Tuesday, December 4, 2007

SonicWALL Global VPN Client Format String

==============================
=======================================================
title: SonicWALL Global VPN Client Format String
Vulnerability
program: SonicWALL Global VPN Client
vulnerable version: < 4.0.0.830
homepage: www.sonicwall.com
found: 06-12-2007
by: lofi42*
perm. link: http://www.sec-consult.com/305.html
=====================================================================================

Vendor description:
---------------

The SonicWALL Global VPN Client provides mobile users with access to
mission-critical network resources by establishing secure connections to
their office network's IPSec-compliant SonicWALL VPN gateway.


Vulnerabilty overview:
---------------

SonicWALL Global VPN Client suffers from a format string vulnerability
that can be triggered by supplying a specially crafted configuration
file. This vulnerability allows an attacker to execute arbitrary code in
the context of the vulnerable client. For a successful attack, the
attacker would have to entice his victim into importing the special
configuration file.


Vulnerability details:
---------------

Format string errors occur when the client parses the "name" attribute
of the "Connection" tag and the content of the "Hostname" Tags in the
configuration file.

Examples:


%s%s%s%s

The bugs has been verified in version 3.1.556 and beta 4.0.0.810. With
version 3.1.556 the client has to initiate a connection to trigger the
vulnerability, whereas with version 4.0.0.810, the bug can be exploited
by simply double-clicking the configuration file. This can be attributed
to the 4.0 version trying to write the imported configuration to an
extra debug log.


Proof-of-concept:
---------------

In 4.0.0.810, the bug can be beautifully demonstrated by supplying a
crafted config file and then viewing the debug logfile. A configuration
like this...

AAAAAAAAAA%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x
BBBBBBBBBB%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x.%x.%x.%x.%x.%x

...yields the following logfile:

----------------------< Connection name
>-----------------------------------
OnLogMessage(): 'The connection "AAAAAAAAAAe64d20.37327830.46413139.
203a3833.782b8d00.6f4c6e4f.73654d67.65676173.203a2928.65685427.
6e6f6320.7463656e.206e6f69.41414122.41414141.25414141" has been
enabled.' ''
----------------------</Connection name
>-----------------------------------
----------------------e>--------------------------------------------
BBBBBBBBBB656d616e.41414120.41414141.25414141.78252e78.2e78252e.252e7825.
78252e78.2e78252e.252e7825.78252e78.2e78252e.252e7825.78252e78.2e78252e.
74207825.6e61206f.20504920.72646461.2e737365.42272027.42424242.42424242'
----------------------</HostName>---------------------------------------


This vulnerability allows reading / writing to arbitrary memory
addresses within the process memory space. Exploitation is trivial under
these circumstances.


vendor status:
---------------
vendor notified: 2007-08-16
vendor response: 2007-08-29
patch available: 2007-11-26

The issue has been fixed in SonicWall VPN client 4.0.0.830.

Ubuntu Security Notice USN-551-1 December 04, 2007

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

==============================

=============================
Ubuntu Security Notice USN-551-1 December 04, 2007
openldap vulnerabilities
CVE-2007-5707, CVE-2007-5708
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
slapd 2.2.26-5ubuntu2.4

Ubuntu 6.10:
slapd 2.2.26-5ubuntu3.2

Ubuntu 7.04:
slapd 2.3.30-2ubuntu0.1

Ubuntu 7.10:
slapd 2.3.35-1ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Thomas Sesselmann discovered that the OpenLDAP slapd server
did not properly handle certain modify requests. A remote
attacker could send malicious modify requests to the server
and cause a denial of service. (CVE-2007-5707)

Toby Blake discovered that slapd did not properly terminate
an array while running as a proxy-caching server. A remote
attacker may be able to send crafted search requests to the
server and cause a denial of service. This issue only affects
Ubuntu 7.04 and 7.10. (CVE-2007-5708)


Updated packages for Ubuntu 6.06 LTS:

Source archives:


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26-5ubuntu2.4.diff.gz
Size/MD5: 511262 b54753c0e681803599125b18bef714ff

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26-5ubuntu2.4.dsc
Size/MD5: 1020 519f96ba1375478163e3c40e881ae2d7

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26.orig.tar.gz
Size/MD5: 2626629 afc8700b5738da863b30208e1d3e9de8

amd64 architecture (Athlon64, Opteron, EM64T Xeon):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu2.4_amd64.deb
Size/MD5: 130406 8d3bf04e5529528c0ac26530b2070f78

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu2.4_amd64.deb
Size/MD5: 165830 e66f9e954c0ea05b4e2611ccd9fbcce6

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu2.4_amd64.deb
Size/MD5: 961236 e5a89ad1cf97801efd27c52191703752

i386 architecture (x86 compatible Intel/AMD):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu2.4_i386.deb
Size/MD5: 118302 c57c5729bc9cf5ada18ebc3bef77d8da

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu2.4_i386.deb
Size/MD5: 145954 caf31365b85db0e03a5f9884dda48fc7

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu2.4_i386.deb
Size/MD5: 872794 8e5380a50fef5a25ac83c309f9a09a7d

powerpc architecture (Apple Macintosh G3/G4/G5):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu2.4_powerpc.deb
Size/MD5: 132560 bcef53015f0225ad7e216d94f23d1190

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu2.4_powerpc.deb
Size/MD5: 157010 2132bdab3beff83ae731103602cdc38d

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu2.4_powerpc.deb
Size/MD5: 959310 629b33d57e8087fbb8f5be51203f6dee

sparc architecture (Sun SPARC/UltraSPARC):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu2.4_sparc.deb
Size/MD5: 120616 13c31cc42532a60ceb499fc044356dc8

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu2.4_sparc.deb
Size/MD5: 148044 3bf8d5ec833a67b9660bb7a448ae0c89

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu2.4_sparc.deb
Size/MD5: 903250 43b642eccf4fdb4b2ae81d9f4e65236d

Updated packages for Ubuntu 6.10:

Source archives:


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26-5ubuntu3.2.diff.gz
Size/MD5: 512406 0a7387e1542e833d4fcf3dd458571805

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26-5ubuntu3.2.dsc
Size/MD5: 1020 2926a0c36b89ebb9dc498005f4a8c93a

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/openldap2.2_2.2.26.orig.tar.gz
Size/MD5: 2626629 afc8700b5738da863b30208e1d3e9de8

amd64 architecture (Athlon64, Opteron, EM64T Xeon):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu3.2_amd64.deb
Size/MD5: 130568 2c0d6fd715c4049d464acc6da91db771

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu3.2_amd64.deb
Size/MD5: 166602 43b9daf9f2938ee91818e08ef88e3897

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu3.2_amd64.deb
Size/MD5: 958238 76f32588bf19a293993f59281a1b19db

i386 architecture (x86 compatible Intel/AMD):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu3.2_i386.deb
Size/MD5: 121234 8ef74f1ac973fd76c383c82d5ed1fcc8

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu3.2_i386.deb
Size/MD5: 152394 20c8c28e5c8f62db165592a847728600

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu3.2_i386.deb
Size/MD5: 900626 2fd37c48cbee64886b75665f3c4b22b7

powerpc architecture (Apple Macintosh G3/G4/G5):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu3.2_powerpc.deb
Size/MD5: 133566 9f8ff85e0bcc546a35174d5f8e4c32d4

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu3.2_powerpc.deb
Size/MD5: 158770 7051d8aa41997d86ad9bdd1f0cbd09fd

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu3.2_powerpc.deb
Size/MD5: 966444 a0a61d9af0fd64251f75cf6062e85834

sparc architecture (Sun SPARC/UltraSPARC):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2.2.26-5ubuntu3.2_sparc.deb
Size/MD5: 121492 9e05e58bb98a5ddd53656fd82a23d45b

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2-7_2.2.26-5ubuntu3.2_sparc.deb
Size/MD5: 149232 8f73c53ad74062f446aac3c31ef953ff

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26-5ubuntu3.2_sparc.deb
Size/MD5: 909242 2a9d3a22330886f4bf727ea1d19187e0

Updated packages for Ubuntu 7.04:

Source archives:


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.30-2ubuntu0.1.diff.gz
Size/MD5: 139726 79fb0171f368ca4312d48d4c695edb53

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.30-2ubuntu0.1.dsc
Size/MD5: 1295 fc1bc630868634c3937dea90fe7f9c4e

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.30.orig.tar.gz
Size/MD5: 2971126 c40bcc23fa65908b8d7a86a4a6061251

amd64 architecture (Athlon64, Opteron, EM64T Xeon):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.30-2ubuntu0.1_amd64.deb
Size/MD5: 187572 cb6072c694a417d01d3da06c94977a4e

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.30-2ubuntu0.1_amd64.deb
Size/MD5: 292212 5afbe83546e56db28b59906d7820d92d

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.30-2ubuntu0.1_amd64.deb
Size/MD5: 1227928 e2e2e821b94b2940bd599ad513922d7f

i386 architecture (x86 compatible Intel/AMD):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.30-2ubuntu0.1_i386.deb
Size/MD5: 155982 05d6d346c35f7e6f3e3b3f13916cc7cb

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.30-2ubuntu0.1_i386.deb
Size/MD5: 267352 c0309cfc9c84f183df478d51c040400b

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.30-2ubuntu0.1_i386.deb
Size/MD5: 1154660 fa9fd13816f4181219749a39ec891413

powerpc architecture (Apple Macintosh G3/G4/G5):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.30-2ubuntu0.1_powerpc.deb
Size/MD5: 203570 ee80e1eeb0e3affccecc9974bbc3e91d

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.30-2ubuntu0.1_powerpc.deb
Size/MD5: 294320 67698b61c8e2aa0b914b02483449813c

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.30-2ubuntu0.1_powerpc.deb
Size/MD5: 1280328 a559f7311835769efd965854e324036e

sparc architecture (Sun SPARC/UltraSPARC):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.30-2ubuntu0.1_sparc.deb
Size/MD5: 164312 51a13892bf9013a12b2f356282281421

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.30-2ubuntu0.1_sparc.deb
Size/MD5: 264178 6fccf9f07791c6cf5ed41c52cdaac2cb

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.30-2ubuntu0.1_sparc.deb
Size/MD5: 1169780 f5d2064a6f5a560151865d87d963e3db

Updated packages for Ubuntu 7.10:

Source archives:


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.35-1ubuntu0.1.diff.gz
Size/MD5: 153304 035a13818eebaca172ef7fb2e1b73f83

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.35-1ubuntu0.1.dsc
Size/MD5: 1305 89bc62db8536ab8292fc3afabbce98b5

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/openldap2.3_2.3.35.orig.tar.gz
Size/MD5: 2947629 5096146b7a7eb6ce3b0a97549347b5be

amd64 architecture (Athlon64, Opteron, EM64T Xeon):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.35-1ubuntu0.1_amd64.deb
Size/MD5: 189744 dce285ce9164fe57f56d99a53935205a

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.35-1ubuntu0.1_amd64.deb
Size/MD5: 346882 1e33bf330b7551e2035ba32f576ed8c7

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.35-1ubuntu0.1_amd64.deb
Size/MD5: 1295526 f16e6d501bb115b4c5b24ac7af676043

i386 architecture (x86 compatible Intel/AMD):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.35-1ubuntu0.1_i386.deb
Size/MD5: 155172 b1229c692b2b0e90842f2a3963710d44

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.35-1ubuntu0.1_i386.deb
Size/MD5: 314500 ea70a6f6d29f2458401cd0de1a99772f

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.35-1ubuntu0.1_i386.deb
Size/MD5: 1215670 083901dcaadcb356d8d743facbe76410

powerpc architecture (Apple Macintosh G3/G4/G5):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.35-1ubuntu0.1_powerpc.deb
Size/MD5: 204936 8144ae85dd773e4126bfb13dda6f383f

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.35-1ubuntu0.1_powerpc.deb
Size/MD5: 345608 449f262dee94fc35f907e3da735b2ff0

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.35-1ubuntu0.1_powerpc.deb
Size/MD5: 1344728 bec28b0dfb90095961a484ec2f3cc96e

sparc architecture (Sun SPARC/UltraSPARC):


http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/ldap-utils_2.3.35-1ubuntu0.1_sparc.deb
Size/MD5: 166128 e14bbb2254d7a577b3f04453b8743ac5

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/libldap-2.3-0_2.3.35-1ubuntu0.1_sparc.deb
Size/MD5: 306682 95a1008f5696a6d9cb6f9e7e521c7ab8

http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.3/slapd_2.3.35-1ubuntu0.1_sparc.deb
Size/MD5: 1228072 8ffd29411e996e6a5853f29621d092d3


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHVMZ2W0JvuRdL8BoRAo44AJ4lKdQaZEkOT/rJCCH87ZHB/sPK9ACghXsW
uzbIzU1FCeG9gaq4dD0g+kQ=
=QjYS
-----END PGP SIGNATURE-----

A user can gain admin level in snitz 2000 by SQL Injection

########################## WwW.BugReport.ir #########################

#

# AmnPardaz Security Research & Penetration Testing Group

#

# Title: A user can gain admin level in snitz 2000 by SQL Injection

# vendor: http://forum.snitz.com/

# Googling: "Powered by Snitz" > 2,440,000 victims

# Last bug report in 2007-02-16 with 4692 visitors

# Exploit: Available

# Fix Available: Update to last version.

######################## Bug Description ###########################

A user can gain admin level in the forum and can access to the forum.

It is because of a SQL Injection in "Active.asp"


After login to your VICTIM forum, execute below script

~~~~~~~~~~~~Start HTML Exploit~~~~~~~~~



Query:


DefaultValues:


Submit:




~~~~~~~~~~~~End HTML Exploit~~~~~~~~~


##############################
#######################################

# Security Site: WwW.BugReport.ir - WwW.AmnPardaz.Com

# Country: Iran

# Contact: admin@bugreport.ir

# Credit: Soroush Dalili found this bug.

#####################################################################

Monday, December 3, 2007

SQL Injection Vulnerability in Beehive Forum

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1





Symantec Vulnerability Research

http://www.symantec.com/research

Security Advisory


Advisory ID: SYMSA-2007-014

Advisory Title: SQL Injection Vulnerability in Beehive Forum

Software

Author: Nick Bennett

Robert Brown / robert_brown@symantec.com

Release Date: 28-11-2007

Application: Beehive Forum 0.7.1 (earlier versions also

vulnerable)

Platform: All supported

Severity: Remotely exploitable / Information Disclosure

Vendor status: Updated Application Versions Available

CVE Number: CVE-2007-6014

Reference: http://www.securityfocus.com/bid/26492



Overview:


Beehive Forum is an open source web based forum application

written in PHP. A vulnerability exists in the Beehive Forum

software that could allow a remote user to execute SQL injection

attacks. These attacks could compromise sensitive data including

usernames and passwords for the Beehive application. Arbitrary

data from other applications hosted on the same server could also

be compromised, depending on the configuration of MySQL.



Details:


This vulnerability exists because of a failure in the application

to properly sanitize user input for the variable "t_dedupe". This

variable is accepted as input in the page "post.php". The value of

this variable is then included in an SQL statement which is

executed with the PHP function "@mysql_query". This function is

specifically designed to mitigate the effects of an SQL injection

attack by not allowing multiple SQL statements in one call.

However, it is still possible to manipluate the SQL statement

through the "t_dedupe" variable to obtain arbitrary data from

the database.



Vendor Response:


There is a security vulnerability in Beehive Forum that could

allow for user logon and password MD5 hash disclosure.


This vulnerability has been fixed in the latest release of the

product, Beehive Forum 0.8. It is recommend all users immediately

obtain the newest version of Beehive Forum to protect against

this threat.


Project Beehive Forum is available for download from the project

website at http://www.beehiveforum.net/


If there are any further questions about this statement, please

contact a member of the development team.



Recommendation:


It is recommend all users immediately obtain the newest version of

Beehive Forum to protect against this threat. Project Beehive

Forum is available for download from the project website at

http://www.beehiveforum.net/.


Common Vulnerabilities and Exposures (CVE) Information:


The Common Vulnerabilities and Exposures (CVE) project has assigned

the following names to these issues. These are candidates for

inclusion in the CVE list (http://cve.mitre.org), which standardizes

names for security problems.



CVE-2007-6014


- ----------Symantec Vulnerability Research Advisory Information-------


For questions about this advisory, or to report an error:

research@symantec.com


For details on Symantec's Vulnerability Reporting Policy:

http://www.symantec.com/research/Symantec-Responsible-Disclosure.pdf


Symantec Vulnerability Research Advisory Archive:

http://www.symantec.com/research/


Symantec Vulnerability Research GPG Key:

http://www.symantec.com/research/Symantec_Vulnerability_Research_GPG.asc


- ----------------Symantec Product Advisory Information-------------


To Report a Security Vulnerability in a Symantec Product:

secure@symantec.com


For general information on Symantec's Product Vulnerability

reporting and response:

http://www.symantec.com/security/


Symantec Product Advisory Archive:

http://www.symantec.com/avcenter/security/SymantecAdvisories.html


Symantec Product Advisory PGP Key:

http://www.symantec.com/security/Symantec-Vulnerability-Management-Key.asc


- ------------------------------

------------------------------------


Copyright (c) 2007 by Symantec Corp.

Permission to redistribute this alert electronically is granted

as long as it is not edited in any way unless authorized by

Symantec Consulting Services. Reprinting the whole or part of

this alert in any medium other than electronically requires

permission from research@symantec.com.


Disclaimer

The information in the advisory is believed to be accurate at the

time of publishing based on currently available information. Use

of the information constitutes acceptance for use in an AS IS

condition. There are no warranties with regard to this information.

Neither the author nor the publisher accepts any liability for any

direct, indirect, or consequential loss or damage arising from use

of, or reliance on, this information.


Symantec, Symantec products, and Symantec Consulting Services are

registered trademarks of Symantec Corp. and/or affiliated companies

in the United States and other countries. All other registered and

unregistered trademarks represented in this document are the sole

property of their respective companies/owners.

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.7 (MingW32)


iD8DBQFHVFXyuk7IIFI45IARAhJqAKCGc/4L5tb0bq1s1jrp6mwEFJBBRgCcDA+F

V7igvapHPpck2rZdZRlgB0Q=

=JzzL

-----END PGP SIGNATURE-----

McAfee SecurityCenter Privacy Service HTML Execution Vulnerability

[HSC] McAfee SecurityCenter Privacy Service HTML Execution Vulnerability



McAfee provides a proactive PC and Internet security service that helps you avoid

online attacks and protects what you value from hackers, identity thieves and other

online criminals.


A HTML execution vulnerability may allow an attacker to execute HTML scripts on

the system under the context of the user. These scripts can perform any action that the

user would. The flaw lies in the processing of filtering that is saved after exiting.




Hackers Center Security Group (http://www.hackerscenter.com)

Credit: DoZ



Risk: Medium

Class: Input Validation Error

Local: Yes


Vendor: http://us.mcafee.com/

Product: McAfee SecurityCenter

Version: McAfee Privacy Service 8.1.0.136


Exploit: An exploit is not required.


An attacker may attack this issue to execute code in the context of the affected software, and distribute this code across Privacy Service infrastructure. Also making a patch that works

with this hole will allow attackers to use this hole as platform for other attacks.




Examples:


1.

After turning your software into a web browser, you can inject

this website http://www.crashie.com/ and it will crash McAfee Privacy Service.

One can also use an Internet Explorer exploit to crash the McAfee Application.





2.

Paste your slogan to see if software is vul to this attack.


Hello!






Proof of Concept:


http://www.hackerscenter.com/public/images/1.jpg

http://www.hackerscenter.com/public/images/2.jpg

http://www.hackerscenter.com/public/images/3.jpg




Only becoming a Ethical Hacker, you can stop Black Hat Hackers. Learn with out

having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive

security pack you will ever find on the net!

Ubuntu Security Notice USN-550-1

===========================================================

Ubuntu Security Notice USN-550-1 December 03, 2007
libcairo vulnerability
CVE-2007-5503
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libcairo2 1.0.4-0ubuntu1.1

Ubuntu 6.10:
libcairo2 1.2.4-1ubuntu2.1

Ubuntu 7.04:
libcairo2 1.4.2-0ubuntu1.1

Ubuntu 7.10:
libcairo2 1.4.10-1ubuntu4.1

After a standard system upgrade you need to restart your session to effect
the necessary changes.

Details follow:

Peter Valchev discovered that Cairo did not correctly decode PNG image data.
By tricking a user or automated system into processing a specially crafted
PNG with Cairo, a remote attacker could execute arbitrary code with user
privileges.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.0.4-0ubuntu1.1.diff.gz
Size/MD5: 21363 923fce5eeadd28210253d4abee94c021
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.0.4-0ubuntu1.1.dsc
Size/MD5: 758 1a9841f672270e575c0b969ac43770e6
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.0.4.orig.tar.gz
Size/MD5: 1475777 9002b0e69b3f94831a22d3f2a7735ce2

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-doc_1.0.4-0ubuntu1.1_all.deb
Size/MD5: 248806 d07f34dfefa986bce48832d8045b7a91

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.0.4-0ubuntu1.1_amd64.deb
Size/MD5: 379060 76ded810d17804925ad12bae5e3d245f
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.0.4-0ubuntu1.1_amd64.deb
Size/MD5: 325530 9a516ba06e5b5a27e21b66bb4347078c

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.0.4-0ubuntu1.1_i386.deb
Size/MD5: 349700 ee50215cd08bf62e31cda8f17c5799f4
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.0.4-0ubuntu1.1_i386.deb
Size/MD5: 305972 55d2c047477e179c5ac7dc67ab376aa4

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.0.4-0ubuntu1.1_powerpc.deb
Size/MD5: 358682 fdf4b2bad4b64ab465869bced8865ba0
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.0.4-0ubuntu1.1_powerpc.deb
Size/MD5: 310390 cdfd66c03c826f73090c230afb4fe9ec

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.0.4-0ubuntu1.1_sparc.deb
Size/MD5: 344788 ff7a4c0a0c9d7a357412156dc9871577
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.0.4-0ubuntu1.1_sparc.deb
Size/MD5: 299764 daf1419acbbf7dc92d395ffbe00fa65c

Updated packages for Ubuntu 6.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.2.4-1ubuntu2.1.diff.gz
Size/MD5: 24719 bcd1d3e83c5582aa19ebca95a24127a3
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.2.4-1ubuntu2.1.dsc
Size/MD5: 896 932452487483a9eb21ebef4a44f2fc82
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.2.4.orig.tar.gz
Size/MD5: 2882781 1222b2bfdf113e2c92f66b3389659f2d

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-doc_1.2.4-1ubuntu2.1_all.deb
Size/MD5: 299204 8d7d5a9983fb53561516082dcbd08bd6

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.2.4-1ubuntu2.1_amd64.deb
Size/MD5: 416736 a5c36bbdb028235421ef125a6402487e
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.2.4-1ubuntu2.1_amd64.deb
Size/MD5: 356570 092a386f6376547f3bb8ce7ce32b485b
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.2.4-1ubuntu2.1_amd64.deb
Size/MD5: 471368 3b8d4bfd594bc70b95cc41db13602af3
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.2.4-1ubuntu2.1_amd64.deb
Size/MD5: 395646 b0c1fef7e375e2d6daf5e30755e084ee
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.2.4-1ubuntu2.1_amd64.udeb
Size/MD5: 158518 26c98933ee1b5454910a0eb817bf8954

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.2.4-1ubuntu2.1_i386.deb
Size/MD5: 399522 766ec4b85a287ff9aa4e166ba18b40a1
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.2.4-1ubuntu2.1_i386.deb
Size/MD5: 348112 ce9ca18e10e1aece9aa5c2ae328e803b
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.2.4-1ubuntu2.1_i386.deb
Size/MD5: 446278 200d50c73cc849e061ed94c4bbd10895
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.2.4-1ubuntu2.1_i386.deb
Size/MD5: 385436 668a20054d0c1a507ebcfc3010432639
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.2.4-1ubuntu2.1_i386.udeb
Size/MD5: 150094 8a06ce6c6b8869b141c45d8507e3d376

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.2.4-1ubuntu2.1_powerpc.deb
Size/MD5: 400866 7342cc89dd8937eaee61eb5f4de2d09a
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.2.4-1ubuntu2.1_powerpc.deb
Size/MD5: 345188 f5ae6066dbef03c3acf524ef890d6da3
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.2.4-1ubuntu2.1_powerpc.deb
Size/MD5: 455126 e78d418d23ec0a0a9ef62392f6970f82
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.2.4-1ubuntu2.1_powerpc.deb
Size/MD5: 382980 6dc5a272d5611a181c328ec2fbac6173
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.2.4-1ubuntu2.1_powerpc.udeb
Size/MD5: 146998 6f406f0fcb4f6638e13681704dde4af0

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.2.4-1ubuntu2.1_sparc.deb
Size/MD5: 383676 cb664835cbfc7460922bb947f32fb372
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.2.4-1ubuntu2.1_sparc.deb
Size/MD5: 333126 4493ce63b9596f0efcea952ed0e68580
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.2.4-1ubuntu2.1_sparc.deb
Size/MD5: 431944 a48df7da812e0ab97eb4905c28bfee02
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.2.4-1ubuntu2.1_sparc.deb
Size/MD5: 368906 8c723281873077a45359691886e656b8
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.2.4-1ubuntu2.1_sparc.udeb
Size/MD5: 135074 0ceca57c8f30bb224c867153ac1f5a13

Updated packages for Ubuntu 7.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.2-0ubuntu1.1.diff.gz
Size/MD5: 28909 dc5d96d605e11690a89a0cc59e042e65
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.2-0ubuntu1.1.dsc
Size/MD5: 980 09a868118408cab715afdba4a64544bf
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.2.orig.tar.gz
Size/MD5: 3081092 b254633046eafe603776d0bee791b751

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-doc_1.4.2-0ubuntu1.1_all.deb
Size/MD5: 328950 d240767edabea69fab2d1340061a8415

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.2-0ubuntu1.1_amd64.deb
Size/MD5: 514708 b394fa71b94e568a71e4ace24a2a1977
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.2-0ubuntu1.1_amd64.deb
Size/MD5: 429892 845d889c83417a8574f378694f81bbd1
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.2-0ubuntu1.1_amd64.deb
Size/MD5: 536802 7ed3be4626a9244c0fafb45fc010a280
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.2-0ubuntu1.1_amd64.deb
Size/MD5: 445778 6afcb89b07478475ac4a8979f1c1c308
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.2-0ubuntu1.1_amd64.udeb
Size/MD5: 213856 51637a90f27e73133b71a28ec312b76d

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.2-0ubuntu1.1_i386.deb
Size/MD5: 488474 321045d3cc696388a577d91cb1b2247c
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.2-0ubuntu1.1_i386.deb
Size/MD5: 419802 89c9b3258a0f360ada145028902d09a2
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.2-0ubuntu1.1_i386.deb
Size/MD5: 508426 5b857c0d96578e0be3a94dc946e2b517
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.2-0ubuntu1.1_i386.deb
Size/MD5: 435198 ccc97bd5ac8e03b2c19cc3b3d4fc1781
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.2-0ubuntu1.1_i386.udeb
Size/MD5: 203914 04537f47590bc36266085f342c401d58

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.2-0ubuntu1.1_powerpc.deb
Size/MD5: 498194 474be7633bf6807c5feed136a9e7a675
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.2-0ubuntu1.1_powerpc.deb
Size/MD5: 422678 13195737993d842cff7f86fe253c74bd
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.2-0ubuntu1.1_powerpc.deb
Size/MD5: 520250 36577274181793f8c962581e89621281
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.2-0ubuntu1.1_powerpc.deb
Size/MD5: 438486 e63d2bacd6728ff18133c4cfa821863e
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.2-0ubuntu1.1_powerpc.udeb
Size/MD5: 206840 84b1ad8e538fd2f7c2e7244acc145d89

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.2-0ubuntu1.1_sparc.deb
Size/MD5: 471746 caefead3a3d701d2511f569bef6f7c5b
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.2-0ubuntu1.1_sparc.deb
Size/MD5: 402034 b67d2c0dc7b8463c5dc490f61a67b99d
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.2-0ubuntu1.1_sparc.deb
Size/MD5: 491938 1d6e659088b0640d97e3706388f8395e
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.2-0ubuntu1.1_sparc.deb
Size/MD5: 416758 4d7530c925a14f982b46c3d21e736540
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.2-0ubuntu1.1_sparc.udeb
Size/MD5: 186118 7b18ab17c8e4362d52fd339ea1ecdf45

Updated packages for Ubuntu 7.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.10-1ubuntu4.1.diff.gz
Size/MD5: 35570 12f55e0fce101397b1030e3085e787e9
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.10-1ubuntu4.1.dsc
Size/MD5: 1013 563489e7174346f4fbbd0503a3c0f9ed
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo_1.4.10.orig.tar.gz
Size/MD5: 3216689 5598a5e500ad922e37b159dee72fc993

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-doc_1.4.10-1ubuntu4.1_all.deb
Size/MD5: 407584 264885e31177e66f213e1105cf87b1f7

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.10-1ubuntu4.1_amd64.deb
Size/MD5: 571828 988ad2fddde5034618d78dce50b2ac34
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.10-1ubuntu4.1_amd64.deb
Size/MD5: 488860 8702b2a50e6a7021c7ed56dcea3c7f10
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.10-1ubuntu4.1_amd64.deb
Size/MD5: 632534 9ee7fd807a87bf3cbe6a582f7ceaee45
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.10-1ubuntu4.1_amd64.deb
Size/MD5: 536752 b07df53c9796fa11031fa9cb1188285d
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.10-1ubuntu4.1_amd64.udeb
Size/MD5: 195644 4db32d0439a5d30782c2862a6a238a13

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.10-1ubuntu4.1_i386.deb
Size/MD5: 546244 dcdca233fd9dfe301bdc4eb003958e73
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.10-1ubuntu4.1_i386.deb
Size/MD5: 479388 f72bfa5554759ab7121f86dff86e1b96
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.10-1ubuntu4.1_i386.deb
Size/MD5: 601014 e6ad6e1a08cd5eb80b3004727a502b6e
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.10-1ubuntu4.1_i386.deb
Size/MD5: 523870 7904ff1c74a8fb55504e02eb7ea83a05
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.10-1ubuntu4.1_i386.udeb
Size/MD5: 186260 e23492f349678781988ab526a5f5b371

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.10-1ubuntu4.1_powerpc.deb
Size/MD5: 554614 4aa9520c327bc96bf0f33e740584a4b8
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.10-1ubuntu4.1_powerpc.deb
Size/MD5: 478798 c25f183b7bd4291d8de295b98dceecfa
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.10-1ubuntu4.1_powerpc.deb
Size/MD5: 613700 13bf3f4c94d3cfb6141f20beccbaaa76
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.10-1ubuntu4.1_powerpc.deb
Size/MD5: 528254 693491287b6695c4487604199f285dd6
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.10-1ubuntu4.1_powerpc.udeb
Size/MD5: 186174 39dd373e44b1e0e3138c78e313ba332a

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2-dev_1.4.10-1ubuntu4.1_sparc.deb
Size/MD5: 543434 f26a9fd33bba743ce57168a92e6fab15
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo-directfb2_1.4.10-1ubuntu4.1_sparc.deb
Size/MD5: 470870 44c50c6a3b2a3b6b22e7c9df743f1ede
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2-dev_1.4.10-1ubuntu4.1_sparc.deb
Size/MD5: 584514 3cb9245c5f4acd9b78177dadd3a43279
http://security.ubuntu.com/ubuntu/pool/main/libc/libcairo/libcairo2_1.4.10-1ubuntu4.1_sparc.deb
Size/MD5: 505054 2272a6ba6f78bf385f9cc1d21cfd078c
http://security.ubuntu.com/ubuntu/pool/universe/libc/libcairo/libcairo-directfb2-udeb_1.4.10-1ubuntu4.1_sparc.udeb
Size/MD5: 177480 4d618844733ed433ca2afc74a52e47a6


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHVHhSH/9LqRcGPm0RAnMaAJ9gKkuJewSxigRh+ah2WGMxYf0BiACgjyIW
St0zaG1Y0pYUZ8wJmRAGX6k=
=OVNT
-----END PGP SIGNATURE-----