OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ISS Security Alert Summary AS03-40

From: X-Force (xforceiss.net)
Date: Mon Oct 06 2003 - 16:02:34 CDT


-----BEGIN PGP SIGNED MESSAGE-----

Internet Security Systems Security Alert Summary AS03-40
October 06, 2003

X-Force Vulnerability and Threat Database:
http://xforce.iss.net/

To receive these Alert Summaries, as well as other Alerts and
Advisories, subscribe to the Internet Security Systems Alert
mailing list at:
https://atla-mm1.iss.net/mailman/listinfo/alert

This summary is available at the following address:
http://xforce.iss.net/xforce/alerts/id/AS03-40
_____
Contents:
* 41 Reported Vulnerabilities
* Risk Factor Key
_____

Date Reported: 10/02/2003
Brief Description: Overture Keyword field in search page allows cross-
                    site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, Overture Any version, Unix Any
                    version, Windows Any version
Vulnerability: overture-keyword-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/11839

Date Reported: 09/29/2003
Brief Description: mIRC USERHOST reply buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: mIRC 6.01 through 6.1, Windows Any version
Vulnerability: mirc-userhost-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13302

Date Reported: 09/27/2003
Brief Description: A-CART signin.asp script cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: A-CART 2.0, A-CART Pro Any version, Windows Any
                    version
Vulnerability: acart-signin-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13303

Date Reported: 09/28/2003
Brief Description: Invision Power Board allows access to conf_global
                    configuration file
Risk Factor: High
Attack Type: Host Based
Platforms: Invision Power Board 1.1.1, Linux Any version, Unix
                    Any version
Vulnerability: invision-confglobal-file-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13304

Date Reported: 09/26/2003
Brief Description: Sambar Server multiple vulnerabilities
Risk Factor: Medium
Attack Type: Host Based / Network Based
Platforms: Sambar Server prior to 6.0 Beta 6, Windows Any
                    version
Vulnerability: sambar-multiple-vulnerabilities
X-Force URL: http://xforce.iss.net/xforce/xfdb/13305

Date Reported: 09/28/2003
Brief Description: GuppY postguest.php cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: GuppY prior to 2.4p1, Linux Any version, Unix Any
                    version, Windows Any version
Vulnerability: guppy-postguest-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13306

Date Reported: 09/29/2003
Brief Description: webfs long pathname buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Debian Linux 3.0, webfs Any version
Vulnerability: webfs-long-pathname-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13308

Date Reported: 09/29/2003
Brief Description: webfs "dot dot" directory traversal
Risk Factor: Medium
Attack Type: Network Based
Platforms: Debian Linux 3.0, webfs Any version
Vulnerability: webfs-dotdot-directory-traversal
X-Force URL: http://xforce.iss.net/xforce/xfdb/13309

Date Reported: 09/29/2003
Brief Description: ArGoSoft FTP Server XCMD command followed by long
                    string causes buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: ArGoSoft FTP Server 1.4.1.1, Windows Any version
Vulnerability: argosoftftp-xcmd-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13311

Date Reported: 09/28/2003
Brief Description: Geeklog multiple scripts SQL injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: Geeklog 1.x, Geeklog 2.x, Linux Any version,
                    Windows Any version
Vulnerability: geeklog-multiple-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13312

Date Reported: 09/28/2003
Brief Description: Geeklog multiple scripts cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Geeklog 1.x, Geeklog 2.x, Linux Any version,
                    Windows Any version
Vulnerability: geeklog-multiple-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13313

Date Reported: 09/30/2003
Brief Description: OpenSSL ASN.1 denial of service
Risk Factor: High
Attack Type: Network Based
Platforms: Cisco ACNS Any version, Cisco Content Service
                    Switch 11000 series, Cisco CSS Secure Content
                    Accelerator 1, Cisco CSS Secure Content Accelerator
                    2, Cisco Firewall Services Module Any version,
                    Cisco Global Site Selector (GSS) 4880, Cisco Global
                    Site Selector (GSS) 4880, Cisco Global Site
                    Selector (GSS) 4880, Cisco IOS 12.1(11)E and later,
                    Cisco IOS 12.1(11)E and later, Cisco IOS 12.1(11)E
                    and later, Cisco IOS 12.2SX, Cisco IOS 12.2SY,
                    Cisco Network Analysis Module Any version, Cisco
                    PIX Firewall Any version, Cisco SIP Proxy Server
                    (SPS) Any version, Cisco SIP Proxy Server (SPS) Any
                    version, Cisco SIP Proxy Server (SPS) Any version,
                    Cisco SN 5428 Storage Router Any version, Cisco
                    Threat Response (CTR) Any version, Cisco Threat
                    Response (CTR) Any version, Cisco Threat Response
                    (CTR) Any version, CiscoWorks 1105 HSE Any version,
                    CiscoWorks 1105 WLSE Any version, CiscoWorks CMF
                    Any version, Conectiva Linux 7.0, Conectiva Linux
                    8.0, Conectiva Linux 9.0, FreeBSD 4.0- 4.8-RELEASE,
                    FreeBSD 5.0-RELEASE, FreeBSD 5.1-RELEASE, Gentoo
                    Linux Any version, HP-UX 11.00, HP-UX 11.11, HP-UX
                    11.20, HP-UX 11.22, HP-UX 11.23, IRIX prior to
                    6.5.22, Mandrake Linux 8.2, Mandrake Linux 9.0,
                    Mandrake Linux 9.1, Mandrake Linux 9.2, Mandrake
                    Linux Corporate Server 2.1, Mandrake Multi Network
                    Firewall 8.2, OpenPKG 1.2, OpenPKG 1.3, OpenPKG
                    CURRENT, OpenSSL 0.9.7b and earlier, Red Hat Linux
                    9, SSLeay Any version, SuSE eMail Server 3.1, SuSE
                    eMail Server III Any version, SuSE Linux 7.2, SuSE
                    Linux 7.3, SuSE Linux 8.0, SuSE Linux 8.1, SuSE
                    Linux 8.2, SuSE Linux 9.0, SuSE Linux Connectivity
                    Server Any version, SuSE Linux Database Server Any
                    version, SuSE Linux Enterprise Server 7, SuSE Linux
                    Enterprise Server 8, SuSE Linux Firewall Any
                    version, SuSE Linux Office Server Any version
Vulnerability: openssl-asn1-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13315

Date Reported: 09/30/2003
Brief Description: OpenSSL ASN.1 SSL certificate denial of service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Cisco ACNS Any version, Cisco Content Service
                    Switch 11000 series, Cisco CSS Secure Content
                    Accelerator 1, Cisco CSS Secure Content Accelerator
                    2, Cisco Firewall Services Module Any version,
                    Cisco Global Site Selector (GSS) 4880, Cisco
                    IOS 12.1(11)E and later, Cisco IOS 12.2SX, Cisco IOS
                    12.2SY, Cisco Network Analysis Module Any version, Cisco
                    PIX Firewall Any version, Cisco SIP Proxy Server
                    (SPS) Any version, Cisco SIP Proxy Server (SPS) Any
                    version, Cisco SIP Proxy Server (SPS) Any version,
                    Cisco SN 5420 Storage Router Any version, Cisco
                    Threat Response (CTR) Any version, Cisco Threat
                    Response (CTR) Any version, Cisco Threat Response
                    (CTR) Any version, CiscoWorks 1105 HSE Any version,
                    CiscoWorks 1105 WLSE Any version, CiscoWorks CMF
                    Any version, Conectiva Linux 7.0, Conectiva Linux
                    8.0, Conectiva Linux 9.0, Debian Linux 3.0, EnGarde
                    Secure Linux 1.0.1, EnGarde Secure Linux Community
                    Edition 2, EnGarde Secure Linux Professional
                    Edition, FreeBSD 4.0- 4.8-RELEASE, FreeBSD 5.0-
                    RELEASE, FreeBSD 5.1-RELEASE, Gentoo Linux Any
                    version, HP-UX 11.00, HP-UX 11.11, HP-UX 11.20, HP-
                    UX 11.22, HP-UX 11.23, Immunix OS 7+-beta, Immunix
                    OS 7+-beta, Immunix OS 7+-beta, IRIX prior to
                    6.5.22, Mandrake Linux 8.2, Mandrake Linux 9.0,
                    Mandrake Linux 9.1, Mandrake Linux 9.2, Mandrake
                    Linux Corporate Server 2.1, Mandrake Multi Network
                    Firewall 8.2, OpenPKG 1.2, OpenPKG 1.3, OpenPKG
                    CURRENT, OpenSSL 0.9.6j and earlier, OpenSSL 0.9.7b
                    and earlier, Red Hat Advanced Workstation 2.1, Red
                    Hat Enterprise Linux 2.1AS, Red Hat Enterprise
                    Linux 2.1ES, Red Hat Enterprise Linux 2.1WS, Red
                    Hat Linux 7.1, Red Hat Linux 7.2, Red Hat Linux
                    7.3, Red Hat Linux 8.0, Red Hat Linux 9, Slackware
                    Linux 8.1, Slackware Linux 9.0, Slackware Linux
                    9.1, Slackware Linux current, SSLeay Any version,
                    SuSE eMail Server 3.1, SuSE eMail Server III Any
                    version
Vulnerability: openssl-asn1-ssl-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13316

Date Reported: 09/30/2003
Brief Description: OpenSSL public key denial of service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Cisco ACNS Any version, Cisco Content Service
                    Switch 11000 series, Cisco CSS Secure Content
                    Accelerator 1, Cisco CSS Sy version, Cisco
                    Global Site Selectoecure Content Accelerator
                    2, Cisco Firewall Services Module Anr (GSS) 4880, Cisco
                    IOS 12.1(11)E and later, Cisco IOS 12.2SX, Cisco
                    IOS 12.2SY, Network Analysis Module Any version, Cisco
                    PIX Firewall Any version, Cisco SIP Proxy Server
                    (SPS) Any version, Cisco SN 5428 Storage Router
                    Any version, Cisco Threat Response (CTR) Any
                    version, CiscoWorks 1105 HSE Any version
                    (CTR) Any version, CiscoWorks 1105 HSE Any version,
                    CiscoWorks CiscoWorks CMF Any version, OpenPKG
                    1.2, OpenPKG 1.3, OpenPKG CURRENT, OpenSSL
                    0.9.6j and earlier, OpenSSL 0.9.7b
                    and earlier
Vulnerability: openssl-public-key-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13317

Date Reported: 09/30/2003
Brief Description: winShadow long password and username denial of
                    service
Risk Factor: Low
Attack Type: Network Based
Platforms: Windows Any version, winShadow 2.0
Vulnerability: winshadow-long-password-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13318

Date Reported: 09/30/2003
Brief Description: winShadow session file hostname buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Windows Any version, winShadow 2.0
Vulnerability: winshadow-session-hostname-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13319

Date Reported: 09/28/2003
Brief Description: mj-server long parameter buffer overflow
Risk Factor: High
Attack Type: Host Based
Platforms: Linux Any version, mj-server Any version, Unix Any
                    version
Vulnerability: mjserver-parameter-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13320

Date Reported: 09/30/2003
Brief Description: OpenSSL fails to properly parse certificates
Risk Factor: Medium
Attack Type: Network Based
Platforms: Cisco ACNS Any version, Cisco Content Service
                    Switch 11000 series, Cisco CSS Secure Content
                    Accelerator 1, Cisco CSS Secure Content Accelerator
                    2, Cisco Firewall Services Module Any version,
                    Cisco Global Site Selector (GSS) 4880, Cisco Global
                    Site Selector (GSS) 4880, Cisco Global Site
                    Selector (GSS) 4880, Cisco IOS 12.1(11)E and later,
                    Cisco IOS 12.1(11)E and later, Cisco IOS 12.1(11)E
                    and later, Cisco IOS 12.2SX, Cisco IOS 12.2SY,
                    Cisco Network Analysis Module Any version, Cisco
                    PIX Firewall Any version, Cisco SIP Proxy Server
                    (SPS) Any version, Cisco SIP Proxy Server (SPS) Any
                    version, Cisco SIP Proxy Server (SPS) Any version,
                    Cisco SN 5428 Storage Router Any version, Cisco
                    Threat Response (CTR) Any version, Cisco Threat
                    Response (CTR) Any version, Cisco Threat Response
                    (CTR) Any version, CiscoWorks 1105 HSE Any version,
                    CiscoWorks 1105 WLSE Any version, CiscoWorks CMF
                    Any version, OpenPKG 1.2, OpenPKG 1.3, OpenPKG
                    CURRENT, OpenSSL 0.9.6j and earlier, OpenSSL 0.9.7b
                    and earlier, SSLeay Any version
Vulnerability: openssl-improper-certificate-parsing
X-Force URL: http://xforce.iss.net/xforce/xfdb/13322

Date Reported: 09/28/2003
Brief Description: Geeklog shoutbox allows cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Geeklog 1.x, Geeklog 2.x, Linux Any version,
                    Windows Any version
Vulnerability: geeklog-shoutbox-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13323

Date Reported: 09/30/2003
Brief Description: SSH Sentinel BER/DER packet denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: SSH Sentinel 1.4, Windows Any version
Vulnerability: ssh-sentinel-ber-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13324

Date Reported: 09/30/2003
Brief Description: GameSpy 3D IRC server response could allow an
                    attacker to execute code
Risk Factor: High
Attack Type: Network Based
Platforms: GameSpy 3D 2.63.015 and earlier, Windows Any
                    version
Vulnerability: gamespy-irc-code-execution
X-Force URL: http://xforce.iss.net/xforce/xfdb/13325

Date Reported: 09/30/2003
Brief Description: silly Poker buffer overflow in HOME environment
                    variable
Risk Factor: High
Attack Type: Host Based
Platforms: Linux Any version, silly Poker 0.25.5, Unix Any
                    version
Vulnerability: sillypoker-home-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13326

Date Reported: 09/30/2003
Brief Description: 1ASPCommerce administrative access to remote users
Risk Factor: Medium
Attack Type: Network Based
Platforms: 1ASPCommerce 1.2 and earlier, Windows Any version
Vulnerability: 1aspcommerce-file-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13327

Date Reported: 10/01/2003
Brief Description: IBM AIX Sendmail application getnodebyname API
                    denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: AIX 5.1, AIX 5.2
Vulnerability: aix-sendmail-getipnodebyname-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13328

Date Reported: 10/01/2003
Brief Description: Everyfind URL cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Everyfind 5.02, Windows Any version
Vulnerability: everyfind-url-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13329

Date Reported: 10/01/2003
Brief Description: IBM DB2 LOAD command buffer overflow
Risk Factor: High
Attack Type: Host Based / Network Based
Platforms: IBM DB2 UDB 7.2, IBM DB2 UDB 8.1, Linux Any
                    version, Windows Any version
Vulnerability: db2-load-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13330

Date Reported: 10/01/2003
Brief Description: IBM DB2 INVOKE buffer overflow
Risk Factor: High
Attack Type: Host Based / Network Based
Platforms: IBM DB2 UDB 7.2, Windows Any version
Vulnerability: db2-invoke-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13331

Date Reported: 10/01/2003
Brief Description: DCP-Portal advertiser.php SQL injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: DCP-Portal 5.5, Linux Any version, Windows Any
                    version
Vulnerability: dcpportal-advertiser-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13332

Date Reported: 10/02/2003
Brief Description: MPWeb Pro "dot dot" directory traversal
Risk Factor: Medium
Attack Type: Network Based
Platforms: MPWeb Pro 1.1.2.13, Windows Any version
Vulnerability: mpwebpro-dotdot-directory-traversal
X-Force URL: http://xforce.iss.net/xforce/xfdb/13333

Date Reported: 10/01/2003
Brief Description: DCP-Portal lostpassword.php script allows SQL
                    injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: DCP-Portal 5.5, Linux Any version, Windows Any
                    version
Vulnerability: dcpportal-lostpassword-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13334

Date Reported: 10/01/2003
Brief Description: DCP-Portal advertiser.php path disclosure
Risk Factor: Medium
Attack Type: Network Based
Platforms: DCP-Portal 5.5, Linux Any version, Windows Any
                    version
Vulnerability: dcpportal-advertiser-path-disclosure
X-Force URL: http://xforce.iss.net/xforce/xfdb/13335

Date Reported: 09/30/2003
Brief Description: Novell Distributed Print Services allows attacker
                    to obtain information by sending HTTP request
Risk Factor: Medium
Attack Type: Network Based
Platforms: Novell Distributed Print Services (NDPS) Any
                    version, Novell Distributed Print Services (NDPS)
                    Any version, Novell Distributed Print Services
                    (NDPS) Any version, Novell iPrint Any version,
                    Novell NetWare 5.1, Novell NetWare 6
Vulnerability: novell-ndps-obtain-information
X-Force URL: http://xforce.iss.net/xforce/xfdb/13337

Date Reported: 09/29/2003
Brief Description: HP-UX socket programs denial of service
Risk Factor: Low
Attack Type: Host Based
Platforms: HP-UX 11.00
Vulnerability: hp-socket-program-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13338

Date Reported: 10/02/2003
Brief Description: VisualRoute LAN topology disclosure
Risk Factor: Medium
Attack Type: Network Based
Platforms: FreeBSD Any version, Linux Any version, Mac OS X
                    Any version, Solaris Any version, VisualRoute Any
                    version, Windows Any version
Vulnerability: visualroute-obtain-lan-topology
X-Force URL: http://xforce.iss.net/xforce/xfdb/13339

Date Reported: 10/02/2003
Brief Description: OpenSSL SSLv2 CLIENT_MASTER_KEY denial of service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Conectiva Linux 7.0, Conectiva Linux 8.0, OpenSSL
                    prior to 0.9.6f, Red Hat Linux 7.1, Red Hat Linux
                    7.2, Red Hat Linux 7.3
Vulnerability: openssl-sslv2-clientmasterkey-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13340

Date Reported: 10/02/2003
Brief Description: FreeBSD readv could leak sensitive file descriptors
Risk Factor: High
Attack Type: Host Based
Platforms: FreeBSD 4.3-4.8-RELEASE, FreeBSD 4-STABLE
Vulnerability: freebsd-readv-descriptor-leak
X-Force URL: http://xforce.iss.net/xforce/xfdb/13341

Date Reported: 10/02/2003
Brief Description: Microsoft Windows PostThreadMessage API allows
                    processes to be terminated without permission
Risk Factor: Low
Attack Type: Host Based
Platforms: Windows 2000 Advanced Server, Windows 2000
                    Datacenter Server, Windows 2000 Professional,
                    Windows 2000 Server, Windows NT 4.0 Server, Windows
                    NT 4.0 TSE, Windows NT 4.0 Workstation, Windows
                    Server 2003 Datacenter Edition, Windows Server 2003
                    Enterprise Edition, Windows Server 2003 Standard
                    Edition, Windows Server 2003 Web Edition, Windows
                    XP Home, Windows XP Professional
Vulnerability: win-postthreadmessage-terminate-process
X-Force URL: http://xforce.iss.net/xforce/xfdb/13342

Date Reported: 10/03/2003
Brief Description: FreeBSD procfs integer overflow/underflow
Risk Factor: High
Attack Type: Host Based
Platforms: FreeBSD Any version
Vulnerability: freebsd-procfs-integer-overflow
X-Force URL: http://xforce.iss.net/xforce/xfdb/13343

Date Reported: 10/02/2003
Brief Description: NetScreen ScreenOS memory leak in previously used
                    buffer
Risk Factor: Medium
Attack Type: Network Based
Platforms: NetScreen Any version, ScreenOS 4.0.3r3 and earlier
Vulnerability: netscreen-screenos-memory-leak
X-Force URL: http://xforce.iss.net/xforce/xfdb/13345

Date Reported: 10/04/2003
Brief Description: Sun Cobalt RaQ server message.cgi cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Cobalt RaQ 550
Vulnerability: cobalt-raq-message-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13347

Date Reported: 10/03/2003
Brief Description: divine Content Server error page cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: divine Content Server Any version, Windows Any
                    version
Vulnerability: divine-content-error-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13348

_____

Risk Factor Key:

     High Security issues that allow immediate remote, or local access
              or immediate execution of code or commands, with unauthorized
              privileges. Examples are most buffer overflows, backdoors,
              default or no password, and bypassing security on firewalls
              or other network components.
     Medium Security issues that have the potential of granting access or
              allowing code execution by means of complex or lengthy exploit
              procedures, or low risk issues applied to major Internet
              components. Examples are cross-site scripting, man-in-the-middle
              attacks, SQL injection, denial of service of major applications,
              and denial of service resulting in system information disclosure
              (such as core files).
     Low Security issues that deny service or provide non-system
              information that could be used to formulate structured attacks
              on a target, but not directly gain unauthorized access. Examples
              are brute force attacks, non-system information disclosure
              (configurations, paths, etc.), and denial of service attacks.

______

About Internet Security Systems (ISS)
Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
pioneer and world leader in software and services that protect critical
online resources from an ever-changing spectrum of threats and misuse.
Internet Security Systems is headquartered in Atlanta, GA, with
additional operations throughout the Americas, Asia, Australia, Europe
and the Middle East.

Copyright (c) 2003 Internet Security Systems, Inc. All rights reserved
worldwide.

Permission is hereby granted for the electronic redistribution of this
document. It is not to be edited or altered in any way without the
express written consent of the Internet Security Systems X-Force. If you
wish to reprint the whole or any part of this document in any other
medium excluding electronic media, please email xforceiss.net for
permission.

Disclaimer: The information within this paper may change without notice. Internet
Security Systems provides this information on an AS IS basis with NO warranties,
implied or otherwise. Any use of this information is at the user’s risk. In no event
shall Internet Security Systems be held liable for any damages whatsoever arising
out of or in connection with the use or dissemination of this information.

X-Force PGP Key available on MIT's PGP key server and PGP.com's key server,
as well as at http://xforce.iss.net/xforce/sensitive.php

Please send suggestions, updates, and comments to: X-Force
xforceiss.net of Internet Security Systems, Inc.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBP4Gx5jRfJiV99eG9AQHx6gP/e25PRNqHzV2j8wKTJrrya9d09YIOxhUC
UREC8NP38QMR49B0XIYj+F2nv3zStUtxKXVN7wxGzoD+v6qSfeFIOnCV4GS7Gi5v
OnR12dQw6oUPXisCCc3WCgMKUeXK/4TAQhvgFeXvL3qzBdj/B/kx9PFJr+bUrCty
e8JlCRET1NE=
=DRtk
-----END PGP SIGNATURE-----