Provided and/or discovered by: 1) Paul Byrne, NGSSoftware.
2) Reported by an anonymous person via ZDI.
3) The vendor credits Roee Hay, IBM Rational Application Security Research Group.
4) Reported by an anonymous person via ZDI.
5) Reported by an anonymous person via iDefense VCP.
6) Reported by an anonymous person via ZDI.
7) Reported by an anonymous person and Subreption via ZDI.
8) The vendor credits David Wharton.
Changelog: 2008-09-16: Added link to NGSSoftware and updated "Description" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.