Weekly Vulnerabilities Reports > January 24 to 30, 2005

Overview

53 new vulnerabilities reported during this period, including 9 critical vulnerabilities and 16 high severity vulnerabilities. This weekly summary report vulnerabilities in 78 products from 53 vendors including Suse, Gentoo, Apple, Redhat, and Easy Software Products. Vulnerabilities are notably categorized as "Resource Management Errors", "Integer Overflow or Wraparound", and "Code Injection".

  • 41 reported vulnerabilities are remotely exploitables.
  • 53 reported vulnerabilities are exploitable by an anonymous user.
  • Suse has the most reported vulnerabilities, with 12 reported vulnerabilities.
  • Redhat has the most reported critical vulnerabilities, with 5 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

9 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-01-27 CVE-2004-0929 Libtiff
Suse
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
10.0
2005-01-27 CVE-2004-0926 Easy Software Products
Apple
Multiple Security vulnerability in Apple Mac OS X

Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.

10.0
2005-01-27 CVE-2004-0903 Mozilla
Conectiva
Redhat
Suse
Remote Buffer Overflow vulnerability in Mozilla Browser Vcard Handling

Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.

10.0
2005-01-27 CVE-2004-0902 Mozilla
Conectiva
Redhat
Suse
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
10.0
2005-01-27 CVE-2004-0891 ROB Flynn
Gentoo
Slackware
Ubuntu
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
10.0
2005-01-27 CVE-2004-0889 Easy Software Products
Gnome
KDE
Pdftohtml
Tetex
Xpdf
Debian
Gentoo
Redhat
Suse
Ubuntu
Integer Overflow vulnerability in Xpdf PDFTOPS

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

10.0
2005-01-27 CVE-2004-0888 Easy Software Products
Gnome
KDE
Pdftohtml
Tetex
Xpdf
Debian
Gentoo
Redhat
Suse
Ubuntu
Integer Overflow vulnerability in Xpdf PDFTOPS

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.

10.0
2005-01-27 CVE-2004-0882 Samba
Conectiva
Redhat
Ubuntu
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
10.0
2005-01-24 CVE-2005-0102 Gnome
Debian
Integer Overflow or Wraparound vulnerability in multiple products

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

9.8

16 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-01-28 CVE-2005-0316 Webwasher Unspecified vulnerability in Webwasher Classic 2.2.1/3.3

WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.

7.5
2005-01-27 CVE-2005-0313 Amax Information Technologies Multiple vulnerability in Amax Information Technologies Magic Winmail Server 4.0

Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

7.5
2005-01-27 CVE-2004-0936 Archive ZIP
Broadcom
CA
Eset Software
Kaspersky LAB
Mcafee
RAV Antivirus
Sophos
Gentoo
Mandrakesoft
Suse
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
2005-01-27 CVE-2004-0935 Archive ZIP
Broadcom
CA
Eset Software
Kaspersky LAB
Mcafee
RAV Antivirus
Sophos
Gentoo
Mandrakesoft
Suse
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
2005-01-27 CVE-2004-0934 Archive ZIP
Broadcom
CA
Eset Software
Kaspersky LAB
Mcafee
RAV Antivirus
Sophos
Gentoo
Mandrakesoft
Suse
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
2005-01-27 CVE-2004-0933 Archive ZIP
Broadcom
CA
Eset Software
Kaspersky LAB
Mcafee
RAV Antivirus
Sophos
Gentoo
Mandrakesoft
Suse
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
2005-01-27 CVE-2004-0932 Archive ZIP
Broadcom
CA
Eset Software
Kaspersky LAB
Mcafee
RAV Antivirus
Sophos
Gentoo
Mandrakesoft
Suse
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
2005-01-27 CVE-2004-0921 Apple Multiple Security vulnerability in Apple Mac OS X

AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.

7.5
2005-01-27 CVE-2004-0892 Microsoft Unspecified vulnerability in Microsoft ISA Server, Proxy Server and Windows 2003 Server

Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.

7.5
2005-01-24 CVE-2005-0308 Ursoftware Buffer Overflow vulnerability in Ursoftware W32Dasm 8.94

Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.

7.5
2005-01-24 CVE-2005-0115 Datarescue Remote Buffer Overflow vulnerability in Datarescue IDA 4.7

Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.

7.5
2005-01-24 CVE-2005-0103 Squirrelmail Code Injection vulnerability in Squirrelmail

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

7.5
2005-01-27 CVE-2004-0887 Linux
Suse
Local Privilege Escalation vulnerability in Linux IBM S/390 Kernel SACF Instruction

SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.

7.2
2005-01-27 CVE-2004-0884 Cyrus
Conectiva
Remote And Local vulnerability in Cyrus SASL

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

7.2
2005-01-26 CVE-2005-0162 Openswan
Xelerance
Remote Buffer Overflow vulnerability in Xelerance Corporation Openswan XAUTH/PAM

Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.

7.2
2005-01-26 CVE-2003-1021 SCO Local Command Line Buffer Overflow vulnerability in SCO scosession

The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.

7.2

20 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-01-29 CVE-2005-0075 Squirrelmail Unspecified vulnerability in Squirrelmail

prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.

5.0
2005-01-28 CVE-2005-0320 Icewarp Remote vulnerability in Icewarp web Mail 5.3

Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.

5.0
2005-01-27 CVE-2004-0930 Samba
SGI
Conectiva
Gentoo
Redhat
Remote Wild Card Denial Of Service vulnerability in Samba

The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.

5.0
2005-01-27 CVE-2004-0927 Easy Software Products
Apple
Multiple Security vulnerability in Apple Mac OS X

ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

5.0
2005-01-27 CVE-2004-0925 Apple Unspecified vulnerability in Apple mac OS X and mac OS X Server

Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.

5.0
2005-01-27 CVE-2004-0924 Easy Software Products
Apple
Multiple Security vulnerability in Apple Mac OS X

NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.

5.0
2005-01-27 CVE-2004-0922 Apple Multiple Security vulnerability in Apple Mac OS X

AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.

5.0
2005-01-27 CVE-2004-0918 Openpkg
Squid
Gentoo
Redhat
Trustix
Ubuntu
Resource Management Errors vulnerability in multiple products

The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.

5.0
2005-01-27 CVE-2004-0917 Vignette Remote Information Disclosure vulnerability in Vignette Application Portal

The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.

5.0
2005-01-27 CVE-2004-0916 Cabextract Project Unspecified vulnerability in Cabextract Project Cabextract 0.2/0.6/1.0

Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing ..

5.0
2005-01-27 CVE-2004-0886 Libtiff
Pdflib
Wxgtk2
Apple
KDE
Mandrakesoft
Redhat
Suse
Trustix
Buffer Overflow vulnerability in LibTIFF

Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.

5.0
2005-01-25 CVE-2005-0306 Mercuryboard Input Validation vulnerability in Mercuryboard 1.1/1.1.1

MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.

5.0
2005-01-25 CVE-2005-0096 Squid Remote Denial Of Service vulnerability in Squid Proxy NTLM Fakeauth_Auth Memory Leak

Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).

5.0
2005-01-27 CVE-2005-0315 Amax Information Technologies Multiple vulnerability in Amax Information Technologies Magic Winmail Server 4.0

The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.

4.6
2005-01-29 CVE-2005-0104 Squirrelmail Unspecified vulnerability in Squirrelmail

Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.

4.3
2005-01-28 CVE-2005-0319 ALT N Remote vulnerability in Alt-N Webadmin 3.0.3

Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.

4.3
2005-01-28 CVE-2005-0317 ALT N Remote vulnerability in Alt-N Webadmin 3.0.2

Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

4.3
2005-01-27 CVE-2005-0314 Amax Information Technologies Multiple vulnerability in Magic Winmail Server

Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.

4.3
2005-01-25 CVE-2005-0309 Exponent Cross-Site Scripting vulnerability in Exponent 0.95

Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.

4.3
2005-01-25 CVE-2005-0307 Mercuryboard Input Validation vulnerability in Mercuryboard 1.1/1.1.1

Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.

4.3

8 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-01-24 CVE-2005-0145 Mozilla Unspecified vulnerability in Mozilla Firefox

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

2.6
2005-01-28 CVE-2005-0318 ALT N Remote vulnerability in Alt-N Webadmin 3.0.2

useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.

2.1
2005-01-27 CVE-2005-0312 WAR FTP Daemon Remote Denial Of Service vulnerability in WAR FTP Daemon WAR FTP Daemon 1.8/1.82Rc9

WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.

2.1
2005-01-27 CVE-2004-0923 Easy Software Products
Apple
Local Password Disclosure vulnerability in CUPS Error_Log

CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.

2.1
2005-01-27 CVE-2004-0881 Getmail
Gentoo
Slackware
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
2.1
2005-01-26 CVE-2004-1340 Debian Unspecified vulnerability in Debian Linux 3.0

Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.

2.1
2005-01-24 CVE-2005-0072 Ejoy AND HU Yong Unspecified vulnerability in Ejoy and HU Yong Zhcon 0.2

zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

2.1
2005-01-27 CVE-2004-0880 Getmail
Gentoo
Slackware
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
1.2