_____________________________________________________________________
Scott Fosseen - Systems Engineer - Arrowhead AEA
www.aea5.k12.ia.us/aeaphone.nsf/web/fosseenscott -
_____________________________________________________________________
I think computer viruses should count as life. I think it says
something about human nature that the only form of life we have
created so far is purely destructive. We've created life in our own
image.  - Stephen Hawking
_____________________________________________________________________

----- Original Message -----
From: "X-Force" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, December 30, 2002 12:18 PM
Subject: ISS Security Alert Summary AS02-52


> -----BEGIN PGP SIGNED MESSAGE-----
>
> Internet Security Systems Security Alert Summary AS02-52
> December 30, 2002
>
> X-Force Vulnerability and Threat Database:
> http://www.iss.net/security_center
>
> To receive these Alert Summaries, as well as other Alerts and
> Advisories, subscribe to the Internet Security Systems Alert
> mailing list at:
> http://www.iss.net/security_center/maillists
>
> This summary is available at the following address:
> http://www.iss.net/security_center/alerts/AS02-52.php
> _____
> Contents:
> * 29 Reported Vulnerabilities
> * Risk Factor Key
> _____
>
>
> Date Reported:      12/16/2002
> Brief Description:  Apache HTTP Server printenv test CGI cross-site
>                     scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, Apache HTTP Server Any version
> Vulnerability:      apache-printenv-xss
> X-Force URL:        http://www.iss.net/security_center/static/10938.php
>
> Date Reported:      12/16/2002
> Brief Description:  Melange Chat System msgText chat_InterpretData()
>                     buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Linux Any version, Melange Chat System 1.10
> Vulnerability:      melange-msgtext-chatinterpretdata-bo
> X-Force URL:        http://www.iss.net/security_center/static/10939.php
>
> Date Reported:      12/17/2002
> Brief Description:  Oracle oracle.sh LD_LIBRARY_PATH environment
>                     variable could allow elevated privileges
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Linux Any version, Oracle9i Application Server Any
>                     version
> Vulnerability:      oracle-ldlibrarypath-gain-privileges
> X-Force URL:        http://www.iss.net/security_center/static/10924.php
>
> Date Reported:      12/19/2002
> Brief Description:  w-Agora editform.php could allow an attacker to
>                     include remote PHP files
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, w-Agora Any version
> Vulnerability:      wagora-editform-file-include
> X-Force URL:        http://www.iss.net/security_center/static/10919.php
>
> Date Reported:      12/19/2002
> Brief Description:  w-Agora editform.php cross-site scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, w-Agora Any version
> Vulnerability:      wagora-editform-xss
> X-Force URL:        http://www.iss.net/security_center/static/10920.php
>
> Date Reported:      12/19/2002
> Brief Description:  libpng file offset buffer overflow
> Risk Factor:        High
> Attack Type:        Host Based / Network Based
> Platforms:          Debian Linux 2.2, Debian Linux 3.0, libpng 1.2.5
>                     and earlier
> Vulnerability:      libpng-file-offset-bo
> X-Force URL:        http://www.iss.net/security_center/static/10925.php
>
> Date Reported:      12/19/2002
> Brief Description:  Oracle9i Application Server JSP source code
>                     disclosure
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Solaris Any version, Unix Any
>                     version, Windows NT Any version, Windows 2000 Any
>                     version, Oracle9i Application Server 9.0.2.0.0
> Vulnerability:      oracle-appserver-jsp-source
> X-Force URL:        http://www.iss.net/security_center/static/10928.php
>
> Date Reported:      12/19/2002
> Brief Description:  Oracle9i Application Server insecure default
>                     permissions
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Windows NT Any version, Windows 2000 Any version,
>                     Oracle9i Application Server 1.0.2.2
> Vulnerability:      oracle-appserver-insecure-permissions
> X-Force URL:        http://www.iss.net/security_center/static/10929.php
>
> Date Reported:      12/19/2002
> Brief Description:  Oracle9i Application Server WEB-INF directory is
>                     accessible
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Solaris Any version, Unix Any
>                     version, Windows NT Any version, Windows 2000 Any
>                     version, Oracle9i Application Server 9.0.2.0.0,
>                     Oracle9i Application Server 1.0.2.2, Oracle9i
>                     Application Server 9.0.2.0.1
> Vulnerability:      oracle-appserver-webinf-access
> X-Force URL:        http://www.iss.net/security_center/static/10930.php
>
> Date Reported:      12/19/2002
> Brief Description:  Dynamic Trojan Horse Network (DTHN) worm
>                     propagation
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Windows Any version
> Vulnerability:      dthn-worm
> X-Force URL:        http://www.iss.net/security_center/static/10931.php
>
> Date Reported:      12/20/2002
> Brief Description:  PHP-Nuke PHP mail() function CRLF injection
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, PHP-Nuke 6.0
> Vulnerability:      phpnuke-crlf-injection
> X-Force URL:        http://www.iss.net/security_center/static/10921.php
>
> Date Reported:      12/20/2002
> Brief Description:  nCipher PKCS#11 library insecure key generation and
>                     access control
> Risk Factor:        Medium
> Attack Type:        Host Based / Network Based
> Platforms:          Linux Any version, Windows NT 4.0, Solaris 2.6, HP-
>                     UX 10.20, Solaris 7, Windows 2000 Any version,
>                     Solaris 8, HP-UX 11, AIX 4.3.3, Solaris 9, AIX 5L,
>                     nCipher PKCS#11 library Any version
> Vulnerability:      ncipher-pkcs-library-insecure
> X-Force URL:        http://www.iss.net/security_center/static/10922.php
>
> Date Reported:      12/20/2002
> Brief Description:  KDE incorrect parameter quoting could allow remote
>                     command execution
> Risk Factor:        Medium
> Attack Type:        Host Based / Network Based
> Platforms:          Linux Any version, Unix Any version, Gentoo Linux
>                     Any version, K Desktop Environment (KDE) 3.0.5 and
>                     earlier
> Vulnerability:      kde-quoting-command-execution
> X-Force URL:        http://www.iss.net/security_center/static/10923.php
>
> Date Reported:      12/22/2002
> Brief Description:  MATLAB /tmp file symlink attack
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Unix Any version, MATLAB 6.5
> Vulnerability:      matlab-tmp-file-symlink
> X-Force URL:        http://www.iss.net/security_center/static/10926.php
>
> Date Reported:      12/22/2002
> Brief Description:  CHETCPASSWD could disclose the local shadow file
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, CHETCPASSWD
>                     1.2 and earlier
> Vulnerability:      chetcpasswd-shadow-file-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10946.php
>
> Date Reported:      12/23/2002
> Brief Description:  Hyperion FTP Server long directory name buffer
>                     overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Windows Any version, Hyperion FTP Server 2.8.11
> Vulnerability:      hyperion-long-directory-bo
> X-Force URL:        http://www.iss.net/security_center/static/10927.php
>
> Date Reported:      12/23/2002
> Brief Description:  KDE smbview command line password is viewable by
>                     other users
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Linux Any version, Unix Any version, K Desktop
>                     Environment (KDE) 3.0.5 and earlier
> Vulnerability:      kde-smbview-password-viewable
> X-Force URL:        http://www.iss.net/security_center/static/10933.php
>
> Date Reported:      12/23/2002
> Brief Description:  Internet Junkbuster proxy allows unauthorized
>                     connections
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Red Hat Linux 6.2, Internet Junkbuster 2.0.1
> Vulnerability:      internet-junkbuster-unauth-connect
> X-Force URL:        http://www.iss.net/security_center/static/10934.php
>
> Date Reported:      12/23/2002
> Brief Description:  CUPS and Xpdf pdftops filter integer overflow
> Risk Factor:        High
> Attack Type:        Host Based / Network Based
> Platforms:          Linux Any version, Unix Any version, CUPS (Common
>                     UNIX Printing System) prior to 1.1.18, Xpdf 2.01
>                     and earlier
> Vulnerability:      pdftops-integer-overflow
> X-Force URL:        http://www.iss.net/security_center/static/10937.php
>
> Date Reported:      12/24/2002
> Brief Description:  Solaris AUTH_DES RPC requests could allow elevated
>                     privileges
> Risk Factor:        High
> Attack Type:        Host Based / Network Based
> Platforms:          Solaris 2.5.1, Solaris 2.6, Solaris 7
> Vulnerability:      solaris-authdes-gain-privileges
> X-Force URL:        http://www.iss.net/security_center/static/10935.php
>
> Date Reported:      12/24/2002
> Brief Description:  monopd messaging framework buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Linux Any version, monopd 0.6.1 and earlier
> Vulnerability:      monopd-messaging-framework-bo
> X-Force URL:        http://www.iss.net/security_center/static/10947.php
>
> Date Reported:      12/25/2002
> Brief Description:  ProFTPD long PASS command buffer overflow
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          ProFTPD 1.2.5, Linux Any version, Unix Any version
> Vulnerability:      proftpd-long-password-bo
> X-Force URL:        http://www.iss.net/security_center/static/10932.php
>
> Date Reported:      12/25/2002
> Brief Description:  Internet Explorer multimedia file URL cross-site
>                     scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows Any version, Microsoft Internet Explorer
>                     6.0, Microsoft Internet Explorer 6.0 SP1
> Vulnerability:      ie-multimedia-url-xss
> X-Force URL:        http://www.iss.net/security_center/static/10945.php
>
> Date Reported:      12/27/2002
> Brief Description:  Typespeed command line buffer overflow
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          Debian Linux 2.2, Debian Linux 3.0, Typespeed 0.4.0
>                     and earlier
> Vulnerability:      typespeed-command-line-bo
> X-Force URL:        http://www.iss.net/security_center/static/10936.php
>
> Date Reported:      12/27/2002
> Brief Description:  SkyStream EMR5000 client shell buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          SkyStream EMR5000 1.16, SkyStream EMR5000 1.17,
>                     SkyStream EMR5000 1.18
> Vulnerability:      skystream-emr5000-shell-bo
> X-Force URL:        http://www.iss.net/security_center/static/10940.php
>
> Date Reported:      12/27/2002
> Brief Description:  PHP wordwrap() buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Any Web server Any version, PHP 4.2.3, PHP 4.2.2
> Vulnerability:      php-wordwrap-bo
> X-Force URL:        http://www.iss.net/security_center/static/10944.php
>
> Date Reported:      12/28/2002
> Brief Description:  Gallery Windows XP Publishing feature could be used
>                     to execute commands
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Linux Any version, Gallery 1.3.2
> Vulnerability:      gallery-winxppublishing-command-execution
> X-Force URL:        http://www.iss.net/security_center/static/10943.php
>
> Date Reported:      12/29/2002
> Brief Description:  web-cyradm IMAP daemon not running denial of
>                     service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, web-cyradm
>                     0.5.2 and earlier
> Vulnerability:      web-cyradm-imap-dos
> X-Force URL:        http://www.iss.net/security_center/static/10941.php
>
> Date Reported:      12/29/2002
> Brief Description:  Leafnode NNTP server denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, Leafnode
>                     1.9.20 to 1.9.29
> Vulnerability:      leafnode-nntp-dos
> X-Force URL:        http://www.iss.net/security_center/static/10942.php
>
>
> ______
>
> About Internet Security Systems (ISS)
> Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
> pioneer and world leader in software and services that protect critical
> online resources from an ever-changing spectrum of threats and misuse.
> Internet Security Systems is headquartered in Atlanta, GA, with
> additional operations throughout the Americas, Asia, Australia, Europe
> and the Middle East.
>
> Copyright (c) 2002 Internet Security Systems, Inc. All rights reserved
> worldwide.
>
> Permission is hereby granted for the electronic redistribution of this
> document. It is not to be edited or altered in any way without the
> express written consent of the Internet Security Systems X-Force. If you
> wish to reprint the whole or any part of this document in any other
> medium excluding electronic media, please email [EMAIL PROTECTED] for
> permission.
>
> Disclaimer: The information within this paper may change without notice.
Internet
> Security Systems provides this information on an AS IS basis with NO
warranties,
> implied or otherwise. Any use of this information is at the user's risk.
In no event
> shall Internet Security Systems be held liable for any damages whatsoever
arising
> out of or in connection with the use or dissemination of this information.
>
> X-Force PGP Key available on MIT's PGP key server and PGP.com's key
server,
> as well as at http://www.iss.net/security_center/sensitive.php
>
> Please send suggestions, updates, and comments to: X-Force
> [EMAIL PROTECTED] of Internet Security Systems, Inc.
>
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
>
> iQCVAwUBPhCNwzRfJiV99eG9AQG14AQApPDQCTna7noVvk7AkAc5ps1VD3bl7eD+
> au3bkwuCIt0b3WBDFZCJvE8aqH5LNy1lRwVDsNkeSkcOJhS3l69UibHLzPFdyOyL
> moX9WJrJ/stv99YD7Rcrvxj8walXsJmUSL+JStpuA+/MLR37+Npv2iFTqbwTv7lq
> CrLkyTgPVjk=
> =xrtF
> -----END PGP SIGNATURE-----
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
>

---
[This E-mail scanned for viruses by Declude Virus]

---------------------------------------------------------
Archived messages from this list can be found at:
http://www.mail-archive.com/[email protected]/
---------------------------------------------------------

Reply via email to