OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ISS Security Alert Summary AS04-09

From: X-Force (xforceiss.net)
Date: Mon Mar 01 2004 - 12:41:18 CST


-----BEGIN PGP SIGNED MESSAGE-----

Internet Security Systems Security Alert Summary AS04-09
March 01, 2004

X-Force Vulnerability and Threat Database:
http://xforce.iss.net/

To receive these Alert Summaries, as well as other Alerts and
Advisories, subscribe to the Internet Security Systems Alert
mailing list at:
https://atla-mm1.iss.net/mailman/listinfo/alert

This summary is available at the following address:
http://xforce.iss.net/xforce/alerts/id/AS04-09
_____
Contents:
* 60 Reported Vulnerabilities
* Risk Factor Key
_____

Date Reported: 02/26/2004
Brief Description: PAM component buffer overflow when parsing
                    SMB protocol
Risk Factor: High
Attack Type: Network Based
Platforms: BlackICE PC Protection: 3.6 cbr through ccb,
                    BlackICE Server Protection: 3.6 cbr through ccb,
                    Linux: Any version, RealSecure Desktop: 7.0
                    eba through ebh, RealSecure Desktop: 3.6 ebr
                    through ecb, RealSecure Guard: 3.6 ebr
                    through ecb, RealSecure Network Sensor: 7.0
                    XPU 20.15 - 22.9, RealSecure Sentry: 3.6 ebr
                    through ecb, RealSecure Server Sensor: 7.0
                    XPU 20.16 - 22.9, Windows: Any version
Vulnerability: pam-smb-protocol-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15207

Date Reported: 02/21/2004
Brief Description: LBreakout2 HOME environment variable buffer
                    overflow
Risk Factor: High
Attack Type: Network Based
Platforms: LBreakout2 prior to 2.4beta-2, Linux Any version
Vulnerability: lbreakout2-home-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15229

Date Reported: 02/20/2004
Brief Description: PSOProxy long HTTP GET request buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Linux Any version, PSOProxy 0.91, Windows Any
                    version
Vulnerability: psoproxy-long-get-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15275

Date Reported: 02/22/2004
Brief Description: hsftp format string attack
Risk Factor: High
Attack Type: Network Based
Platforms: Debian Linux 3.0, hsftp Any version, Linux Any
                    version, Unix Any version
Vulnerability: hsftp-format-string
X-Force URL: http://xforce.iss.net/xforce/xfdb/15276

Date Reported: 02/23/2004
Brief Description: Proxy-Pro GateKeeper Pro long HTTP GET buffer
                    overflow
Risk Factor: High
Attack Type: Network Based
Platforms: GateKeeper Pro 4.7, Windows Any version
Vulnerability: gatekeeper-long-get-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15277

Date Reported: 02/23/2004
Brief Description: Load Sharing Facility eauth component could
                    allow attacker to hijack other user's process
Risk Factor: Medium
Attack Type: Network Based
Platforms: Any operating system Any version, LSF 4.x, LSF 5.x,
                    LSF 6.x
Vulnerability: lsf-eauth-process-hijack
X-Force URL: http://xforce.iss.net/xforce/xfdb/15278

Date Reported: 02/21/2004
Brief Description: Synaesthesia configuration file symlink attack
Risk Factor: Medium
Attack Type: Host Based
Platforms: Linux Any version, Synaesthesia 2.2 and earlier,
                    Unix Any version
Vulnerability: synaesthesia-configuration-symlink-attack
X-Force URL: http://xforce.iss.net/xforce/xfdb/15279

Date Reported: 02/21/2004
Brief Description: Proofpoint Protection Server MySQL allows
                    unauthorized access
Risk Factor: Medium
Attack Type: Network Based
Platforms: Proofpoint Protection Server Any version, Red Hat
                    Linux Any version
Vulnerability: proofpoint-mysql-gain-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/15280

Date Reported: 02/23/2004
Brief Description: nCipher HSM information disclosure
Risk Factor: Medium
Attack Type: Host Based
Platforms: nCipher HSM 1.67.x - 1.99.x, nCipher HSM 2.0.0 and
                    later, nCipher HSM 2.12.0 and later, Windows Any
                    version
Vulnerability: ncipher-hsm-obtain-info
X-Force URL: http://xforce.iss.net/xforce/xfdb/15281

Date Reported: 02/23/2004
Brief Description: Load Sharing Facility eauth component allows code
                    execution
Risk Factor: High
Attack Type: Host Based / Network Based
Platforms: Any operating system Any version, LSF 4.x, LSF 5.x,
                    LSF 6.x
Vulnerability: lsf-eauth-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/15282

Date Reported: 02/23/2004
Brief Description: PhpNewsManager "dot dot" directory traversal
Risk Factor: Medium
Attack Type: Network Based
Platforms: Any operating system Any version, PhpNewsManager
                    1.46
Vulnerability: phpnewsmanager-dotdot-directory-traversal
X-Force URL: http://xforce.iss.net/xforce/xfdb/15283

Date Reported: 02/23/2004
Brief Description: Microsoft Windows XP Windows shell shimgvw.dll
                    buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Windows XP Any version
Vulnerability: winxp-shell-shimgvw-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15284

Date Reported: 02/22/2004
Brief Description: Dell TrueMobile Help files allow attacker to gain
                    privileges
Risk Factor: High
Attack Type: Host Based
Platforms: TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet
                    3.10.39.0, Windows XP Any version
Vulnerability: dell-truemobile-gain-privileges
X-Force URL: http://xforce.iss.net/xforce/xfdb/15285

Date Reported: 02/23/2004
Brief Description: Avirt SOHO multiple buffer overflows
Risk Factor: Low
Attack Type: Network Based
Platforms: Avirt SOHO 4.3, Windows Any version
Vulnerability: avirt-soho-multiple-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15286

Date Reported: 02/23/2004
Brief Description: ezboard font tag cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Any operating system Any version, ezboard 7u
Vulnerability: ezboard-font-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15287

Date Reported: 02/23/2004
Brief Description: Avirt Voice long GET request buffer overflow
Risk Factor: Medium
Attack Type: Network Based
Platforms: Avirt Voice 4.0, Windows Any version
Vulnerability: avirt-voice-get-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15288

Date Reported: 02/22/2004
Brief Description: WebzEdit done.jsp cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Any operating system Any version, WebzEdit 1.9 and
                    earlier
Vulnerability: webzedit-done-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15289

Date Reported: 02/23/2004
Brief Description: Confirm header allows unauthorized access
Risk Factor: High
Attack Type: Network Based
Platforms: Confirm 0.62 and earlier, Linux Any version
Vulnerability: confirm-header-gain-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/15290

Date Reported: 02/23/2004
Brief Description: Darwin Streaming Server DESCRIBE request denial of
                    service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Darwin Streaming Server 4.1.3
Vulnerability: darwin-describe-request-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15291

Date Reported: 02/23/2004
Brief Description: XMB multiple scripts allow cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, Windows Any version, XMB 1.8 SP2
Vulnerability: xmb-multiple-scripts-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15292

Date Reported: 02/24/2004
Brief Description: Apache for Cygwin "dot dot" directory traversal
Risk Factor: Medium
Attack Type: Network Based
Platforms: Apache HTTP Server 1.3.29 and earlier, Apache HTTP
                    Server 2.0.48 and earlier, Cygwin Any version
Vulnerability: apache-cygwin-directory-traversal
X-Force URL: http://xforce.iss.net/xforce/xfdb/15293

Date Reported: 02/23/2004
Brief Description: XMB embed script within BBCode image or align tags
                    allows execution of code
Risk Factor: High
Attack Type: Network Based
Platforms: Linux Any version, Windows Any version, XMB 1.8 SP2
Vulnerability: xmb-bbcode-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/15294

Date Reported: 02/23/2004
Brief Description: XMB multiple scripts allow SQL injection
Risk Factor: High
Attack Type: Network Based
Platforms: Linux Any version, Windows Any version, XMB 1.8 SP2
Vulnerability: xmb-multiple-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/15295

Date Reported: 02/24/2004
Brief Description: Opt-X header.php PHP file include
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, Opt-X 0.7.2
Vulnerability: optx-header-file-include
X-Force URL: http://xforce.iss.net/xforce/xfdb/15296

Date Reported: 02/23/2004
Brief Description: Mac OS X ppp daemon format string attack
Risk Factor: Medium
Attack Type: Host Based
Platforms: Mac OS X 10.2.8 and earlier, Mac OS X 10.3.2 and
                    earlier, Mac OS X Server 10.2.8 and earlier, Mac OS
                    X Server 10.3.2 and earlier
Vulnerability: macos-pppd-format-string
X-Force URL: http://xforce.iss.net/xforce/xfdb/15297

Date Reported: 02/23/2004
Brief Description: Jigsaw code embedded in URL allows code execution
Risk Factor: High
Attack Type: Network Based
Platforms: Jigsaw prior to 2.2.4, Linux Any version, Unix Any
                    version, Windows Any version
Vulnerability: jigsaw-url-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/15298

Date Reported: 02/23/2004
Brief Description: Mac OS X unknown issue in CoreFoundation
                    notification logging
Risk Factor: Medium
Attack Type: Host Based / Network Based
Platforms: Mac OS X 10.2.8 and earlier, Mac OS X 10.3.2 and
                    earlier, Mac OS X Server 10.2.8 and earlier, Mac OS
                    X Server 10.3.2 and earlier
Vulnerability: macos-corefoundation-unknown
X-Force URL: http://xforce.iss.net/xforce/xfdb/15299

Date Reported: 02/23/2004
Brief Description: Mac OS X unknown issue in DiskArbitration
                    implementation
Risk Factor: Medium
Attack Type: Host Based / Network Based
Platforms: Mac OS X 10.2.8 and earlier, Mac OS X 10.3.2 and
                    earlier, Mac OS X Server 10.2.8 and earlier, Mac OS
                    X Server 10.3.2 and earlier
Vulnerability: macos-diskarbitration-unknown
X-Force URL: http://xforce.iss.net/xforce/xfdb/15300

Date Reported: 02/24/2004
Brief Description: Libxml2 nanohttp buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Any operating system Any version, Libxml2 prior to
                    2.6.6, Red Hat Advanced Workstation 2.1, Red Hat
                    Enterprise Linux 2.1AS, Red Hat Enterprise Linux
                    2.1ES, Red Hat Enterprise Linux 2.1WS, Red Hat
                    Enterprise Linux 3AS, Red Hat Enterprise Linux 3ES,
                    Red Hat Enterprise Linux 3WS, Red Hat Linux 9
Vulnerability: libxml2-nanohttp-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15301

Date Reported: 02/24/2004
Brief Description: Libxml2 nanoftp buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Any operating system Any version, Libxml2 prior to
                    2.6.6, Red Hat Advanced Workstation 2.1, Red Hat
                    Enterprise Linux 2.1AS, Red Hat Enterprise Linux
                    2.1ES, Red Hat Enterprise Linux 2.1WS, Red Hat
                    Enterprise Linux 3AS, Red Hat Enterprise Linux 3ES,
                    Red Hat Enterprise Linux 3WS, Red Hat Linux 9
Vulnerability: libxml2-nanoftp-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15302

Date Reported: 02/24/2004
Brief Description: Trillian DirectIM packet buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Trillian 0.71 through 0.74, Trillian Pro 1.0,
                    Trillian Pro 2.0, Trillian Pro 2.01, Windows Any
                    version
Vulnerability: trillian-directim-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15303

Date Reported: 02/24/2004
Brief Description: Trillian key name buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Trillian 0.71 through 0.74, Trillian Pro 1.0,
                    Trillian Pro 2.0, Trillian Pro 2.01, Windows Any
                    version
Vulnerability: trillian-key-name-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15304

Date Reported: 02/24/2004
Brief Description: Red Storm games denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Desert Siege Any version, Ghost Recon 1.4 and
                    earlier, The Sum of all Fears 1.1.1.0 and earlier,
                    Windows Any version
Vulnerability: redstorm-games-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15305

Date Reported: 02/23/2004
Brief Description: TYPSoft FTP Server FTP commands denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: TYPSoft FTP Server 1.10, Windows Any version
Vulnerability: typsoft-ftp-command-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15306

Date Reported: 02/25/2004
Brief Description: Bochs long HOME variable buffer overflow
Risk Factor: High
Attack Type: Host Based
Platforms: Any operating system Any version, Bochs prior to
                    2.1.1
Vulnerability: bochs-home-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15309

Date Reported: 02/18/2004
Brief Description: AOL Instant Messenger stores buddy icon in
                    predictable location
Risk Factor: Medium
Attack Type: Network Based
Platforms: AOL Instant Messenger 4.3 through 5.5, Windows Any
                    version
Vulnerability: aim-buddy-predictable-location
X-Force URL: http://xforce.iss.net/xforce/xfdb/15310

Date Reported: 02/25/2004
Brief Description: BadBlue phptest.php script discloses path
                    information
Risk Factor: Medium
Attack Type: Network Based
Platforms: BadBlue Personal Edition 2.4, Windows Any version
Vulnerability: badblue-phptestphp-path-disclosure
X-Force URL: http://xforce.iss.net/xforce/xfdb/15311

Date Reported: 02/24/2004
Brief Description: Gigabyte Technology GN-B46B router allows
                    authentication to be bypassed
Risk Factor: High
Attack Type: Host Based
Platforms: GN-B46B firmware 1.003.00, Windows Any version
Vulnerability: gigabyte-gnb46b-bypass-authentication
X-Force URL: http://xforce.iss.net/xforce/xfdb/15313

Date Reported: 02/25/2004
Brief Description: 1st Class Mail Server APOP USER command denial of
                    service
Risk Factor: Low
Attack Type: Network Based
Platforms: 1st Class Mail Server 4.0, Windows Any version
Vulnerability: 1st-class-apop-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15314

Date Reported: 02/18/2004
Brief Description: Microsoft Internet Explorer .chm file could allow
                    code execution
Risk Factor: High
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.0, Microsoft Internet
                    Explorer 6.0, Windows Any version
Vulnerability: ie-chm-code-execution
X-Force URL: http://xforce.iss.net/xforce/xfdb/15316

Date Reported: 02/25/2004
Brief Description: mtools mformat utility creates files with insecure
                    permissions
Risk Factor: Medium
Attack Type: Host Based
Platforms: Mandrake Linux 9.2, mtools prior to 3.9.9
Vulnerability: mtools-mformat-insecure-permissions
X-Force URL: http://xforce.iss.net/xforce/xfdb/15317

Date Reported: 02/19/2004
Brief Description: Alcatel OmniSwitch Nessus scan can create denial of
                    service
Risk Factor: Low
Attack Type: Network Based
Platforms: Alcatel OmniSwitch 7700, Alcatel OmniSwitch 7800
Vulnerability: alcatel-omniswitch-nessus-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15318

Date Reported: 02/25/2004
Brief Description: Jabber Gadu-Gadu Transport denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: BSD Any version, Jabber Gadu-Gadu Transport 1.2.2,
                    Linux Any version
Vulnerability: jabber-gadugadu-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15319

Date Reported: 02/25/2004
Brief Description: Mail multiple connections denial of service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Mail WebMail System 3.64, Windows 2000 Advanced
                    Server, Windows 2000 Any version, Windows NT Any
                    version, Windows XP Any version
Vulnerability: atmail-connection-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15320

Date Reported: 02/26/2004
Brief Description: FreeChat string denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: FreeChat 1.1.1a, Windows Any version
Vulnerability: freechat-string-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15321

Date Reported: 02/25/2004
Brief Description: Mozilla event handler cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Any operating system Any version, Mozilla prior to
                    1.6b
Vulnerability: mozilla-event-handler-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15322

Date Reported: 02/26/2004
Brief Description: Serv-U MDTM buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Serv-U FTP Server prior to 5.0.0.4, Windows Any
                    version
Vulnerability: servu-mdtm-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15323

Date Reported: 02/25/2004
Brief Description: Mail util.pl cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Mail WebMail System 3.64, Windows 2000 Advanced
                    Server, Windows 2000 Any version, Windows NT 4.0,
                    Windows XP Any version
Vulnerability: atmail-util-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15324

Date Reported: 02/26/2004
Brief Description: Dell OpenManage Web Server OCSGetOEMINIPathFile
                    function buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Dell OpenManage Web Server 3.7.0, Red Hat Linux
                    7.x, Windows 2000 Any version, Windows NT 4.0
Vulnerability: dell-openmanage-ocsgetoeminpathfile-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15325

Date Reported: 02/26/2004
Brief Description: Microsoft Internet Explorer Perfect Nav plugin
                    denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Microsoft Internet Explorer Any version, Windows
                    Any version
Vulnerability: ie-perfect-nav-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15326

Date Reported: 02/26/2004
Brief Description: Solaris passwd(1) allows elevated privileges
Risk Factor: High
Attack Type: Host Based
Platforms: Solaris 8 SPARC, Solaris 8 x86, Solaris 9 SPARC,
                    Solaris 9 x86
Vulnerability: solaris-passwd-gain-privileges
X-Force URL: http://xforce.iss.net/xforce/xfdb/15327

Date Reported: 02/26/2004
Brief Description: Solaris NIS account denial of service
Risk Factor: Low
Attack Type: Host Based
Platforms: Solaris 8, Solaris 9
Vulnerability: solaris-nis-account-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/15328

Date Reported: 02/26/2004
Brief Description: eXtremail all digit password allows unauthorized
                    access
Risk Factor: High
Attack Type: Network Based
Platforms: eXtremail 1.5.9, Linux Any version
Vulnerability: extremail-password-gain-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/15329

Date Reported: 02/26/2004
Brief Description: Symantec Gateway Security error page cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Symantec Gateway Security 2.0, Windows Any version
Vulnerability: symantecgateway-error-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/15330

Date Reported: 02/26/2004
Brief Description: Sun Solaris /usr/lib/print/conv_fix allows elevated
                    privileges
Risk Factor: High
Attack Type: Host Based
Platforms: Solaris 7, Solaris 8, Solaris 9
Vulnerability: solaris-covfix-gain-privileges
X-Force URL: http://xforce.iss.net/xforce/xfdb/15331

Date Reported: 02/27/2004
Brief Description: Calife long password buffer overflow
Risk Factor: High
Attack Type: Host Based
Platforms: Calife 2.8.4, Calife 2.8.5, Linux Any version
Vulnerability: calife-long-password-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15335

Date Reported: 02/27/2004
Brief Description: WinZip MIME buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Windows Any version, WinZip 8.1
Vulnerability: winzip-mime-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/15336

Date Reported: 02/27/2004
Brief Description: Microsoft Internet Explorer cross-frame domain
                    restrictions bypass
Risk Factor: Medium
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.0, Microsoft Internet
                    Explorer 6.0, Windows 2000 Professional, Windows XP
                    Professional
Vulnerability: ie-frame-domain-bypass
X-Force URL: http://xforce.iss.net/xforce/xfdb/15337

Date Reported: 02/27/2004
Brief Description: Mac OS X AFP man-in-the-middle attack
Risk Factor: Medium
Attack Type: Network Based
Platforms: Mac OS X Any version, Mac OS X Server Any version
Vulnerability: macos-afp-mitm
X-Force URL: http://xforce.iss.net/xforce/xfdb/15338

Date Reported: 02/27/2004
Brief Description: Mac OS X SSH failure
Risk Factor: Medium
Attack Type: Network Based
Platforms: Mac OS X 10.3 through 10.3.1
Vulnerability: macos-ssh-failure
X-Force URL: http://xforce.iss.net/xforce/xfdb/15339

_____

Risk Factor Key:

     High Security issues that allow immediate remote, or local access
              or immediate execution of code or commands, with unauthorized
              privileges. Examples are most buffer overflows, backdoors,
              default or no password, and bypassing security on firewalls
              or other network components.
     Medium Security issues that have the potential of granting access or
              allowing code execution by means of complex or lengthy exploit
              procedures, or low risk issues applied to major Internet
              components. Examples are cross-site scripting, man-in-the-middle
              attacks, SQL injection, denial of service of major applications,
              and denial of service resulting in system information disclosure
              (such as core files).
     Low Security issues that deny service or provide non-system
              information that could be used to formulate structured attacks
              on a target, but not directly gain unauthorized access. Examples
              are brute force attacks, non-system information disclosure
              (configurations, paths, etc.), and denial of service attacks.

______

About Internet Security Systems (ISS)
Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
pioneer and world leader in software and services that protect critical
online resources from an ever-changing spectrum of threats and misuse.
Internet Security Systems is headquartered in Atlanta, GA, with
additional operations throughout the Americas, Asia, Australia, Europe
and the Middle East.

Copyright (c) 2004 Internet Security Systems, Inc. All rights reserved
worldwide.

Permission is hereby granted for the electronic redistribution of this
document. It is not to be edited or altered in any way without the
express written consent of the Internet Security Systems X-Force. If you
wish to reprint the whole or any part of this document in any other
medium excluding electronic media, please email xforceiss.net for
permission.

Disclaimer: The information within this paper may change without notice. Internet
Security Systems provides this information on an AS IS basis with NO warranties,
implied or otherwise. Any use of this information is at the user's risk. In no event
shall Internet Security Systems be held liable for any damages whatsoever arising
out of or in connection with the use or dissemination of this information.

X-Force PGP Key available on MIT's PGP key server and PGP.com's key server,
as well as at http://xforce.iss.net/xforce/sensitive.php

Please send suggestions, updates, and comments to: X-Force
xforceiss.net of Internet Security Systems, Inc.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBQEODszRfJiV99eG9AQFdowP+J5+rWiZRyru92hYb6Eu1w9TF/Wp2FWLx
5PC2V/RmdLR4QZrz3GSAEOmUOQV1uDUOWlsJ+nJZ8sco10h5J+pmPz1+tl0GRYap
DSFIOu4071Hr2UT0Nw+Dvkhg+x+vz6j7dS+uBq10QoCY92x1X1ZZHBWztyWkl3vg
GstSS9DOMkY=
=nBtz
-----END PGP SIGNATURE-----