SecuriTeam.comBeyond Security will help you expose your security holes and will show you what the bad guys already know about your hosts and network. Use our Automated Scanning service to perform a full security audit of your site, and find the latest security news and tools on Beyond Security's SecuriTeam web site.TorrentTrader Multiple SQL Injection Vulnerabilities- June 24, 2008 "TorrentTrader is a feature packed and highly customisable PHPMySQL Based BitTorrent tracker. Featuring intergrated forums, and plenty of administration options." Secunia Research has discovered some vulnerabilities in TorrentTrader, which can be exploited by malicious people and malicious users to conduct SQL injection attacks.http://www.securiteam.com/securitynews/5XP0P15OKO.html Cisco Intrusion Prevention System Jumbo Frame Denial of Service- June 24, 2008 Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable.http://www.securiteam.com/securitynews/5WP0O15OKY.html XnView, NConvert, and GFL SDK Sun TAAC Buffer Overflow- June 24, 2008 XnView is "A software to view and convert graphic files, really simple to use!". NConvert is "a batch utility to convert graphic files!". GFL SDK is "a free library (used by XnView) for developers who would like to support graphics image formats easily." Secunia Research has discovered a vulnerability in XnView, NConvert, and GFL SDK, which can be exploited by malicious people to compromise a user's system.http://www.securiteam.com/securitynews/5VP0N15OKO.html Diigo Toolbar Global XSS and Information Leakage in SSL URLs- June 24, 2008 Diigo is "a social bookmarking and sharing application which allows users to see other users comments and notes for every website. For this feature users should use Diigolet bookmarklet or Diigo Toolbar. These are almost mandatory to use Diigo and almost all Diigo members have them installed". Two security vulnerabilities have been discovered in Diigo Toolbar, one of these vulnerabilities allows a remote attackers to insert arbitrary Javascript into the context of the Diigo Toolbar, which will..http://www.securiteam.com/windowsntfocus/5UP0M15OKE.html World in Conflict NULL Pointer- June 24, 2008 World in Conflict is "a RTS game developed by Massive Entertainment and released in the 2007". The WIC server can be easily crashed through an access violation caused by a NULL pointer resulted by the receiving of a data block of zero bytes to the main TCP game port (default 48000).http://www.securiteam.com/windowsntfocus/5TP0L15OKU.html Alt-N SecurityGateway Username Buffer Overflow (Exploit)- June 17, 2008 A vulnerability in Alt-N SecurityGateway allows remote attackers to overflow a buffer found inside the SecurityGateway.dll which would allow a remote attacker to cause the program to execute arbitrary code.http://www.securiteam.com/exploits/5GP0C20OKI.html Multiple Vendor X Server Vulnerabilities (SHM, RSE, REG, AllocateGlyph)- June 17, 2008 The X Window System is "a graphical windowing system based on a clientserver model". Multiple vulnerabilities have been discovered in the X server product, allowing local attackers to cause the product to disclose data, corrupt memory and possibly execute arbitrary code.http://www.securiteam.com/unixfocus/5FP0B20OKG.html SNMP Version 3 Authentication Vulnerabilities- June 15, 2008 Multiple Cisco products contain either of two authentication vulnerabilities in the Simple Network Management Protocol version 3 (SNMPv3) feature. These vulnerabilities can be exploited when processing a malformed SNMPv3 message. These vulnerabilities could allow the disclosure of network information or may enable an attacker to perform configuration changes to vulnerable devices. The SNMP server is an optional service that is disabled by default in Cisco products. Only SNMPv3 is impacted by...http://www.securiteam.com/securitynews/5HP0I1FOKK.html CitectSCADA ODBC Service Vulnerability- June 15, 2008 Citect is a supplier of industrial automation software with headquarters in Australia and over 20 offices in Oceania, South East Asia, China, Japan, the Americas, Europe, Africa and the Middle East. Citect's products are distributed in over 80 countries through a network of more than 500 partners. According to Citect's website 1 the company, a fully owned subsidiary of Schneider Electric, has more than 150,000 licenses of its software sold to date. Citect's products are used by organizations...http://www.securiteam.com/windowsntfocus/5GP0H1FOKS.html |