June 2007

[Other] GD Graphics Library Multiple Vulnerabilitie

TITLE:
GD Graphics Library Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA25855

VERIFY ADVISORY:
http://secunia.com/advisories/25855/

CRITICAL:
Moderately critical

IMPACT:
Unknown, DoS

WHERE:
From remote

SOFTWARE:
GD Graphics Library 2.x
http://secunia.com/product/4178/

DESCRIPTION:
Some vulnerabilities have been reported in the GD Graphics Library,
where some have unknown impact and others can potentially be exploited
to cause a DoS.

1) An integer overflow exists in the “gdImageCreateTrueColor()”
function.

2) An error in the “gdImageCreateXbm()” function can potentially be
exploited to cause a crash.

Various issues in the GIF reader have also been reported as security
related.

SOLUTION:
Update to version 2.0.35.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://www.libgd.org/ReleaseNote020035

[Joomla] Joomla! Section Manager Script Insertio

TITLE:
Joomla! Section Manager Script Insertion

SECUNIA ADVISORY ID:
SA25804

VERIFY ADVISORY:
http://secunia.com/advisories/25804/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting

WHERE:
From remote

SOFTWARE:
Joomla! 1.x
http://secunia.com/product/5788/

DESCRIPTION:
Cindy Chee has discovered a vulnerability in Joomla!, which can be
exploited by malicious people to conduct cross-site scripting attacks.

Input passed to the “Title” and “Section Name” form fields when creating
new sections in Section Manager is not properly sanitised before being
stored. This can be exploited to insert arbitrary HTML and script code,
which is executed in a user’s browser session in context of an affected
site when the data is viewed.

Successful exploitation requires that the target user has valid
administrator credentials.

The vulnerability is confirmed in version 1.0.12. Other versions may
also be affected.

SOLUTION:
Do not browse untrusted sites when logged in as administrator.

PROVIDED AND/OR DISCOVERED BY:
Cindy Chee

ORIGINAL ADVISORY:
http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&
tracker_item_id=5654

Next »