Weekly Vulnerabilities Reports > June 9 to 15, 2003

Overview

48 new vulnerabilities reported during this period, including 5 critical vulnerabilities and 21 high severity vulnerabilities. This weekly summary report vulnerabilities in 52 products from 32 vendors including Microsoft, Debian, Leszek Krupinski, Apple, and Redhat. Vulnerabilities are notably categorized as "Off-by-one Error", "Improper Restriction of Operations within the Bounds of a Memory Buffer", and "Classic Buffer Overflow".

  • 39 reported vulnerabilities are remotely exploitables.
  • 48 reported vulnerabilities are exploitable by an anonymous user.
  • Microsoft has the most reported vulnerabilities, with 8 reported vulnerabilities.
  • Microsoft has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

5 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2003-06-09 CVE-2003-0331 Ttcms SQL-Injection vulnerability in Ttcms Ttforum 4

SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.

10.0
2003-06-09 CVE-2003-0304 Oneorzero Remote Security vulnerability in Oneorzero Helpdesk 1.4Rc4

one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.

10.0
2003-06-09 CVE-2003-0240 Axis Authentication Bypass vulnerability in Axis Network Camera HTTP

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

10.0
2003-06-09 CVE-2003-0224 Microsoft Unspecified vulnerability in Microsoft Internet Information Services 5.0

Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."

10.0
2003-06-09 CVE-2003-0356 Ethereal Off-by-one Error vulnerability in Ethereal 0.8.13/0.9.11/0.9.3

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

9.8

21 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2003-06-09 CVE-2003-0332 Working Resources INC Security Bypass vulnerability in BadBlue

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.

7.6
2003-06-09 CVE-2003-0361 Debian Remote Security vulnerability in Linux

gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.

7.5
2003-06-09 CVE-2003-0360 Debian Denial-Of-Service vulnerability in Linux

Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

7.5
2003-06-09 CVE-2003-0328 Epic Unspecified vulnerability in Epic Epic4 Pre2.002/Pre2.003

EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.

7.5
2003-06-09 CVE-2003-0324 Epic Buffer Overflow vulnerability in Epic Epic4 1.0.1

Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.

7.5
2003-06-09 CVE-2003-0323 Michael Sandrof Unspecified vulnerability in Michael Sandrof Ircii 20020912

Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.

7.5
2003-06-09 CVE-2003-0321 Colten Edwards Remote Cluster() Heap Corruption vulnerability in BitchX

Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it.

7.5
2003-06-09 CVE-2003-0320 Andy Prevost Remote Security vulnerability in Ttcms

header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.

7.5
2003-06-09 CVE-2003-0319 Smartmax Software Remote Security vulnerability in MailMax

Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.

7.5
2003-06-09 CVE-2003-0309 Microsoft Unspecified vulnerability in Microsoft Internet Explorer 6.0.2800

Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."

7.5
2003-06-09 CVE-2003-0307 Poster Remote Security vulnerability in Poster Version.Two

Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.

7.5
2003-06-09 CVE-2003-0242 Apple Unspecified vulnerability in Apple mac OS X

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.

7.5
2003-06-09 CVE-2003-0241 Frontrange Unspecified vulnerability in Frontrange Goldmine 5.70/6.00

FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.

7.5
2003-06-09 CVE-2002-1463 Symantec Unspecified vulnerability in Symantec products

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

7.5
2003-06-09 CVE-2002-1461 Webscriptworld Remote Arbitrary Command Execution vulnerability in Webscriptworld web Shop Manager 1.1

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

7.5
2003-06-09 CVE-2002-1459 Leszek Krupinski Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

7.5
2003-06-09 CVE-2002-1458 Leszek Krupinski Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

7.5
2003-06-09 CVE-2002-1457 Leszek Krupinski SQL Injection vulnerability in Leszek Krupinski L-Forum 2.4.0

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

7.5
2003-06-09 CVE-2002-1456 Khaled Mardam BEY Buffer Overflow vulnerability in Khaled Mardam-Bey Mirc 6.0/6.0.1/6.0.2

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

7.5
2003-06-09 CVE-2003-0306 Microsoft Local Security vulnerability in Windows XP Gold

Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.

7.2
2003-06-09 CVE-2003-0188 LV
Redhat
lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.
7.2

22 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2003-06-09 CVE-2003-0223 Microsoft Unspecified vulnerability in Microsoft products

Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.

6.8
2003-06-09 CVE-2003-0362 Debian Denial-Of-Service vulnerability in Linux

Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.

5.0
2003-06-09 CVE-2003-0355 Apple
KDE
Remote Security vulnerability in Konqueror Embedded

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.

5.0
2003-06-09 CVE-2003-0322 Colten Edwards Denial-Of-Service vulnerability in Bitchx

Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).

5.0
2003-06-09 CVE-2003-0305 Cisco Denial-Of-Service vulnerability in IOS

The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.

5.0
2003-06-09 CVE-2003-0303 Oneorzero SQL Injection vulnerability in Oneorzero Helpdesk 1.4Rc4

SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.

5.0
2003-06-09 CVE-2003-0227 Microsoft Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Windows 2000 and Windows NT

The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.

5.0
2003-06-09 CVE-2003-0226 Microsoft Unspecified vulnerability in Microsoft Internet Information Services 5.0

Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.

5.0
2003-06-09 CVE-2003-0225 Microsoft Unspecified vulnerability in Microsoft products

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

5.0
2003-06-09 CVE-2002-1564 Microsoft Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0

Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability.

5.0
2003-06-09 CVE-2002-1462 Organicphp Authentication Bypassing vulnerability in OrganicPHP PHP-Affiliate Details.PHP Hidden Field

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

5.0
2003-06-09 CVE-2002-1460 Leszek Krupinski Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

5.0
2003-06-09 CVE-2002-1454 Mywebserver Unspecified vulnerability in Mywebserver 1.0.2

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

5.0
2003-06-13 CVE-2003-0420 Apple Unspecified vulnerability in Apple mac OS X Server 10.2.6

Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.

4.6
2003-06-09 CVE-2003-0358 Falconseye Project
Nethack
Debian
Classic Buffer Overflow vulnerability in multiple products

Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.

4.6
2003-06-09 CVE-2003-0330 Ambrosia Software Local Security vulnerability in Maelstrom

Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.

4.6
2003-06-09 CVE-2003-0329 Aclogic Local Security vulnerability in Aclogic Cesarftp 0.99G

CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.

4.6
2003-06-09 CVE-2003-0326 Slocate Heap Overflow vulnerability in SLocate Path Malloc Integer Signing

Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.

4.6
2003-06-09 CVE-2003-0325 Ambrosia Software Unspecified vulnerability in Ambrosia Software Maelstrom 3.0.6

Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.

4.6
2003-06-09 CVE-2003-0194 Redhat Unspecified vulnerability in Redhat Linux and Tcpdump

tcpdump does not properly drop privileges to the pcap user when starting up.

4.6
2003-06-09 CVE-2003-0318 Francisco Burzi Cross-Site Scripting vulnerability in PHP-Nuke

Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.

4.3
2003-06-09 CVE-2002-1455 Omnicron Cross-Site Scripting vulnerability in OmniHTTPD

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

4.3

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS