Release Date: 2008-10-31
Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch
OS: Gentoo Linux 1.x
Description:
Gentoo has issued an update for libspf2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Solution:
Update to "mail-filter/libspf2-1.2.8" or later.
Original Advisory:
GLSA-200810-03:
http://www.gentoo.org/security/en/glsa/glsa-200810-03.xml
Other References:
SA32396:
http://secunia.com/advisories/32396/
PHP-Nuke BookCatalog Module "catid" SQL Injection Vulnerability
Release Date: 2008-10-31
Critical:
Moderately critical
Impact: Manipulation of data
Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: BookCatalog 1.x (module for PHP-Nuke)
Description:
Ehsan_Hp200 has reported a vulnerability in the BookCatalog module for PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "catid" parameter via modules.php (when "name" is set to "BookCatalog" and "op" is set to "category") is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
Ehsan_Hp200
Original Advisory:
http://packetstorm.linuxsecurity.com/0810-exploits/phpnukebook-sql.txt

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic