Release Date: 2008-10-03
Critical:
Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
Software: XAMPP 1.x
Description:
Jaykishan Nirmal has discovered some vulnerabilities in XAMPP, which can be exploited by malicious people to conduct cross-site scripting attacks.
Input passed to the "dbserver", "host", "user", "password", "database", and "table" parameters in xmapp/adodb.php is not properly sanitised before being returned to a user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
The vulnerabilities are confirmed in version 1.6.8 (Windows Installer). Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
Jaykishan Nirmal, Aujas Networks
Red Hat update for pam_krb5
Release Date: 2008-10-03
Critical:
Less critical
Impact: Security Bypass
Where: Local system
Solution Status: Vendor Patch
OS: Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
Description:
Red Hat has issued an update for pam_krb5. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Solution:
Updated packages are available via Red Hat Network.
http://rhn.redhat.com
Original Advisory:
RHSA-2008-0907:
https://rhn.redhat.com/errata/RHSA-2008-0907.html
Other References:
SA32119:
http://secunia.com/advisories/32119/

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic