">
5102	  <p>Due to an internal error Squid-2.6 is vulnerable to a denial of
5103	    service attack when processing the TRACE request method.</p>
5104	  <p>Workarounds:</p>
5105	  <p>To work around the problem deny access to using the TRACE method by
5106	    inserting the following two lines before your first http_access
5107	    rule.</p>
5108	  <p>acl TRACE method TRACE</p>
5109	  <p>http_access deny TRACE</p>
5110	</blockquote>
5111      </body>
5112    </description>
5113    <references>
5114      <cvename>CVE-2007-1560</cvename>
5115      <url>http://www.squid-cache.org/Advisories/SQUID-2007_1.txt</url>
5116    </references>
5117    <dates>
5118      <discovery>2007-03-20</discovery>
5119      <entry>2007-03-21</entry>
5120      <modified>2010-05-12</modified>
5121    </dates>
5122  </vuln>
5123
5124  <vuln vid="8e02441d-d39c-11db-a6da-0003476f14d3">
5125    <topic>sql-ledger -- security bypass vulnerability</topic>
5126    <affects>
5127      <package>
5128	<name>sql-ledger</name>
5129	<range><lt>2.6.26</lt></range>
5130      </package>
5131    </affects>
5132    <description>
5133      <body xmlns="http://www.w3.org/1999/xhtml">
5134	<p>Chris Travers reports:</p>
5135	<blockquote cite="http://www.securityfocus.com/archive/1/462375">
5136	  <p>George Theall of Tenable Security notified the LedgerSMB
5137	    core team today of an authentication bypass vulnerability
5138	    allowing full access to the administrator interface of
5139	    LedgerSMB 1.1 and SQL-Ledger 2.x.  The problem is caused
5140	    by the password checking routine failing to enforce a
5141	    password check under certain circumstances. The user
5142	    can then create accounts or effect denial of service
5143	    attacks.</p>
5144	  <p>This is not related to any previous CVE.</p>
5145	  <p>We have coordinated with the SQL-Ledger vendor and
5146	    today both of us released security patches correcting
5147	    the problem. SQL-Ledger users who can upgrade to 2.6.26
5148	    should do so, and LedgerSMB 1.1 or 1.0 users should
5149	    upgrade to 1.1.9. Users who cannot upgrade should
5150	    configure their web servers to use http authentication
5151	    for the admin.pl script in the main root directory.</p>
5152	</blockquote>
5153      </body>
5154    </description>
5155    <references>
5156      <freebsdpr>ports/110350</freebsdpr>
5157      <url>http://www.securityfocus.com/archive/1/462375</url>
5158    </references>
5159    <dates>
5160      <discovery>2007-03-09</discovery>
5161      <entry>2007-03-16</entry>
5162    </dates>
5163  </vuln>
5164
5165  <vuln vid="f235fe7a-b9ca-11db-bf0f-0013720b182d">
5166    <topic>samba -- potential Denial of Service bug in smbd</topic>
5167    <affects>
5168      <package>
5169	<name>samba</name>
5170	<name>ja-samba</name>
5171	<range><ge>3.0.6,1</ge><lt>3.0.24,1</lt></range>
5172      </package>
5173    </affects>
5174    <description>
5175      <body xmlns="http://www.w3.org/1999/xhtml">
5176	<p>The Samba Team reports:</p>
5177	<blockquote cite="http://www.samba.org/samba/security/CVE-2007-0452.html">
5178	  <p>Internally Samba's file server daemon, smbd, implements
5179	    support for deferred file open calls in an attempt to serve
5180	    client requests that would otherwise fail due to a share mode
5181	    violation.	When renaming a file under certain circumstances
5182	    it is possible that the request is never removed from the deferred
5183	    open queue.  smbd will then become stuck is a loop trying to
5184	    service the open request.</p>
5185	  <p>This bug may allow an authenticated user to exhaust resources
5186	    such as memory and CPU on the server by opening multiple CIFS
5187	    sessions, each of which will normally spawn a new smbd process,
5188	    and sending each connection into an infinite loop.</p>
5189	</blockquote>
5190      </body>
5191    </description>
5192    <references>
5193      <cvename>CVE-2007-0452</cvename>
5194      <url>http://www.samba.org/samba/security/CVE-2007-0452.html</url>
5195    </references>
5196    <dates>
5197      <discovery>2007-02-05</discovery>
5198      <entry>2007-03-16</entry>
5199    </dates>
5200  </vuln>
5201
5202  <vuln vid="57ae52f7-b9cc-11db-bf0f-0013720b182d">
5203    <topic>samba -- format string bug in afsacl.so VFS plugin</topic>
5204    <affects>
5205      <package>
5206	<name>samba</name>
5207	<name>ja-samba</name>
5208	<range><ge>3.0.6,1</ge><lt>3.0.24,1</lt></range>
5209      </package>
5210    </affects>
5211    <description>
5212      <body xmlns="http://www.w3.org/1999/xhtml">
5213	<p>The Samba Team reports:</p>
5214	<blockquote cite="http://www.samba.org/samba/security/CVE-2007-0454.html">
5215	  <p>NOTE: This security advisory only impacts Samba servers
5216	    that share AFS file systems to CIFS clients and which have
5217	    been explicitly instructed in smb.conf to load the afsacl.so
5218	    VFS module.</p>
5219	  <p>The source defect results in the name of a file stored on
5220	    disk being used as the format string in a call to snprintf().
5221	    This bug becomes exploitable only when a user is able
5222	    to write to a share which utilizes Samba's afsacl.so library
5223	    for setting Windows NT access control lists on files residing
5224	    on an AFS file system.</p>
5225	</blockquote>
5226      </body>
5227    </description>
5228    <references>
5229      <cvename>CVE-2007-0454</cvename>
5230      <url>http://www.samba.org/samba/security/CVE-2007-0454.html</url>
5231    </references>
5232    <dates>
5233      <discovery>2007-02-05</discovery>
5234      <entry>2007-03-16</entry>
5235    </dates>
5236  </vuln>
5237
5238  <vuln vid="73f53712-d028-11db-8c07-0211d85f11fb">
5239    <topic>ktorrent -- multiple vulnerabilities</topic>
5240    <affects>
5241      <package>
5242	<name>ktorrent</name>
5243	<range><lt>2.1.2</lt></range>
5244      </package>
5245      <package>
5246	<name>ktorrent-devel</name>
5247	<range><lt>20070311</lt></range>
5248      </package>
5249    </affects>
5250    <description>
5251      <body xmlns="http://www.w3.org/1999/xhtml">
5252	<p>Two problems have been found in KTorrent:</p>
5253	<ul>
5254	  <li>KTorrent does not properly sanitize file names to filter
5255	    out ".." components, so it's possible for an attacker to create
5256	    a malicious torrent in order to overwrite arbitrary files within
5257	    the filesystem.</li>
5258	  <li>Messages with invalid chunk indexes aren't rejected.</li>
5259	</ul>
5260      </body>
5261    </description>
5262    <references>
5263      <cvename>CVE-2007-1384</cvename>
5264      <cvename>CVE-2007-1385</cvename>
5265      <url>http://ktorrent.org/forum/viewtopic.php?t=1401</url>
5266    </references>
5267    <dates>
5268      <discovery>2007-03-09</discovery>
5269      <entry>2007-03-11</entry>
5270      <modified>2007-03-14</modified>
5271    </dates>
5272  </vuln>
5273
5274  <vuln vid="abeb9b64-ce50-11db-bc24-0016179b2dd5">
5275    <topic>mplayer -- DMO File Parsing Buffer Overflow Vulnerability</topic>
5276    <affects>
5277      <package>
5278	<name>mplayer</name>
5279	<name>mplayer-esound</name>
5280	<name>mplayer-gtk</name>
5281	<name>mplayer-gtk2</name>
5282	<name>mplayer-gtk-esound</name>
5283	<name>mplayer-gtk2-esound</name>
5284	<range><lt>0.99.10_5</lt></range>
5285      </package>
5286    </affects>
5287    <description>
5288      <body xmlns="http://www.w3.org/1999/xhtml">
5289	<p>"Moritz Jodeit reports:</p>
5290	<blockquote cite="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html">
5291	  <p>There's an exploitable buffer overflow in the current version
5292	    of MPlayer (v1.0rc1) which can be exploited with a maliciously
5293	    crafted video file.  It is hidden in the DMO_VideoDecoder()
5294	    function of `loader/dmo/DMO_VideoDecoder.c' file.</p>
5295	</blockquote>
5296      </body>
5297    </description>
5298    <references>
5299      <bid>22771</bid>
5300      <cvename>CVE-2007-1246</cvename>
5301    </references>
5302    <dates>
5303      <discovery>2007-02-11</discovery>
5304      <entry>2007-03-09</entry>
5305    </dates>
5306  </vuln>
5307
5308  <vuln vid="e546c7ce-ce46-11db-bc24-0016179b2dd5">
5309    <topic>trac -- cross site scripting vulnerability</topic>
5310    <affects>
5311      <package>
5312	<name>trac</name>
5313	<range><lt>0.10.3</lt></range>
5314      </package>
5315      <package>
5316	<name>ja-trac</name>
5317	<range><lt>0.10.3_1</lt></range>
5318      </package>
5319    </affects>
5320    <description>
5321      <body xmlns="http://www.w3.org/1999/xhtml">
5322	<p>Secunia reports:</p>
5323	<blockquote cite="http://secunia.com/advisories/24470/">
5324	  <p>The vulnerability is caused due to an error within the
5325	    "download wiki page as text" function, which can be exploited
5326	    to execute arbitrary HTML and script code in a user's browser
5327	    session in context of an affected site.</p>
5328	  <p>Successful exploitation may require that the victim uses IE.</p>
5329	</blockquote>
5330      </body>
5331    </description>
5332    <references>
5333      <url>http://secunia.com/advisories/24470</url>
5334      <url>http://trac.edgewall.org/wiki/ChangeLog#a0.10.3.1</url>
5335    </references>
5336    <dates>
5337      <discovery>2007-03-09</discovery>
5338      <entry>2007-03-09</entry>
5339    </dates>
5340  </vuln>
5341
5342  <vuln vid="cf86c644-cb6c-11db-8e9d-000c6ec775d9">
5343    <topic>mod_jk -- long URL stack overflow vulnerability</topic>
5344    <affects>
5345      <package>
5346	<name>mod_jk-ap2</name>
5347	<name>mod_jk</name>
5348	<range><ge>1.2.19</ge><lt>1.2.21</lt></range>
5349      </package>
5350    </affects>
5351    <description>
5352      <body xmlns="http://www.w3.org/1999/xhtml">
5353	<p>TippingPoint and The Zero Day Initiative reports:</p>
5354	<blockquote cite="http://www.zerodayinitiative.com/advisories/ZDI-07-008.html">
5355	  <p>This vulnerability allows remote attackers to execute
5356	    arbitrary code on vulnerable installations of Apache
5357	    Tomcat JK Web Server Connector. Authentication is not
5358	    required to exploit this vulnerability.</p>
5359	  <p>The specific flaw exists in the URI handler for the
5360	    mod_jk.so library, map_uri_to_worker(), defined in
5361	    native/common/jk_uri_worker_map.c. When parsing a long URL
5362	    request, the URI worker map routine performs an unsafe
5363	    memory copy. This results in a stack overflow condition
5364	    which can be leveraged to execute arbitrary code.</p>
5365	</blockquote>
5366      </body>
5367    </description>
5368    <references>
5369      <cvename>CVE-2007-0774</cvename>
5370      <url>http://tomcat.apache.org/security-jk.html</url>
5371      <url>http://www.zerodayinitiative.com/advisories/ZDI-07-008.html</url>
5372    </references>
5373    <dates>
5374      <discovery>2007-03-02</discovery>
5375      <entry>2007-03-05</entry>
5376      <modified>2007-03-06</modified>
5377    </dates>
5378  </vuln>
5379
5380  <vuln vid="3cb6f059-c69d-11db-9f82-000e0c2e438a">
5381    <topic>bind -- Multiple Denial of Service vulnerabilities</topic>
5382    <affects>
5383      <package>
5384	<name>named</name>
5385	<range><lt>9.3.4</lt></range>
5386      </package>
5387      <package>
5388	<name>FreeBSD</name>
5389	<range><ge>6.2</ge><lt>6.2_1</lt></range>
5390	<range><ge>6.1</ge><lt>6.1_13</lt></range>
5391	<range><ge>5.5</ge><lt>5.5_11</lt></range>
5392      </package>
5393    </affects>
5394    <description>
5395      <body xmlns="http://www.w3.org/1999/xhtml">
5396	<h1>Problem Description:</h1>
5397	<p>A type * (ANY) query response containing multiple RRsets can
5398	  trigger an assertion failure.</p>
5399	<p>Certain recursive queries can cause the nameserver to crash
5400	  by using memory which has already been freed.</p>
5401	<h1>Impact:</h1>
5402	<p>A remote attacker sending a type * (ANY) query to an
5403	  authoritative DNS server for a DNSSEC signed zone can cause
5404	  the named(8) daemon to exit, resulting in a Denial of
5405	  Service.</p>
5406	<p>A remote attacker sending recursive queries can cause the
5407	  nameserver to crash, resulting in a Denial of Service.</p>
5408	<h1>Workaround:</h1>
5409	<p>There is no workaround available, but systems which are not
5410	  authoritative servers for DNSSEC signed zones are not
5411	  affected by the first issue; and systems which do not permit
5412	  untrusted users to perform recursive DNS resolution are not
5413	  affected by the second issue.  Note that the default
5414	  configuration for named(8) in FreeBSD allows local access
5415	  only (which on many systems is equivalent to refusing access
5416	  to untrusted users).</p>
5417      </body>
5418    </description>
5419    <references>
5420      <cvename>CVE-2007-0493</cvename>
5421      <cvename>CVE-2007-0494</cvename>
5422      <freebsdsa>SA-07:02.bind</freebsdsa>
5423    </references>
5424    <dates>
5425      <discovery>2007-02-09</discovery>
5426      <entry>2007-02-27</entry>
5427      <modified>2016-08-09</modified>
5428    </dates>
5429  </vuln>
5430
5431  <vuln vid="46b922a8-c69c-11db-9f82-000e0c2e438a">
5432    <topic>FreeBSD -- Jail rc.d script privilege escalation</topic>
5433    <affects>
5434      <package>
5435	<name>FreeBSD</name>
5436	<range><ge>6.1</ge><lt>6.1_12</lt></range>
5437	<range><ge>6.0</ge><lt>6.0_17</lt></range>
5438	<range><ge>5.5</ge><lt>5.5_15</lt></range>
5439      </package>
5440    </affects>
5441    <description>
5442      <body xmlns="http://www.w3.org/1999/xhtml">
5443	<h1>Problem Description:</h1>
5444	<p>In multiple situations the host's jail rc.d(8) script does
5445	  not check if a path inside the jail file system structure is
5446	  a symbolic link before using the path.  In particular this is
5447	  the case when writing the output from the jail start-up to
5448	  /var/log/console.log and when mounting and unmounting file
5449	  systems inside the jail directory structure.</p>
5450	<h1>Impact:</h1>
5451	<p>Due to the lack of handling of potential symbolic links the
5452	  host's jail rc.d(8) script is vulnerable to "symlink
5453	  attacks".  By replacing /var/log/console.log inside the jail
5454	  with a symbolic link it is possible for the superuser (root)
5455	  inside the jail to overwrite files on the host system outside
5456	  the jail with arbitrary content.  This in turn can be used to
5457	  execute arbitrary commands with non-jailed superuser
5458	  privileges.</p>
5459	<p>Similarly, by changing directory mount points inside the
5460	  jail file system structure into symbolic links, it may be
5461	  possible for a jailed attacker to mount file systems which
5462	  were meant to be mounted inside the jail at arbitrary points
5463	  in the host file system structure, or to unmount arbitrary
5464	  file systems on the host system.</p>
5465	<p>NOTE WELL: The above vulnerabilities occur only when a jail
5466	  is being started or stopped using the host's jail rc.d(8)
5467	  script; once started (and until stopped), running jails
5468	  cannot exploit this.</p>
5469	<h1>Workaround:</h1>
5470	<p>If the sysctl(8) variable security.jail.chflags_allowed is
5471	  set to 0 (the default), setting the "sunlnk" system flag on
5472	  /var, /var/log, /var/log/console.log, and all file system
5473	  mount points and their parent directories inside the jail(s)
5474	  will ensure that the console log file and mount points are
5475	  not replaced by symbolic links.  If this is done while jails
5476	  are running, the administrator must check that an attacker
5477	  has not replaced any directories with symlinks after setting
5478	  the "sunlnk" flag.</p>
5479      </body>
5480    </description>
5481    <references>
5482      <cvename>CVE-2007-0166</cvename>
5483      <freebsdsa>SA-07:01.jail</freebsdsa>
5484    </references>
5485    <dates>
5486      <discovery>2007-01-11</discovery>
5487      <entry>2007-02-27</entry>
5488      <modified>2016-08-09</modified>
5489    </dates>
5490  </vuln>
5491
5492  <vuln vid="44449bf7-c69b-11db-9f82-000e0c2e438a">
5493    <topic>gtar -- name mangling symlink vulnerability</topic>
5494    <affects>
5495      <package>
5496	<name>FreeBSD</name>
5497	<range><ge>5.5</ge><lt>5.5_9</lt></range>
5498	<range><ge>4.11</ge><lt>4.11_26</lt></range>
5499      </package>
5500    </affects>
5501    <description>
5502      <body xmlns="http://www.w3.org/1999/xhtml">
5503	<h1>Problem Description:</h1>
5504	<p>Symlinks created using the "GNUTYPE_NAMES" tar extension can
5505	  be absolute due to lack of proper sanity checks.</p>
5506	<h1>Impact:</h1>
5507	<p>If an attacker can get a user to extract a specially crafted
5508	  tar archive the attacker can overwrite arbitrary files with
5509	  the permissions of the user running gtar.  If file system
5510	  permissions allow it, this may allow the attacker to overwrite
5511	  important system file (if gtar is being run as root), or
5512	  important user configuration files such as .tcshrc or .bashrc,
5513	  which would allow the attacker to run arbitrary commands.</p>
5514	<h1>Workaround:</h1>
5515	<p>Use "bsdtar", which is the default tar implementation in
5516	  FreeBSD 5.3 and higher.  For FreeBSD 4.x, bsdtar is available
5517	  in the FreeBSD Ports Collection as
5518	  ports/archivers/libarchive.</p>
5519      </body>
5520    </description>
5521    <references>
5522      <cvename>CVE-2006-6097</cvename>
5523      <freebsdsa>SA-06:26.gtar</freebsdsa>
5524    </references>
5525    <dates>
5526      <discovery>2006-12-06</discovery>
5527      <entry>2007-02-27</entry>
5528      <modified>2016-08-09</modified>
5529    </dates>
5530  </vuln>
5531
5532  <vuln vid="5c554c0f-c69a-11db-9f82-000e0c2e438a">
5533    <topic>FreeBSD -- Kernel memory disclosure in firewire(4)</topic>
5534    <affects>
5535      <package>
5536	<name>FreeBSD</name>
5537	<range><ge>6.1</ge><lt>6.1_11</lt></range>
5538	<range><ge>6.0</ge><lt>6.2_16</lt></range>
5539	<range><ge>5.5</ge><lt>5.5_9</lt></range>
5540	<range><ge>4.11</ge><lt>4.11_26</lt></range>
5541      </package>
5542    </affects>
5543    <description>
5544      <body xmlns="http://www.w3.org/1999/xhtml">
5545	<h1>Problem Description:</h1>
5546	<p>In the FW_GCROM ioctl, a signed integer comparison is used
5547	  instead of an unsigned integer comparison when computing the
5548	  length of a buffer to be copied from the kernel into the
5549	  calling application.</p>
5550	<h1>Impact:</h1>
5551	<p>A user in the "operator" group can read the contents of
5552	  kernel memory.  Such memory might contain sensitive
5553	  information, such as portions of the file cache or terminal
5554	  buffers.  This information might be directly useful, or it
5555	  might be leveraged to obtain elevated privileges in some way;
5556	  for example, a terminal buffer might include a user-entered
5557	  password.</p>
5558	<h1>Workaround:</h1>
5559	<p>No workaround is available, but systems without IEEE 1394
5560	  ("FireWire") interfaces are not vulnerable.  (Note that
5561	  systems with IEEE 1394 interfaces are affected regardless of
5562	  whether any devices are attached.)</p>
5563	<p>Note also that FreeBSD does not have any non-root users in
5564	  the "operator" group by default; systems on which no users
5565	  have been added to this group are therefore also not
5566	  vulnerable.</p>
5567      </body>
5568    </description>
5569    <references>
5570      <cvename>CVE-2006-6013</cvename>
5571      <freebsdsa>SA-06:25.kmem</freebsdsa>
5572    </references>
5573    <dates>
5574      <discovery>2006-12-06</discovery>
5575      <entry>2007-02-27</entry>
5576      <modified>2016-08-09</modified>
5577    </dates>
5578  </vuln>
5579
5580  <vuln vid="792bc222-c5d7-11db-9f82-000e0c2e438a">
5581    <topic>libarchive -- Infinite loop in corrupt archives handling in libarchive</topic>
5582    <affects>
5583      <package>
5584	<name>libarchive</name>
5585	<range><lt>1.3.1</lt></range>
5586      </package>
5587    </affects>
5588    <description>
5589      <body xmlns="http://www.w3.org/1999/xhtml">
5590	<h1>Problem Description:</h1>
5591	<p>If the end of an archive is reached while attempting to
5592	  "skip" past a region of an archive, libarchive will enter an
5593	  infinite loop wherein it repeatedly attempts (and fails) to
5594	  read further data.</p>
5595	<h1>Impact:</h1>
5596	<p>An attacker able to cause a system to extract (via "tar -x"
5597	  or another application which uses libarchive) or list the
5598	  contents (via "tar -t" or another libarchive-using
5599	  application) of an archive provided by the attacker can cause
5600	  libarchive to enter an infinite loop and use all available
5601	  CPU time.</p>
5602	<h1>Workaround:</h1>
5603	<p>No workaround is available.</p>
5604      </body>
5605    </description>
5606    <references>
5607      <cvename>CVE-2006-5680</cvename>
5608      <freebsdsa>SA-06:24.libarchive</freebsdsa>
5609    </references>
5610    <dates>
5611      <discovery>2006-11-08</discovery>
5612      <entry>2007-02-26</entry>
5613    </dates>
5614  </vuln>
5615
5616  <vuln vid="0f37d765-c5d4-11db-9f82-000e0c2e438a">
5617    <topic>OpenSSL -- Multiple problems in crypto(3)</topic>
5618    <affects>
5619      <package>
5620	<name>openssl</name>
5621	<range><lt>0.9.7l_0</lt></range>
5622	<range><ge>0.9.8</ge><lt>0.9.8d_0</lt></range>
5623      </package>
5624      <package>
5625	<name>FreeBSD</name>
5626	<range><ge>6.1</ge><lt>6.1_9</lt></range>
5627	<range><ge>6.0</ge><lt>6.0_14</lt></range>
5628	<range><ge>5.5</ge><lt>5.5_7</lt></range>
5629	<range><ge>5.4</ge><lt>5.4_21</lt></range>
5630	<range><ge>5.3</ge><lt>5.3_36</lt></range>
5631	<range><ge>4.11</ge><lt>4.11_24</lt></range>
5632      </package>
5633    </affects>
5634    <description>
5635      <body xmlns="http://www.w3.org/1999/xhtml">
5636	<h1>Problem Description:</h1>
5637	<p>Several problems have been found in OpenSSL:</p>
5638	<ul>
5639	  <li>During the parsing of certain invalid ASN1 structures an
5640	    error condition is mishandled, possibly resulting in an
5641	    infinite loop.</li>
5642	  <li>A buffer overflow exists in the SSL_get_shared_ciphers
5643	    function.</li>
5644	  <li>A NULL pointer may be dereferenced in the SSL version 2
5645	    client code.</li>
5646	</ul>
5647	<p>In addition, many applications using OpenSSL do not perform
5648	  any validation of the lengths of public keys being used.</p>
5649	<h1>Impact:</h1>
5650	<p>Servers which parse ASN1 data from untrusted sources may be
5651	  vulnerable to a denial of service attack.</p>
5652	<p>An attacker accessing a server which uses SSL version 2 may
5653	  be able to execute arbitrary code with the privileges of that
5654	  server.</p>
5655	<p>A malicious SSL server can cause clients connecting using
5656	  SSL version 2 to crash.</p>
5657	<p>Applications which perform public key operations using
5658	  untrusted keys may be vulnerable to a denial of service
5659	  attack.</p>
5660	<h1>Workaround:</h1>
5661	<p>No workaround is available, but not all of the
5662	  vulnerabilities mentioned affect all applications.</p>
5663      </body>
5664    </description>
5665    <references>
5666      <cvename>CVE-2006-2937</cvename>
5667      <cvename>CVE-2006-2938</cvename>
5668      <cvename>CVE-2006-2940</cvename>
5669      <cvename>CVE-2006-3738</cvename>
5670      <cvename>CVE-2006-4343</cvename>
5671      <freebsdsa>SA-06:23.openssl</freebsdsa>
5672    </references>
5673    <dates>
5674      <discovery>2006-09-28</discovery>
5675      <entry>2007-02-26</entry>
5676      <modified>2016-08-09</modified>
5677    </dates>
5678  </vuln>
5679
5680  <vuln vid="12bd6ecf-c430-11db-95c5-000c6ec775d9">
5681    <topic>mozilla -- multiple vulnerabilities</topic>
5682    <affects>
5683      <package>
5684	<name>firefox</name>
5685	<range><lt>1.5.0.10,1</lt></range>
5686	<range><gt>2.*,1</gt><lt>2.0.0.2,1</lt></range>
5687      </package>
5688      <package>
5689	<name>linux-firefox</name>
5690	<range><lt>1.5.0.10</lt></range>
5691      </package>
5692      <package>
5693	<name>lightning</name>
5694	<range><lt>0.3.1</lt></range>
5695      </package>
5696      <package>
5697	<name>seamonkey</name>
5698	<name>linux-seamonkey</name>
5699	<range><lt>1.0.8</lt></range>
5700	<range><ge>1.1</ge><lt>1.1.1</lt></range>
5701      </package>
5702      <package>
5703	<name>thunderbird</name>
5704	<name>linux-thunderbird</name>
5705	<name>mozilla-thunderbird</name>
5706	<range><lt>1.5.0.10</lt></range>
5707      </package>
5708      <package>
5709	<name>linux-firefox-devel</name>
5710	<range><lt>3.0.a2007.04.18</lt></range>
5711      </package>
5712      <package>
5713	<name>linux-seamonkey-devel</name>
5714	<range><lt>1.5.a2007.04.18</lt></range>
5715      </package>
5716      <package>
5717	<name>firefox-ja</name>
5718	<name>linux-mozilla-devel</name>
5719	<name>linux-mozilla</name>
5720	<name>mozilla</name>
5721	<range><gt>0</gt></range>
5722      </package>
5723    </affects>
5724    <description>
5725      <body xmlns="http://www.w3.org/1999/xhtml">
5726	<p>The Mozilla Foundation reports of multiple security issues
5727	  in Firefox, Seamonkey, and Thunderbird.  Several of these
5728	  issues can probably be used to run arbitrary code with the
5729	  privilege of the user running the program.</p>
5730	<blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.2">
5731	  <ul>
5732	    <li>MFSA 2007-08 onUnload + document.write() memory corruption</li>
5733	    <li>MFSA 2007-07 Embedded nulls in location.hostname confuse same-domain checks</li>
5734	    <li>MFSA 2007-06 Mozilla Network Security Services (NSS) SSLv2 buffer overflow</li>
5735	    <li>MFSA 2007-05 XSS and local file access by opening blocked popups</li>
5736	    <li>MFSA 2007-04 Spoofing using custom cursor and CSS3 hotspot</li>
5737	    <li>MFSA 2007-03 Information disclosure through cache collisions</li>
5738	    <li>MFSA 2007-02 Improvements to help protect against Cross-Site Scripting attacks</li>
5739	    <li>MFSA 2007-01 Crashes with evidence of memory corruption (rv:1.8.0.10/1.8.1.2)</li>
5740	  </ul>
5741	</blockquote>
5742      </body>
5743    </description>
5744    <references>
5745      <cvename>CVE-2006-6077</cvename>
5746      <cvename>CVE-2007-0008</cvename>
5747      <cvename>CVE-2007-0009</cvename>
5748      <cvename>CVE-2007-0775</cvename>
5749      <cvename>CVE-2007-0776</cvename>
5750      <cvename>CVE-2007-0777</cvename>
5751      <cvename>CVE-2007-0778</cvename>
5752      <cvename>CVE-2007-0779</cvename>
5753      <cvename>CVE-2007-0780</cvename>
5754      <cvename>CVE-2007-0800</cvename>
5755      <cvename>CVE-2007-0981</cvename>
5756      <cvename>CVE-2007-0995</cvename>
5757      <cvename>CVE-2007-1092</cvename>
5758      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482</url>
5759      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483</url>
5760      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</url>
5761      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</url>
5762      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-03.html</url>
5763      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-04.html</url>
5764      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</url>
5765      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</url>
5766      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-07.html</url>
5767      <url>http://www.mozilla.org/security/announce/2007/mfsa2007-08.html</url>
5768    </references>
5769    <dates>
5770      <discovery>2007-02-23</discovery>
5771      <entry>2007-02-24</entry>
5772      <modified>2007-04-19</modified>
5773    </dates>
5774  </vuln>
5775
5776  <vuln vid="afdf500f-c1f6-11db-95c5-000c6ec775d9">
5777    <topic>snort -- DCE/RPC preprocessor vulnerability</topic>
5778    <affects>
5779      <package>
5780	<name>snort</name>
5781	<range><ge>2.6.1</ge><lt>2.6.1.3</lt></range>
5782      </package>
5783    </affects>
5784    <description>
5785      <body xmlns="http://www.w3.org/1999/xhtml">
5786	<p>A IBM Internet Security Systems Protection Advisory
5787	  reports:</p>
5788	<blockquote cite="http://iss.net/threats/257.html">
5789	  <p>Snort is vulnerable to a stack-based buffer overflow as a
5790	    result of DCE/RPC reassembly. This vulnerability is in a
5791	    dynamic-preprocessor enabled in the default configuration,
5792	    and the configuration for this preprocessor allows for
5793	    auto-recognition of SMB traffic to perform reassembly
5794	    on. No checks are performed to see if the traffic is part
5795	    of a valid TCP session, and multiple Write AndX requests
5796	    can be chained in the same TCP segment. As a result, an
5797	    attacker can exploit this overflow with a single TCP PDU
5798	    sent across a network monitored by Snort or Sourcefire.</p>
5799	  <p>Snort users who cannot upgrade immediately are advised to
5800	    disable the DCE/RPC preprocessor by removing the DCE/RPC
5801	    preprocessor directives from snort.conf and restarting
5802	    Snort. However, be advised that disabling the DCE/RPC
5803	    preprocessor reduces detection capabilities for attacks in
5804	    DCE/RPC traffic. After upgrading, customers should
5805	    re-enable the DCE/RPC preprocessor.</p>
5806	</blockquote>
5807      </body>
5808    </description>
5809    <references>
5810      <certvu>196240</certvu>
5811      <cvename>CVE-2006-5276</cvename>
5812      <url>http://xforce.iss.net/xforce/xfdb/31275</url>
5813      <url>http://www.snort.org/docs/advisory-2007-02-19.html</url>
5814    </references>
5815    <dates>
5816      <discovery>2007-02-19</discovery>
5817      <entry>2007-02-21</entry>
5818    </dates>
5819  </vuln>
5820
5821  <vuln vid="94234e00-be8a-11db-b2ec-000c6ec775d9">
5822    <topic>rar -- password prompt buffer overflow vulnerability</topic>
5823    <affects>
5824      <package>
5825	<name>rar</name>
5826	<range><lt>3.70.b1,1</lt></range>
5827      </package>
5828      <package>
5829	<name>unrar</name>
5830	<name>zh-unrar</name>
5831	<range><lt>3.70.b1,4</lt></range>
5832      </package>
5833    </affects>
5834    <description>
5835      <body xmlns="http://www.w3.org/1999/xhtml">
5836	<p>iDefense reports:</p>
5837	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472">
5838	  <p>Remote exploitation of a stack based buffer overflow
5839	    vulnerability in RARLabs Unrar may allow an attacker to
5840	    execute arbitrary code with the privileges of the user
5841	    opening the archive.</p>
5842	  <p>Unrar is prone to a stack based buffer overflow when
5843	    processing specially crafted password protected
5844	    archives.</p>
5845	  <p>If users are using the vulnerable command line based
5846	    unrar, they still need to interact with the program in
5847	    order to trigger the vulnerability. They must respond to
5848	    the prompt asking for the password, after which the
5849	    vulnerability will be triggered. They do not need to enter
5850	    a correct password, but they must at least push the enter
5851	    key.</p>
5852	</blockquote>
5853      </body>
5854    </description>
5855    <references>
5856      <bid>22447</bid>
5857      <cvename>CVE-2007-0855</cvename>
5858      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472</url>
5859      <url>http://www.rarsoft.com/rarnew.htm</url>
5860    </references>
5861    <dates>
5862      <discovery>2007-02-07</discovery>
5863      <entry>2007-02-17</entry>
5864    </dates>
5865  </vuln>
5866
5867  <vuln vid="7fcf1727-be71-11db-b2ec-000c6ec775d9">
5868    <topic>php -- multiple vulnerabilities</topic>
5869    <affects>
5870      <package>
5871	<name>php5-imap</name>
5872	<name>php5-odbc</name>
5873	<name>php5-session</name>
5874	<name>php5-shmop</name>
5875	<name>php5-sqlite</name>
5876	<name>php5-wddx</name>
5877	<name>php5</name>
5878	<range><lt>5.2.1_2</lt></range>
5879      </package>
5880      <package>
5881	<name>php4-odbc</name>
5882	<name>php4-session</name>
5883	<name>php4-shmop</name>
5884	<name>php4-wddx</name>
5885	<name>php4</name>
5886	<range><lt>4.4.5</lt></range>
5887      </package>
5888      <package>
5889	<name>mod_php4-twig</name>
5890	<name>mod_php4</name>
5891	<name>mod_php5</name>
5892	<name>mod_php</name>
5893	<name>php4-cgi</name>
5894	<name>php4-cli</name>
5895	<name>php4-dtc</name>
5896	<name>php4-horde</name>
5897	<name>php4-nms</name>
5898	<name>php5-cgi</name>
5899	<name>php5-cli</name>
5900	<name>php5-dtc</name>
5901	<name>php5-horde</name>
5902	<name>php5-nms</name>
5903	<range><ge>4</ge><lt>4.4.5</lt></range>
5904	<range><ge>5</ge><lt>5.2.1_2</lt></range>
5905      </package>
5906    </affects>
5907    <description>
5908      <body xmlns="http://www.w3.org/1999/xhtml">
5909	<p>Multiple vulnerabilities have been found in PHP, including:
5910	  buffer overflows, stack overflows, format string, and
5911	  information disclosure vulnerabilities.</p>
5912	<p>The session extension contained <code>safe_mode</code> and
5913	  <code>open_basedir</code> bypasses, but the FreeBSD Security
5914	  Officer does not consider these real security
5915	  vulnerabilities, since <code>safe_mode</code> and
5916	  <code>open_basedir</code> are insecure by design and should
5917	  not be relied upon.</p>
5918      </body>
5919    </description>
5920    <references>
5921      <cvename>CVE-2007-0905</cvename>
5922      <cvename>CVE-2007-0906</cvename>
5923      <cvename>CVE-2007-0907</cvename>
5924      <cvename>CVE-2007-0908</cvename>
5925      <cvename>CVE-2007-0909</cvename>
5926      <cvename>CVE-2007-0910</cvename>
5927      <cvename>CVE-2007-0988</cvename>
5928      <url>http://secunia.com/advisories/24089/</url>
5929      <url>http://www.php.net/releases/4_4_5.php</url>
5930      <url>http://www.php.net/releases/5_2_1.php</url>
5931    </references>
5932    <dates>
5933      <discovery>2007-02-09</discovery>
5934      <entry>2007-02-17</entry>
5935      <modified>2013-04-01</modified>
5936    </dates>
5937  </vuln>
5938
5939  <vuln vid="7bb127c1-a5aa-11db-9ddc-0011098b2f36">
5940    <topic>joomla -- multiple remote vulnerabilities</topic>
5941    <affects>
5942      <package>
5943	<name>joomla</name>
5944	<range><lt>1.0.12</lt></range>
5945      </package>
5946    </affects>
5947    <description>
5948      <body xmlns="http://www.w3.org/1999/xhtml">
5949	<p>Secunia reports:</p>
5950	<blockquote cite="http://secunia.com/advisories/23563/">
5951	  <p>Some vulnerabilities have been reported in Joomla!, where some
5952	    have unknown impacts and one can be exploited by malicious people
5953	    to conduct cross-site scripting attacks.</p>
5954	  <ol>
5955	    <li>Input passed to an unspecified parameter is not properly
5956	      sanitised before being returned to the user.  This can be
5957	      exploited to execute arbitrary HTML and script code in a
5958	      user's browser session in context of an affected site.</li>
5959	    <li>The vulnerabilities are caused due to unspecified errors
5960	      in Joomla!.  The vendor describes them as "several low level
5961	      security issues". No further information is currently
5962	      available.</li>
5963	    </ol>
5964	</blockquote>
5965      </body>
5966    </description>
5967    <references>
5968      <bid>21810</bid>
5969      <cvename>CVE-2006-6832</cvename>
5970      <cvename>CVE-2006-6833</cvename>
5971      <cvename>CVE-2006-6834</cvename>
5972      <url>http://secunia.com/advisories/23563/</url>
5973    </references>
5974    <dates>
5975      <discovery>2006-12-29</discovery>
5976      <entry>2007-01-17</entry>
5977    </dates>
5978  </vuln>
5979
5980  <vuln vid="1374b96c-a1c2-11db-9ddc-0011098b2f36">
5981    <topic>sircd -- remote reverse DNS buffer overflow</topic>
5982    <affects>
5983      <package>
5984       <name>sircd</name>
5985       <range><le>0.4.0</le></range>
5986      </package>
5987    </affects>
5988    <description>
5989      <body xmlns="http://www.w3.org/1999/xhtml">
5990	<p>Secunia reports:</p>
5991	<blockquote cite="http://secunia.com/advisories/8153/">
5992	 <p>A vulnerability in sircd can be exploited by a malicious person
5993	   to compromise a vulnerable system.  The vulnerability is caused
5994	   by a boundary error in the code handling reverse DNS lookups,
5995	   when a user connects to the service. If the FQDN (Fully Qualified
5996	   Domain Name) returned is excessively long, the allocated buffer
5997	   is overflowed making it possible to execute arbitrary code on the
5998	   system with the privileges of the sircd daemon.</p>
5999       </blockquote>
6000      </body>
6001    </description>
6002    <references>
6003      <bid>6924</bid>
6004      <url>http://secunia.com/advisories/8153</url>
6005    </references>
6006    <dates>
6007      <discovery>2003-02-24</discovery>
6008      <entry>2007-01-15</entry>
6009    </dates>
6010  </vuln>
6011
6012  <vuln vid="e92d8f6b-a1c0-11db-9ddc-0011098b2f36">
6013    <topic>sircd -- remote operator privilege escalation vulnerability</topic>
6014    <affects>
6015      <package>
6016       <name>sircd</name>
6017       <range><ge>0</ge></range>
6018      </package>
6019    </affects>
6020    <description>
6021      <body xmlns="http://www.w3.org/1999/xhtml">
6022	<p>Secunia reports:</p>
6023	<blockquote cite="http://secunia.com/advisories/10274/">
6024	 <p>A vulnerability has been reported in sircd, which can be
6025	   exploited by malicious users to gain operator privileges.
6026	   The problem is that any user reportedly can set their usermode
6027	   to operator.  The vulnerability has been reported in
6028	   versions 0.5.2 and 0.5.3. Other versions may also be affected.</p>
6029       </blockquote>
6030      </body>
6031    </description>
6032    <references>
6033      <bid>9097</bid>
6034      <url>http://secunia.com/advisories/10274/</url>
6035    </references>
6036    <dates>
6037      <discovery>2003-11-20</discovery>
6038      <entry>2007-01-15</entry>
6039    </dates>
6040  </vuln>
6041
6042  <vuln vid="41da2ba4-a24e-11db-bd24-000f3dcc6a5d">
6043    <topic>cacti -- Multiple vulnerabilities</topic>
6044    <affects>
6045      <package>
6046	<name>cacti</name>
6047	<range><lt>0.8.6i.4</lt></range>
6048      </package>
6049    </affects>
6050    <description>
6051      <body xmlns="http://www.w3.org/1999/xhtml">
6052	<p>Secunia reports:</p>
6053	<blockquote cite="http://secunia.com/advisories/23528/">
6054	  <p>rgod has discovered four vulnerabilities in Cacti,
6055	    which can be exploited by malicious people to bypass
6056	    certain security restrictions, manipulate data
6057	    and compromise vulnerable systems.</p>
6058	</blockquote>
6059      </body>
6060    </description>
6061    <references>
6062      <url>http://secunia.com/advisories/23528/</url>
6063      <url>http://forums.cacti.net/about18846-0-asc-0.html</url>
6064    </references>
6065    <dates>
6066      <discovery>2006-12-28</discovery>
6067      <entry>2007-01-12</entry>
6068    </dates>
6069  </vuln>
6070
6071  <vuln vid="b2ff68b2-9f29-11db-a4e4-0211d87675b7">
6072    <topic>mplayer -- buffer overflow in the code for RealMedia RTSP streams.</topic>
6073    <affects>
6074      <package>
6075	<name>mplayer</name>
6076	<name>mplayer-esound</name>
6077	<name>mplayer-gtk</name>
6078	<name>mplayer-gtk2</name>
6079	<name>mplayer-gtk-esound</name>
6080	<name>mplayer-gtk2-esound</name>
6081	<range><lt>0.99.10_1</lt></range>
6082      </package>
6083    </affects>
6084    <description>
6085      <body xmlns="http://www.w3.org/1999/xhtml">
6086	<blockquote cite="http://www.mplayerhq.hu/design7/news.html">
6087	<p>A potential buffer overflow was found in the code used to handle
6088	RealMedia RTSP streams. When checking for matching asm rules, the code
6089	stores the results in a fixed-size array, but no boundary checks are
6090	performed. This may lead to a buffer overflow if the user is tricked
6091	into connecting to a malicious server. Since the attacker cannot write
6092	arbitrary data into the buffer, creating an exploit is very hard; but a
6093	DoS attack is easily made.
6094	A fix for this problem was committed to SVN on Sun Dec 31 13:27:53 2006
6095	UTC as r21799. The fix involves three files: stream/realrtsp/asmrp.c,
6096	stream/realrtsp/asmrp.h and stream/realrtsp/real.c.</p>
6097	</blockquote>
6098      </body>
6099    </description>
6100    <references>
6101      <freebsdpr>ports/107217</freebsdpr>
6102      <cvename>CVE-2006-6172</cvename>
6103      <url>http://www.mplayerhq.hu/design7/news.html</url>
6104    </references>
6105    <dates>
6106      <discovery>2006-12-31</discovery>
6107      <entry>2007-01-08</entry>
6108    </dates>
6109  </vuln>
6110
6111  <vuln vid="37e30313-9d8c-11db-858b-0060084a00e5">
6112    <topic>fetchmail -- crashes when refusing a message bound for an MDA</topic>
6113    <affects>
6114      <package>
6115	<name>fetchmail</name>
6116	<range><ge>6.3.5</ge><lt>6.3.6</lt></range>
6117      </package>
6118    </affects>
6119    <description>
6120      <body xmlns="http://www.w3.org/1999/xhtml">
6121	<p>Matthias Andree reports:</p>
6122	<blockquote cite="http://www.fetchmail.info/fetchmail-SA-2006-03.txt">
6123	  <p>When delivering messages to a message delivery agent by means
6124	    of the "mda" option, fetchmail can crash (by passing
6125	    a NULL pointer to ferror() and fflush()) when refusing a message.
6126	    SMTP and LMTP delivery modes aren't affected.</p>
6127	</blockquote>
6128      </body>
6129    </description>
6130    <references>
6131      <cvename>CVE-2006-5974</cvename>
6132      <url>http://www.fetchmail.info/fetchmail-SA-2006-03.txt</url>
6133    </references>
6134    <dates>
6135      <discovery>2007-01-04</discovery>
6136      <entry>2007-01-06</entry>
6137    </dates>
6138  </vuln>
6139
6140  <vuln vid="5238ac45-9d8c-11db-858b-0060084a00e5">
6141    <topic>fetchmail -- TLS enforcement problem/MITM attack/password exposure</topic>
6142    <affects>
6143      <package>
6144	<name>fetchmail</name>
6145	<range><lt>6.3.6</lt></range>
6146      </package>
6147    </affects>
6148    <description>
6149      <body xmlns="http://www.w3.org/1999/xhtml">
6150	<p>Matthias Andree reports:</p>
6151	<blockquote cite="http://www.fetchmail.info/fetchmail-SA-2006-02.txt">
6152	  <p>Fetchmail has had several longstanding password disclosure
6153	    vulnerabilities.</p>
6154	  <ul>
6155	    <li>sslcertck/sslfingerprint options should have implied
6156	      "sslproto tls1" in order to enforce TLS negotiation,
6157	      but did not.</li>
6158	    <li>Even with "sslproto tls1" in the config, fetches
6159	      would go ahead in plain text if STLS/STARTTLS wasn't available
6160	      (not advertised, or advertised but rejected).</li>
6161	    <li>POP3 fetches could completely ignore all TLS options
6162	      whether available or not because it didn't reliably issue
6163	      CAPA before checking for STLS support - but CAPA is a
6164	      requisite for STLS. Whether or not CAPAbilities were probed,
6165	      depended on the "auth" option. (Fetchmail only
6166	      tried CAPA if the auth option was not set at all, was set
6167	      to gssapi, kerberos, kerberos_v4, otp, or cram-md5.)</li>
6168	    <li>POP3 could fall back to using plain text passwords, even
6169	      if strong authentication had been configured.</li>
6170	    <li>POP2 would not complain if strong authentication or TLS
6171	      had been requested.</li>
6172	  </ul>
6173	</blockquote>
6174      </body>
6175    </description>
6176    <references>
6177      <cvename>CVE-2006-5867</cvename>
6178      <url>http://www.fetchmail.info/fetchmail-SA-2006-02.txt</url>
6179    </references>
6180    <dates>
6181      <discovery>2007-01-04</discovery>
6182      <entry>2007-01-06</entry>
6183    </dates>
6184  </vuln>
6185
6186  <vuln vid="78ad2525-9d0c-11db-a5f6-000c6ec775d9">
6187    <topic>opera -- multiple vulnerabilities</topic>
6188    <affects>
6189      <package>
6190	<name>opera</name>
6191	<name>opera-devel</name>
6192	<name>linux-opera</name>
6193	<range><lt>9.10</lt></range>
6194      </package>
6195    </affects>
6196    <description>
6197      <body xmlns="http://www.w3.org/1999/xhtml">
6198	<p>iDefense reports:</p>
6199	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457">
6200	  <p>The vulnerability specifically exists due to Opera
6201	    improperly processing a JPEG DHT marker. The DHT marker is
6202	    used to define a Huffman Table which is used for decoding
6203	    the image data. An invalid number of index bytes in the
6204	    DHT marker will trigger a heap overflow with partially
6205	    user controlled data.</p>
6206	  <p>Exploitation of this vulnerability would allow an
6207	    attacker to execute arbitrary code on the affected
6208	    host. The attacker would first need to construct a website
6209	    containing the malicious image and trick the vulnerable
6210	    user into visiting the site. This would trigger the
6211	    vulnerability and allow the code to execute with the
6212	    privileges of the local user.</p>
6213	</blockquote>
6214	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458">
6215	  <p>A flaw exists within Opera's Javascript SVG
6216	    implementation. When processing a
6217	    createSVGTransformFromMatrix request Opera does not
6218	    properly validate the type of object passed to the
6219	    function. Passing an incorrect object to this function can
6220	    result in it using a pointer that is user controlled when
6221	    it attempts to make the virtual function call.</p>
6222	  <p>Exploitation of this vulnerability would allow an
6223	    attacker to execute arbitrary code on the affected
6224	    host. The attacker would first need to construct a website
6225	    containing the malicious JavaScript and trick the
6226	    vulnerable user into visiting the site. This would trigger
6227	    the vulnerability and allow the code to execute with the
6228	    privileges of the local user.</p>
6229	</blockquote>
6230      </body>
6231    </description>
6232    <references>
6233      <cvename>CVE-2007-0126</cvename>
6234      <cvename>CVE-2007-0127</cvename>
6235      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457</url>
6236      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458</url>
6237      <url>http://www.opera.com/support/search/supsearch.dml?index=851</url>
6238      <url>http://www.opera.com/support/search/supsearch.dml?index=852</url>
6239    </references>
6240    <dates>
6241      <discovery>2007-01-05</discovery>
6242      <entry>2007-01-05</entry>
6243      <modified>2010-05-12</modified>
6244    </dates>
6245  </vuln>
6246
6247  <vuln vid="3d8d3548-9d02-11db-a541-000ae42e9b93">
6248    <topic>drupal -- multiple vulnerabilities</topic>
6249    <affects>
6250      <package>
6251	<name>drupal</name>
6252	<range><gt>4.7</gt><lt>4.7.5</lt></range>
6253	<range><lt>4.6.11</lt></range>
6254      </package>
6255    </affects>
6256    <description>
6257      <body xmlns="http://www.w3.org/1999/xhtml">
6258	<p>The Drupal security team reports:</p>
6259	<blockquote cite="http://drupal.org/files/sa-2007-001/advisory.txt">
6260	  <p>A few arguments passed via URLs are not properly sanitized
6261	    before display.  When an attacker is able to entice an
6262	    administrator to follow a specially crafted link, arbitrary
6263	    HTML and script code can be injected and executed in the
6264	    victim's session. Such an attack may lead to administrator
6265	    access if certain conditions are met.</p>
6266	</blockquote>
6267	<blockquote cite="http://drupal.org/files/sa-2007-002/advisory.txt">
6268	  <p>The way page caching was implemented allows a denial of
6269	    service attack. An attacker has to have the ability to post
6270	    content on the site. He or she would then be able to poison
6271	    the page cache, so that it returns cached 404 page not found
6272	    errors for existing pages.</p>
6273	  <p>If the page cache is not enabled, your site is not vulnerable.
6274	    The vulnerability only affects sites running on top of MySQL.</p>
6275	</blockquote>
6276      </body>
6277    </description>
6278    <references>
6279      <cvename>CVE-2007-0136</cvename>
6280      <url>http://drupal.org/files/sa-2007-001/advisory.txt</url>
6281      <url>http://drupal.org/files/sa-2007-002/advisory.txt</url>
6282    </references>
6283    <dates>
6284      <discovery>2007-01-05</discovery>
6285      <entry>2007-01-05</entry>
6286      <modified>2010-05-12</modified>
6287    </dates>
6288  </vuln>
6289
6290  <vuln vid="9347d82d-9a66-11db-b271-000e35248ad7">
6291    <topic>w3m -- format string vulnerability</topic>
6292    <affects>
6293      <package>
6294	<name>w3m</name>
6295	<name>w3m-img</name>
6296	<name>w3m-m17n</name>
6297	<name>w3m-m17n-img</name>
6298	<name>ja-w3m</name>
6299	<name>ja-w3m-img</name>
6300	<range><lt>0.5.1_6</lt></range>
6301      </package>
6302    </affects>
6303    <description>
6304      <body xmlns="http://www.w3.org/1999/xhtml">
6305	<p>An anonymous person reports:</p>
6306	<blockquote cite="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1612792&amp;group_id=39518&amp;atid=425439">
6307	  <p>w3m-0.5.1 crashes when using the -dump or -backend options to
6308	    open a HTTPS URL with a SSL certificate where the CN contains
6309	    "%n%n%n%n%n%n".</p>
6310	</blockquote>
6311      </body>
6312    </description>
6313    <references>
6314      <bid>21735</bid>
6315      <cvename>CVE-2006-6772</cvename>
6316      <url>http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1612792&amp;group_id=39518&amp;atid=425439</url>
6317      <url>http://secunia.com/advisories/23492/</url>
6318    </references>
6319    <dates>
6320      <discovery>2006-12-10</discovery>
6321      <entry>2007-01-03</entry>
6322    </dates>
6323  </vuln>
6324