SecurityFocus Newsletter #146
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #146
-----------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Securing Microsoft Services
2. The Viral Mind: Understanding the Motives of Malicious Coders
3. No Stone Unturned, Part Four
4. Black Hat Briefings
5. Security Hole Strip Tease
II. BUGTRAQ SUMMARY
1. bzip2 Decompression File Overwrite Vulnerability
2. bzip2 Insecure Decompressed File Permissions Vulnerability
3. bzip2 Archive Inherited Symbolic Link Permissions Vulnerability
4. FreeBSD k5su Wheel Group Membership Validation Vulnerability
5. Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
6. BannerWheel Remote Buffer Overflow Vulnerability
7. Nullsoft Winamp Plaintext Authentication Credentials...
8. Deerfield WebSite Pro 8.3 Filename Source Disclosure...
9. Sun AnswerBook2 Gettransbitmap Buffer Overflow Vulnerability
10. Stronghold Secure Server Path Information Disclosure...
11. Cisco IOS ICMP Redirect Denial Of Service Vulnerability
12. Eric S. Raymond Fetchmail Message Count IMAP Buffer Overflow...
13. Cisco Catalyst Unicast Traffic Broadcast Vulnerability
14. YoungZSoft CMailServer Buffer Overflow Vulnerability
15. Sun Solaris In.Rarpd Multiple Vulnerabilities
16. Matu FTP Server Buffer Overflow Vulnerability
17. Microsoft MSDE/SQL Server 2000 Desktop Engine Default...
18. Cisco VoIP Phone Web Interface System Memory Contents...
19. Cisco VoIP Phone Stream Request Denial Of Service Vulnerability
20. Cisco VoIP Phone Default Administrative Password Vulnerability
21. NewAtlanta ServletExec/ISAPI Path Disclosure Vulnerability
22. NewAtlanta ServletExec/ISAPI File Disclosure Vulnerability
23. NewAtlanta ServletExec/ISAPI JSPServlet Denial Of Service...
24. Compaq ProLiant BL e-Class Enclosure Unauthorized Integrated...
25. OpenBSD sshd BSD Authentication Implementation Error...
26. Microsoft Active Directory Zero Page Length Query Vulnerability
27. Ethereal DNS Dissector Infinite Loop Denial of Service...
28. Ethereal Server Message Block Dissector Malformed Packet...
29. Ethereal GIOP Dissector Memory Exhaustion Vulnerability
30. SSH Communications Secure Shell Server AllowedAuthentications...
31. Cisco CBOS Oversized Packet DHCP Denial Of Service Vulnerability
32. Cisco Broadband Operating System TCP/IP Stack Denial of...
33. Cisco CBOS Telnet Denial of Service Vulnerability
34. Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
35. IBM DB2 db2ckpw Buffer Overflow Vulnerability
36. ViewCVS Cross-Site Scripting Vulnerability
37. LocalWEB2000 File Disclosure Vulnerability
38. Microsoft Excel 2002 XML Stylesheet Arbitrary Code Execution...
39. Sendmail File Locking Denial Of Service Vulnerability
40. OpenBB Cross-Site Scripting Vulnerability
41. OpenBB BBCode Cross Agent HTML Injection Vulnerability
42. OpenBB Unauthorized Moderator Access Vulnerability
43. GNU Mailman Admin Login Cross-Site Scripting Vulnerability
44. GNU Mailman Pipermail Index Summary HTML Injection Vulnerability
46. MIT PGP Public Key Server Search String Remote Buffer Overflow...
III. SECURITYFOCUS NEWS ARTICLES
1. Qwest Glitch Exposes Customer Data
2. Biometric sensors beaten senseless in tests
3. Navy Domain Hijacked By German Pornography Site
4. Microsoft's Privacy Czar on the 'Trust Model'
IV.SECURITYFOCUS TOP 6 TOOLS
1. IPWatch 1.1
2. Sophie v1.35
3. XORCrypt v2.0
4. sysklogd-sql v1.4.1
5. COMU Privacy Guard 1.0
6. Easy Firewall Generator 1.05
V. SECURITYJOBS LIST SUMMARY
1. Opening - Experienced Wireless Security Architect...
2. Looking in Denver (Thread)
3. Job Lead -- TX-Dallas-Data Security Administrator (Thread)
4. Senior Security Analyst (Thread)
5. Security Engineer (Thread)
6. NJ/NYC area consulting gig wanted (Thread)
7. Chicago-based Application Security Architect with extensive...
8. Updated posting for Chicago-based Unix Network Security...
9. Looking for position in Berkshire / Reading UK (Thread)
10. WireX Support Engineer (Thread)
11. Seeking an Information Security Position (Thread)
12. List Closure till Friday (Thread)
13. ClearTrust/Single Signon Security Engineer position in NY...
14. SR. CORRELATION ENGINEER (Austin, TX) (Thread)
15. Seattle Based InfoSec Engineer (Thread)
VI. INCIDENTS LIST SUMMARY
1. GET /proxy-test.php (Thread)
2. odd scans? (Thread)
3. Worms and CScript/WScript (Thread)
4. Strange scans (Thread)
5. strange .ch scan by 195.141.86.145 (Thread)
6. continues SCAN Proxy attempt (Thread)
7. odd scans? (Thread)
8. Decrease in 1433 Scans? (Thread)
9. Decrease in 1433 Scans? (Thread)
10. 1999-2000 oops (Thread)
11. Interesting scan to ports 1999-2000 (Thread)
12. Worms and CScript/WScript (Thread)
13. Strange scan on 1433 (Thread)
14. Strange scan on 1433 (Thread)
15. Increased connects to Port 1433 (Thread)
16. Increased connects to Port 1433 (Thread)
17. exploited win2k box, not quite sure how: (Thread)
18. FW: exploited win2k box, not quite sure how: (Thread)
19. exploited win2k box, not quite sure how: (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. On-Line Games and Privacy Issues (Thread)
2. WinNT and previously used passwords (Thread)
3. Sendmail file locking - PoC (Thread)
4. [DER ADV#8] - Local off by one in CVSD (Thread)
5. MacOS X 10.1.4 MAC Address Spoofing (Thread)
6. Verizon Call Intercept (Thread)
7. addition: CVS off by one (Thread)
8. XSS And Headers... (Thread)
9. WinNT and previously used passwords (Thread)
10. High APAR - Microsoft: Microsoft Security Bulletin MS02-024:...
11. game console hacking thread (Thread)
12. COWS continuation (Thread)
13. OT? Are chroots immune to buffer overflows? (Thread)
14. OT? Are chroots immune to buffer overflows? (Thread)
15. Online Games Consoles and Security Implications (Thread)
16. Security holes in OpenBB (Thread)
17. Online Games Consoles and Security Implications (Thread)
18. TRU64 /bin/chsh overflow (Thread)
19. boegADT (Thread)
20. Xerox DocuTech problems (Thread)
21. [NGSEC] ngGame #1 - Web Authentication (Thread)
22. GIF87a (Thread)
23. saving .asx target file (Thread)
24. TRU64 /usr/sbin/quot overflow (Thread)
25. TRU64 /usr/bin/passwd overflow (Thread)
26. Generating shellcode (Thread)
27. saving .asx target file (Thread)
28. The Cross Site Scripting FAQ (Thread)
29. Evolution of Cross-Site Scripting Attacks (Thread)
30. Generating shellcode (Thread)
31. ps under FreeBSD (Thread)
32. Radar Detectors interfere with Texaco VSAT terminals? (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Q320206 and SP4 (Thread)
2. Q320206 and SP4 (Thread)
3. No browsing group (Thread)
4. Hfnetchk scans every file (Thread)
5. No browsing group (Thread)
6. IIS 5.0 and Netscape Authentication (Thread)
7. SQL Spider question (Thread)
8. Hfnetchk scans every file (Thread)
9. hotfix overwrite; hfnetchk (Thread)
10. IIS 5.0 and Netscape Authentication (Thread)
11. SQL Spider. (Thread)
12. About ping request? (Thread)
13. MS02-18 causes Exchange problems ?? (Thread)
14. SecurityFocus Microsoft Newsletter # 87 (Thread)
15. About ping request? (Thread)
16. Hotfixes overwritten? (Thread)
IX. SUN FOCUS LIST SUMMARY
1. UseLogin and X11Forwarding (Thread)
2. UseLogin and X11Forwarding (Thread)
3. C2 security standards (Thread)
4. BSM tool (Thread)
5. ICMP_MASKREQ (Thread)
6. C2 security standards (Thread)
X. LINUX FOCUS LIST SUMMARY
1. How to get rid of spoofed IP-Address responses (Thread)
2. What Is hosts2-ns (Thread)
3. Linux Hardening (Thread)
4. How to get rid of spoofed IP-Address responses (Thread)
5. protecting DHCP servers (Thread)
6. protecting DHCP servers (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Securing Microsoft Services
By Mark Burnett
To master Windows security, administrators must master Windows services.
They must understand how services work, how they are exploited and how
services are secured. This article will give readers the how-tos of
Windows services.
http://online.securityfocus.com/infocus/1581
2. The Viral Mind: Understanding the Motives of Malicious Coders
by D. D. Shelby
Over the years I have seen many people offer opinions on why virus writers
do what they do. While I accept that many of these people have indeed
spoken to a small number of malware authors, it has become all too
apparent that much of their text has been based on opinion and not fact.
In this article, I will draw upon my own experiences as a virus writer and
as a member of the virus (and anti-virus) community to explore some of the
reasons that people would devote their time to developing viruses.
http://online.securityfocus.com/infocus/1583
3. No Stone Unturned, Part Four
By H. Carvey
This is the fourth installment of a five-part series describing the
(mis)adventures of a sysadmin named Eliot and his haphazard journey in
discovering "the Way" of incident response.
http://online.securityfocus.com/infocus/1584
4. Black Hat Briefings
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
http://www.blackhat.com
5. Security Hole Strip Tease
By Tim Mullen
By letting the public catch a tantalizing peek at unannounced security
holes, one prolific bug-finder turns up the heat on vendors to close them.
http://online.securityfocus.com/columnists/84
II. BUGTRAQ SUMMARY
-------------------
1. bzip2 Decompression File Overwrite Vulnerability
BugTraq ID: 4774
Remote: Yes
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4774
Summary:
bzip2 is an open-source file compression/decompression utility for Unix
and Linux variants.
bzip2 does not decompress files securely. When a file is decompressed,
the program does not sufficiently check to see if the file already exists,
potentially allowing files to be overwritten without warning during the
decompression.
The source of this problem is that the O_EXCL flag is not used when the
files are created during decompression. An attacker may potentially
create a malicious archive which exploits this vulnerability, causing
files owned by the user decompressing the archive to be overwritten.
2. bzip2 Insecure Decompressed File Permissions Vulnerability
BugTraq ID: 4775
Remote: No
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4775
Summary:
bzip2 is an open-source file compression/decompression utility for Unix
and Linux variants.
bzip2 is prone to a race condition which may cause files to decompress
with world-readable permissions. The race condition exists between the
creation of files that are being decompressed and the setting of
permissions, potentially causing decompression files to be created with
inappropriate permissions.
This vulnerability may potentially expose sensitive files to other local
users.
3. bzip2 Archive Inherited Symbolic Link Permissions Vulnerability
BugTraq ID: 4776
Remote: No
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4776
Summary:
bzip2 is an open-source file compression/decompression utility for Unix
and Linux variants.
bzip2 inherits the permissions of symbolic links when a file is
compressed, instead of the permissions of the actual file being
compressed. Therefore, if a symbolic link is attached to a file that is
compressed using the software, then the permissions for the symbolic link
are stored in the archive as the permissions for the file.
The source of the problem is a failure to derefence the symbolic links
when creating the archive.
This may result in decompressed files being created with insecure
permissions (such as world-readable), potentially causing sensitive
information to contained in the decompressed files to be disclosed to
local users.
4. FreeBSD k5su Wheel Group Membership Validation Vulnerability
BugTraq ID: 4777
Remote: No
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4777
Summary:
k5su is a utility for the FreeBSD operating system which is similar to su.
It allows a local user to gain superuser privileges by further
authenticating as the superuser. Authentication is performed either via
the local passwd file or Kerberos 5.
To be used, the su utility normally requires that the local user is a
member of the 'wheel' group. k5su does not sufficiently validate that the
user possesses this group membership and may be used by arbitrary local
users who know the superuser password or have an explicit entry in the
Kerberos 5 ACL for the superuser account.
This presents an insecurity as the expected behavior is that k5su may only
be executed by users with 'wheel' group membership. k5su cannot be relied
upon to restrict which accounts may gain superuser privileges.
It has also been reported that k5su does not possess a number of other
security features provided by the su utility.
It should be noted that administrators must explicitly install k5su and
this vulnerability is not present in default installations of the FreeBSD
operating system.
5. Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
BugTraq ID: 4780
Remote: Yes
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4780
Summary:
Ipswitch IMail is an e-mail server that serves clients their mail via a
web interface. It runs on Microsoft Windows operating systems.
IMail ships with a LDAP server to enable remote clients to have read
access to the IMail directory.
The IMail LDAP component is prone to a remotely exploitable buffer
overflow condition, allowing attackers to execute arbitrary
attacker-supplied instructions.
The overflow is known to occur when an overly long string is provided as a
"bind DN" during authentication. It is possible to exploit this condition
to overwrite stack variables, such as the return address, with arbitrary
instructions. In this manner, a remote attacker may leverage this
vulnerability to execute arbitrary code.
IMail normally runs in the SYSTEM context, meaning that successful
exploitation will result in a full compromise of the underlying system.
It should be noted that this condition may also be exploited to trigger a
denial of service.
6. BannerWheel Remote Buffer Overflow Vulnerability
BugTraq ID: 4782
Remote: Yes
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4782
Summary:
BannerWheel is a freely available ad banner rotation program. It runs on
most Unix and Linux variants as well as Microsoft Windows operating
systems.
A condition has been reported in BannerWheel which may lead to arbitrary
code execution or a denial of service.
Due to insufficient bounds checking of externally supplied data,
BannerWheel may be prone to a buffer overflow condition. It may be
possible for an attacker to overwrite stack variables (including the
return address) with attacker-supplied instructions.
If exploitable, this condition may allow a remote attacker to execute
arbitrary instructions with the privileges of the webserver process.
7. Nullsoft Winamp Plaintext Authentication Credentials Vulnerability
BugTraq ID: 4781
Remote: No
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4781
Summary:
Nullsoft Winamp is a media player for Microsoft Windows supporting MP3 and
other filetypes.
A problem has been discovered which may potentially cause the HTTP
authentication credentials for streaming content to be exposed.
A user's authentication credentials for streaming content will be stored
in plaintext by Winamp. The credentials are stored in the file
'winamp.ini' under the [HTTP-AUTH] and [winamp] headings.
Local attackers may exploit this situation to gain access to the
credentials for streaming content that has been accessed by that user.
This issue was reported for Nullsoft Winamp 2.80. Other versions may also
be affected.
8. Deerfield WebSite Pro 8.3 Filename Source Disclosure Vulnerability
BugTraq ID: 4783
Remote: Yes
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4783
Summary:
Deerfield WebSite Pro is a commercial webserver for Microsoft Windows
operating systems.
32bit Microsoft Windows operating systems support long filenames, but also
offer a means of backwards compatibility with the older 8.3 short
filenames required by previous versions of DOS and Windows.
Deerfield WebSite Pro is prone to a vulnerability which is the result of
how requests for files using the 8.3 short filenames are handled.
In particular, this issue occurs when the software attempts to serve files
with extensions which are at least four characters long (such as .shtml),
but are requested using the 8.3 short filenames. When the short filename
is used in the request, the software will fail to call the correct handler
for the extension. The effect is that the requested file will not be
interpreted.
An attacker may exploit this issue to disclose script source code.
9. Sun AnswerBook2 Gettransbitmap Buffer Overflow Vulnerability
BugTraq ID: 4784
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4784
Summary:
Sun AnswerBook2 is vulnerable to a buffer overflow condition.
AnswerBook2 is a documentation server provided by Sun Microsystems for
users and administrators of Sun Solaris operating systems.
The vulnerability exists in the gettransbitmap CGI. This CGI is installed
as /usr/lib/ab2/bin/ab2bin/gettransbitmap.
It has been reported that the gettransbitmap CGI does not perform proper
bounds checking on the filename argument. Therefore, it is possible for a
remote malicious attacker to craft a request that will result in code
execution on the vulnerable system.
10. Stronghold Secure Server Path Information Disclosure Vulnerability
BugTraq ID: 4785
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4785
Summary:
Redhat Stronghold Secure Web Server is a web server based on the Apache
source.
It has been reported that Stronghold Server 3.0 may disclose path
information to a remote user.
The vulnerability exists in SWISH (Simple Web Indexing System for Humans),
which is Stronghold's site indexer. SWISH is bundled with Stronghold
Server. An attacker is able to send a request that will cause SWISH to
disclose the path to the web root. In some cases, SWISH may disclose
system specific information to the attacker.
Obtaining path and system information may be used by a malicious attacker
to mount further, potentially damaging, attacks against the vulnerable
system.
11. Cisco IOS ICMP Redirect Denial Of Service Vulnerability
BugTraq ID: 4786
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4786
Summary:
IOS is the Internet Operating System, used on Cisco routers. It is
distributed and maintained by Cisco.
It has been reported that it is possible to cause a denial of service in
some Cisco routers by sending a large amount of spoofed ICMP redirect
messages.
ICMP redirect messages are normally sent to indicate inefficient routing,
a new route or a routing change. When receiving an ICMP redirect message,
Cisco routers will set aside the messages in memory to be handled later.
The affected routers do not limit how much memory such messages will
consume, making it possible to exhaust the available resources on the
device.
This problem occurs in Cisco IOS 12.x if IP routing is disabled. In Cisco
IOS 11.x, this problem occurs regardless of whether IP routing is enabled
or disabled. The overall effect of successful exploitation will vary
depending on the version of IOS and the device. Some enviroments will
continue to perform normal IP routing but will not be able to perform
other operations, while other environments will fail to route properly if
exploited.
This vulnerability has been assigned Cisco bug ID CSCdx32056.
The following products are known to be affected:
Cisco 1005 running IOS 11.0(18)
Cisco 1603 running IOS 11.3(11b)
Cisco 1603 running IOS 12.0(3)
Cisco 2503 running IOS 11.0(22a)
Cisco 2503 running IOS 11.1(24a)
12. Eric S. Raymond Fetchmail Message Count IMAP Buffer Overflow Vulnerability
BugTraq ID: 4788
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4788
Summary:
Fetchmail is a freely available, open source mail retrieval utility. It
is maintained by Eric S. Raymond.
A vulnerability in the IMAP handling code could make it possible for a
malicious server to exploit a buffer overflow. The problem is in the
index count of messages.
It may be possible for a malicious server to take advantage of a fetchmail
client. This could result in a denial of service, and potentially the
execution of arbitrary code. By default, the fetchmail client trusts the
message index count sent by the server. For the message index count
returned by the server, the fetchmail client allocates an appropriate
amount of memory.
A malicious IMAP server may return a message index count of large size.
In the event of an IMAP server doing so, the fetchmail client could
allocate an amount of memory that overwrites the process stack memory
space.
This problem is likely to result in a denial of service attack. This
vulnerability, however, also has the potential for remote exploitation,
provided an attacker has control of the IMAP server that the fetchmail
client polls.
13. Cisco Catalyst Unicast Traffic Broadcast Vulnerability
BugTraq ID: 4790
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4790
Summary:
Catalyst is a commercial-grade switch distributed by Cisco.
A problem with the switch could make it possible to view parts of
communication between hosts. The vulnerability is related to the
mechanism used to learn MAC addresses.
Under normal circumstances, a switch will learn the MAC address of a
system connected to a port once a single ARP reply has been received.
While the switch is learning the MAC address, all traffic addressed to the
host will be broadcast to all ports. It has been reported that the switch
may not learn the MAC of a connected system until several more packets
have been sent to the unknown host. If this occurs, unicast traffic
between two systems across the switch may be broadcast to all systems
connected to the switch.
This vulnerability may make it possible for attackers to gain information
about systems which communicate across the switch regularly. This could
be used in an information gathering attack. Additionally, this could lead
to the sniffing of clear text communication, which in some instances may
result in the gathering of usernames, passwords, and other sensitive
information.
14. YoungZSoft CMailServer Buffer Overflow Vulnerability
BugTraq ID: 4789
Remote: Yes
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4789
Summary:
CMailServer is an mail server program for Microsoft Windows systems. It
is maintained by YoungZSoft.
It has been reported that an exploitable buffer overrun condition exists
CMailServer. The overflow condition is due to a lack of proper bounds
checking when processing client input. The overrun will occur if an
excessively long argument to the USER command is sent to the server.
An attacker exploiting this vulnerability may overwrite stack variables
including the return address, possibly to execute arbitrary code. The
attacker may also crash the service by sending excessive amounts of data
that has not specifically been designed to cause code execution.
This issue has been reported in CMailServer 3.30. Other versions may also
be affected.
15. Sun Solaris In.Rarpd Multiple Vulnerabilities
BugTraq ID: 4791
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4791
Summary:
The implementation of rarpd for Solaris is vulnerable to buffer overflow
conditions.
in.rarpd is a Reverse Address Resolution Protocol daemon. RARP is used by
machines at boot time to discover their Internet Protocol (IP) address.
For Solaris, in.rarpd resides as the following /usr/sbin/in.rarpd.
It has been reported that there seem to be three remotely exploitable
buffer overflow conditions, two locally exploitable vulnerabilities, and
two string format vulnerabilities.
in.rarpd does not perform proper string formatting when writing entries to
syslog. Since in.rarpd must run with superuser privileges, it is possible
for a remote malicious attacker to craft a request that will result in
code execution on the vulnerable system as the superuser.
Sun Microsystems has reported that these conditions are not exploitable,
as data passed to the offending routines is not externally supplied.
Furthermore, attackers must be on the local subnet to exploit this
vulnerability as ARP packets do not have IP headers and are not routeable.
Administrators are still advised to disable or block access to the service
if it is not necessary. This record will be updated when more information
becomes available.
16. Matu FTP Server Buffer Overflow Vulnerability
BugTraq ID: 4792
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4792
Summary:
Matu FTP Server is a freely available FTP server for Microsoft Windows 95
and 98 operating systems.
It has been reported that an exploitable buffer overrun condition exists
in Matu FTP. The overflow condition is due to the handling of user input.
Reportedly, the overrun will occur if an excessively long argument is
submitted to the server.
An attacker exploiting this vulnerability may overwrite stack variables
including the return address, possibly to execute arbitrary code. The
attacker may also crash the service by sending excessive amounts of data
that has not specifically been designed to cause code execution.
This issue has been reported in Matu FTP Server 1.13. Other versions may
also be affected.
17. Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
BugTraq ID: 4797
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4797
Summary:
Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine
can be deployed with various applications as a database server. A
configuration error exists which could compromise a host running
applications based on these components.
It has been reported that the services are configured with a default
username of 'sa' and a null administrative password. Remote attackers may
exploit this flaw to gain administrative access to the database if the
default password has not been changed.
It should be noted that a worm attempting to exploit default, null,
passwords in Microsoft SQL server and derived products, including MSDE and
SQL Server 2000 Desktop Engine, is currently propagating through the
Internet.
18. Cisco VoIP Phone Web Interface System Memory Contents Information Leakage Vulnerability
BugTraq ID: 4798
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4798
Summary:
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by
Cisco Systems.
A problem with the phone systems could make it possible for remote users
to gain access to information that could allow the mapping of previously
placed calls. The problem is in the handling of some types of web
requests.
Cisco 7900 series phones include a web server built into the the product.
This web server allows any user to connect to the web interface on the
phone system, and view statistics. These statistics include information
about ethernet ports on the phone system, and is handled by the
/PortInformation script.
By placing a request to the /PortInformation script with a port ID (i.e.
http://www.example.com/PortInformation?<port> where <port> is an integer
value) of arbitrarily high value, the web server will return a dump of the
contents of phone memory. This has been reportedly reproduced by passing
port ID values of greater than 32768, and consistently reproduced with a
value of 120000.
Though the contents of memory may vary, it could be possible to analyze
the memory to extract information. This information may include the
addresses of previously called phones.
19. Cisco VoIP Phone Stream Request Denial Of Service Vulnerability
BugTraq ID: 4794
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4794
Summary:
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by
Cisco Systems.
A problem with the phone systems could make it possible for remote users
to deny service to legitimate users of the system. The problem is in the
handling of some types of web requests.
Cisco 7900 series phones include a web server built into the the product.
This web server allows any user to connect to the web interface on the
phone system, and view statistics. These statistics include information
about call streams, and is handled by the /StreamingStatistics script.
By placing a request to the /StreamingStatistics script with a stream ID
(i.e. http://www.example.com/StreamingStatistics?<stream> where <stream>
is an integer value) of arbitrarily high value, the phone will reset
itself, creating the inability to place or receive calls for a period of
up to thirty seconds. This has been reportedly reproduced by passing
stream ID values of greater than 32768, and consistently reproduced with a
value of 120000.
This problem could make it possible for a remote user to reset the phone
at any time, thus preventing the receipt of calls, or interrupting calls
already in progress.
20. Cisco VoIP Phone Default Administrative Password Vulnerability
BugTraq ID: 4799
Remote: No
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4799
Summary:
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by
Cisco Systems.
A problem with the phone systems could make it possible for a user with
physical access to the phone to change the configuration. The problem is
in the default administrative password.
By default, Cisco VoIP 7900 series phones use a default administrative
password. The firmware sets a hard coded password of
asterisk-asterisk-pound (*-*-#) that allows a user access to phone
configuration parameters in the firmware. Through the use of this
password, a user with physical access to the phone may be able to change
configuration information on the phone.
This could allow a user to perform malicious activity, such as loading
trojaned firmware, or other malicious deeds such as changing the call
manager system IP address.
21. NewAtlanta ServletExec/ISAPI Path Disclosure Vulnerability
BugTraq ID: 4793
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4793
Summary:
ServletExec/ISAPI is a plug-in Java Servlet/JSP engine for Microsoft IIS.
It runs with IIS on Microsoft Windows NT/2000/XP systems.
ServletExec/ISAPI discloses the absolute path to the webroot directory
when sent a specially formatted request without a trailing filename.
Specifically, if the class 'com.newatlanta.servletexec.JSP10Servlet' is
invoked without the trailing filename, then an error page will be
displayed with the path to wwwroot.
This type of sensitive information may aid in further attacks against the
vulnerable host.
22. NewAtlanta ServletExec/ISAPI File Disclosure Vulnerability
BugTraq ID: 4795
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4795
Summary:
ServletExec/ISAPI is a plug-in Java Servlet/JSP engine for Microsoft IIS.
It runs with IIS on Microsoft Windows NT/2000/XP systems.
ServletExec/ISAPI will disclose the contents of arbitrary files within the
webroot directory.
For this to occur, the 'com.newatlanta.servletexec.JSP10Servlet' class
must be invoked followed by URL encoded directory traversal sequences and
the name of the file to be disclosed. While this will cause the software
to serve files within wwwroot that normally would not be served, it does
not appear possible to exploit this condition to break out of the webroot.
This condition is due to lack of sufficient validation of external data
supplied to the JSPServlet. This may result in the disclosure of sensitive
information.
23. NewAtlanta ServletExec/ISAPI JSPServlet Denial Of Service Vulnerability
BugTraq ID: 4796
Remote: Yes
Date Published: May 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4796
Summary:
ServletExec/ISAPI is a plug-in Java Servlet/JSP engine for Microsoft IIS.
It runs with IIS on Microsoft Windows NT/2000/XP systems.
The JSPServlet encounters difficulties when handling overly long requests.
If the JSPServlet is sent an overly long request directly or is invoked
via a long request for a JSP file, a denial of service condition will
occur.
It has been reported that this will cause the underlying webserver to
crash.
This condition may be the result of insufficient bounds checking, which
may allow an attacker to execute arbitrary code. This possibility has not
been confirmed.
24. Compaq ProLiant BL e-Class Enclosure Unauthorized Integrated Administrator Access Vulnerability
BugTraq ID: 4802
Remote: No
Date Published: May 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4802
Summary:
The Compaq ProLiant BL e-Class enclosure utilizes the Integrated
Administrator to provide system management.
An issue has been discovered which may enable a local user, during a CLI
(Command Line Interface) session, to gain administrative access to the
Compaq ProLiant BL e-Class enclosure via the Integrated Administrator.
This issue has only been known to be exploitable if the user has telnet,
SSH or console access to the system.
It should be noted that this vulnerability does not extend to the Server
Blade.
No further technical details are currently available.
25. OpenBSD sshd BSD Authentication Implementation Error Vulnerability
BugTraq ID: 4803
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4803
Summary:
OpenBSD is a freely available, open source operating system designed with
security in mind. It is maintained and distributed by the OpenBSD project.
A possible security issue in the OpenSSH server for OpenBSD has been
reported. The vulnerability is related to the implementation of BSD
authentication.
In the sshd utility, a condition exists where the 'auth_approval()'
function may overwrite a libc password entry structure that is in use with
that of another user. This may occur when YP/NIS is in use. Exploitation
of this vulnerability may allow for users with locked accounts to
authenticate successfully.
26. Microsoft Active Directory Zero Page Length Query Vulnerability
BugTraq ID: 4804
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4804
Summary:
Microsoft Active Directory is reportedly vulnerable to a query that will
result in Active Directory to no longer respond.
The vulnerability has been reported for querying Active Directory servers
using Kerberos V authentication via GSS-API (Generic Security Standard
Application Programming Interface).
Active Directory servers, by default, return as many entries as possible
when responding to requests. A LDAP client is able to specify the number
of entries to be retrieved by setting page length to a smaller number.
The reported vulnerability occurs when the page length value is set to
zero and the client makes a large request. This will cause the vulnerable
Active Directory server to hang causing a denial of service to occur.
27. Ethereal DNS Dissector Infinite Loop Denial of Service Vulnerability
BugTraq ID: 4807
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4807
Summary:
Ethereal is a freely available, open source network traffic analysis tool.
It is maintained by the Ethereal Project and is available for most Unix
and Linux variants as well as Microsoft Windows operating systems.
The Ethereal DNS dissector is a mechanism for decoding the DNS protocol.
A condition exists where the DNS dissector routine may enter an infinite
loop while processing a request. This may be triggered by a maliciously
constructed DNS query transmitted across the network. A remote attacker
may exploit this vulnerability to prevent Ethereal from functioning.
Successful exploitation may result in data loss and evasion of detection
by Ethereal.
28. Ethereal Server Message Block Dissector Malformed Packet Denial Of Service Vulnerability
BugTraq ID: 4806
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4806
Summary:
Ethereal is a freely available, open source network traffic analysis tool.
It is maintained by the Ethereal Project and is available for most Unix
and Linux variants as well as Microsoft Windows operating systems.
The Ethereal Server Message Block (SMB) dissector is a mechanism for
decoding the Microsoft SMB protocol. A problem with this portion of
Ethereal could make it possible for a remote attacker to deny service to
an Ethereal user.
Two conditions exists that may result in attempts to dereference NULL
pointers. The conditions may be triggered by a specially constructed SMB
packet transmitted across the network by the attacker. By transmitting
such a packet while a session of Ethereal is running, Ethereal could be
made to dereference a NULL pointer, resulting in a crash of the
application.
Successful exploitation may result in Ethereal crashing due to an access
violation, resulting in a denial of service.
29. Ethereal GIOP Dissector Memory Exhaustion Vulnerability
BugTraq ID: 4808
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4808
Summary:
Ethereal is a freely available, open source network traffic analysis tool.
It is maintained by the Ethereal Project and is available for most Unix
and Linux variants as well as Microsoft Windows operating systems.
The Ethereal GIOP dissector is a mechanism for decoding the General
Inter-ORB Protocol (GIOP). A condition exists that may result in
exhaustion of available memory. A specially constructed packet may cause
allocation of a large amount of memory. Attackers may exploit this
vulnerability to cause an exhaustion of available memory.
Successful exploitation may result in Ethereal failing or crashing.
30. SSH Communications Secure Shell Server AllowedAuthentications Configuration Overriding Vulnerability
BugTraq ID: 4810
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4810
Summary:
Secure Shell is the commercial SSH implementation distributed and
maintained by SSH Communications. It is available for the Unix, Linux,
and Microsoft Windows platforms.
A problem with some SSH servers may allow remote users to authentication
using arbitrary methods. The problem is in the handling of authentication
types specified via configuration.
SSH Servers allow an administrator to specify modes of authentication via
the server configuration file. Through the "AllowedAuthentications"
parameter, an administrator may limit the means of authentication used by
remote users.
Under some circumstances, it may be possible for a remote user to bypass
the "AllowedAuthentications" specified in the server configuration. This
could allow a user to authenticate using a different or weaker means, such
as a password. In such a situation where stronger authentication
protocols are in place, and system user accounts have been secured with
weak passwords, an attacker may be able to gain access to the system using
the weak password, rather than the strong authentcation scheme.
This problem makes it possible for remote users to circumvent
authentication mechanisms and, potentially, use a weaker method of
authentication.
31. Cisco CBOS Oversized Packet DHCP Denial Of Service Vulnerability
BugTraq ID: 4813
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4813
Summary:
CBOS (Cisco Broadband Operating System) is the operating system for Cisco
600 series routers.
CBOS is prone to a denial of service when handling large packets.
It is possible to cause the CPE (Customer Premises Equipment) to freeze by
sending a large packet to the DHCP (Dynamic Host Configuration Protocol)
port. The DHCP port is enabled by default on the affected devices.
The following devices in the Cisco 600 series of routers are affected:
605, 626, 627, 633, 673, 675, 675e, 676, 677, 677i and 678.
This vulnerability has been assigned Cisco Bug ID CSCdw90020.
32. Cisco Broadband Operating System TCP/IP Stack Denial of Service Vulnerability
BugTraq ID: 4815
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4815
Summary:
Cisco Broadband Operating System (CBOS) is the operating system used on
Cisco 600 series routers.
The CBOS TCP/IP stack is vulnerable to a denial of service condition
resulting from exhaustion of all available memory. When the stack is
forced to process a high number of unusually large packets, it will
eventually consume all available memory. When this occurs, the router
will freeze and stop forwarding any packets.
The following devices in the Cisco 600 series of routers are affected:
605, 626, 627, 633, 673, 675, 675e, 676, 677, 677i and 678.
This vulnerability has been assigned Cisco Bug ID CSCdx36121.
33. Cisco CBOS Telnet Denial of Service Vulnerability
BugTraq ID: 4814
Remote: Yes
Date Published: May 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4814
Summary:
CBOS (Cisco Broadband Operating System) is the operating system for Cisco
600 series routers.
A denial of service vulnerability exists in CBOS software 2.4.4 and prior.
The vulnerability results when an unusually large packet is sent to the
telnet port of a CPE. Remote users could exploit this issue to deny
service to legitimate users of the device.
It should be noted that telnet is enabled by default.
The following devices in the Cisco 600 series of routers are affected by
this issue:
605, 626, 627, 633, 673, 675, 675e, 676, 677, 677i and 678.
This vulnerability has been assigned Cisco Bug ID CSCdv50135.
34. Debian GNU/Linux netstd Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 4816
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4816
Summary:
The netstd package, included with the Debian GNU/Linux distribution is a
collection of networking utilities and daemons. Reportedly, version
3.07-17 of netstd included with Debian is vulnerable to a buffer overflow
attack. The vulnerability affects multiple utilities included with
netstd. The affected utilities are:
- linux-ftpd
- pcnfsd
- tftp
- traceroute
- from/to
The condition occurs when an FQDN (Fully Qualified Domain Name) response,
generated by the target DNS (Domain Name System) server is copied into a
small buffer without any checks. It may be possible for a malicious
attacker to overflow the buffer and execute code as the owner of the
vulnerable processes.
35. IBM DB2 db2ckpw Buffer Overflow Vulnerability
BugTraq ID: 4817
Remote: No
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4817
Summary:
IBM DB2 includes the utility 'db2ckpw' as part of it's authentication
system. By default, db2ckpw is installed setuid root.
An exploitable buffer overflow vulnerability exists in db2ckpw. It is
possible to trigger the condition by supplying a username value greater
than 8 characters in length.
By design, db2ckpw is meant to be invoked by other components. While
bounds checking on username and password values occurs in these components
prior to invocation of db2ckpw, none exists in db2ckpw itself.
An unsafe string copy operation in db2ckpw may thus be exploited by local
users if db2ckpw is run directly. Local users may supply a username value
that overwrites the return address of the affected function with a pointer
to shellcode. When the function returns, the attacker-supplied shellcode
will run with effective root privileges.
Successful exploitation of this vulnerability may result in complete
compromise of the host.
36. ViewCVS Cross-Site Scripting Vulnerability
BugTraq ID: 4818
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4818
Summary:
ViewCVS is an open-source web interface for CVS. It is available for most
Unix and Linux variants as well as Microsoft Windows operating systems.
ViewCVS does not filter HTML tags from certain URL parameters, making it
prone to cross-site scripting attacks.
An attacker may exploit this by constructing a malicious link with script
code to a site running ViewCVS and sending it to a legitimate user of the
site. When the legitimate user follows the link, the attacker's script
code is executed in their web client in the security context of the
website running ViewCVS.
The attacker may be able to steal cookie-based authentication credentials
or hijack web content as a result of this vulnerability.
37. LocalWEB2000 File Disclosure Vulnerability
BugTraq ID: 4820
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4820
Summary:
LocalWEB2000 is a web server for Microsoft Windows operating systems.
A vulnerability exists in LocalWEB2000 related to content password
protection. It is possible to have LocalWEB2000 treat files as
unprotected by requesting them as files within the '.' (current)
directory. If the file http://server/file.txt is set to be password
protected, the protection will be bypassed if a request is made for
http://server/./file.txt. This is likely due to a design error in the
protection component.
This vulnerability was reported for LocalWEB2000 Standard Version 2.1.0.
Other versions (such as the Professional Edition) may also be affected by
this issue.
38. Microsoft Excel 2002 XML Stylesheet Arbitrary Code Execution Vulnerability
BugTraq ID: 4821
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4821
Summary:
A vulnerability exists in the handling of XML stylesheets in Microsoft
Excel documents. This vulnerability may result in script contained in an
XML stylesheet to execute on a user's system.
With Microsoft Excel 2002, it is possible to include XML stylesheets with
XML documents. When such a document is loaded, the user is given the
choice to load the associated stylesheet or not. If the XML stylesheet
contains script (ie.Javascript & VBscript modules), and the user chooses
to apply the stylesheet when viewing the .xls file, the script will run.
There is no indication to the user that embedded script will execute. By
default, the XML stylesheet is not loaded.
Successful exploitation of this vulnerability could lead to the execution
or malicious code on a user's system.
39. Sendmail File Locking Denial Of Service Vulnerability
BugTraq ID: 4822
Remote: No
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4822
Summary:
Sendmail is a MTA (Mail Transport Agent) for Unix and Linux variants.
There is a vulnerability in Sendmail that will lead to a denial of service
condition. The vulnerability occurs when a malicious user acquires an
exclusive lock on files that Sendmail requires for operation.
Sendmail uses file locking for a variety of files including aliases, maps,
statistics, and the pid file. If a user has access to these files, the
user may be able to obtain exclusive locks on these files. If Sendmail,
or its associated programs, is unable to obtain access to any critical
files, it will cease to function properly.
A malicious user may exploit this vulnerability to cause Sendmail to stop
functioning.
40. OpenBB Cross-Site Scripting Vulnerability
BugTraq ID: 4824
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4824
Summary:
OpenBB is web forum software written in PHP. It will run on most Linux and
Unix variants, in addition to Microsoft Windows operating systems.
It has been reported that OpenBB is vulnerable to a cross-site scripting
attack.
The vulnerability is present in the 'myhome.php' script. OpenBB does not
properly santize client-supplied value of certain parameters prior to
output. Attackers are able to circumvent existing measures to protect
against cross- site scripting attacks with the use of '<form>' tags
followed by arbitrary HTML.
Attackers may exploit this vulnerability by constructing a link to one of
these scripts containing malicious script code. If the link is sent to an
OpenBB user and clicked on, the attacker-supplied script code will run in
the context of the user's OpenBB session. The script code may obtain
cookie values or perform unauthorized actions as the victim user.
41. OpenBB BBCode Cross Agent HTML Injection Vulnerability
BugTraq ID: 4819
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4819
Summary:
OpenBB is web forum software written in PHP. It will run on most Linux and
Unix variants, in addition to Microsoft Windows operating systems.
This vulnerability is similar to the issue discussed in BugTraq ID 4171.
The vulnerability discussed in BugTraq ID 4171 was fixed in OpenBB 1.0.0
RC3, however this issue bypasses the fix provided in 1.0.0 RC3.
OpenBB version 1.0.0 RC3 is reportedly vulnerable to HTML injection
attacks. The vulnerability occurs in the file lib/codeparse.php which
replaces HTML code with BBCodes.
OpenBB uses 'BBCodes' in the place of HTML code to include images, links
etc. This is meant for HTML functionality without being suceptible to
malicious users. However, HTML tags are not adequately replaced with
BBCodes. It is possible to inject arbitrary HTML code into forum messages.
As a result, OpenBB is prone to cross-agent scripting attacks. Script code
will be executed in the browser of the user viewing the forum message and
may allow an attacker to steal cookie-based authentication credentials.
42. OpenBB Unauthorized Moderator Access Vulnerability
BugTraq ID: 4823
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4823
Summary:
OpenBB is web forum software written in PHP. It will run on most Linux and
Unix variants, in addition to Microsoft Windows operating systems.
OpenBB is reported to be vulnerable to a condition that will allow an
unauthorized user to gain moderator or administrative access to forums.
The attacker can only change a few options as follows:
- Open or close a forum
- To toggle sticky mode status of a forum
- To toggle significant mode status of a forum
This will allow an attacker to effectively cause significant, if not all,
parts of the forum to be closed.
43. GNU Mailman Admin Login Cross-Site Scripting Vulnerability
BugTraq ID: 4825
Remote: Yes
Date Published: May 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4825
Summary:
GNU Mailman is a freely available, open-source mailing list manager
written in Python and C. It runs on Linux and other Unix-based systems.
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker
may construct a malicious link to the administrative login page, which
contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in
their web browser in the context of the site running the vulnerable
software.
The attacker may potentially exploit this condition to steal cookie-based
authentication credentials.
44. GNU Mailman Pipermail Index Summary HTML Injection Vulnerability
BugTraq ID: 4826
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4826
Summary:
GNU Mailman is a freely available, open-source mailing list manager
written in Python and C. It runs on Linux and other Unix-based systems.
Pipermail is bundled into GNU Mailman and is used as the mailing list
archiver.
HTML tags are not properly filtered from the HTML list archive index.
This may enable a remote attacker to inject arbitrary HTML, including
script code, into the HTML list archive index.
When a web user views the list index archive containing attacker-supplied
script code, the script code will be executed in their web client in the
security context of the website running GNU Mailman.
This issue exists in the Pipermail component of GNU Mailman.
45. Microsoft MSN Messenger Malformed Invite Request Denial of Service
BugTraq ID: 4827
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4827
Summary:
MSN Messenger is an instant messenging client for Microsoft Windows
systems, based on the Passport system.
A vulnerability has been reported in some versions of MSN Messenger. Under
some circumstances, it may be possible to crash a target client when it
receives a malformed invite request. By including a number of
HTML-encoded space characters (%20) in the Invitation-Cookie field, and
sending the header to a remote user, it is reportedly possible to crash a
remote user's client.
Exploitation of this vulnerability may result in a denial of MSN service.
The possibility of other consequences, such as code execution, has not yet
been ruled out. This record will be updated as more information becomes
available.
46. MIT PGP Public Key Server Search String Remote Buffer Overflow Vulnerability
BugTraq ID: 4828
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4828
Summary:
The PGP Public Key Server is a freely available, open source software
package distributed by MIT. It is designed for use on Linux and Unix
operating systems.
A problem with the software package may allow remote code execution. The
problem is in the handling of long search strings.
The PGP Public Key Server does not properly handle long search strings.
Under some conditions, it may be possible to pass a long string to the
server that could result in a buffer overflow. This may result in the
overwriting of stack variables, including the return address.
Upon passing a search string of 512 or more characters, the server
crashes. Minimally, this could result in a denial of service to users of
the key server. In the event that this could be exploited to execute
code, a remote user would be able to execute code with the privileges of
the PGP Public Key Server process.
It is noteworthy that exploit strings must be able to pass through an
isalnum() function, as well as a tolower() function, limiting the
characters that may be used in an exploit string.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Qwest Glitch Exposes Customer Data
By Kevin Poulsen
Long-distance phone bills and subscriber credit card numbers were wide
open when the company's Web-based billing payment system stopped verifying
passwords.
http://online.securityfocus.com/news/431
2. Biometric sensors beaten senseless in tests
By John Leyden, The Register
Have biometric systems developed to the point where theycould be a viable
alternative to passwords and PINs?
http://online.securityfocus.com/news/435
3. Navy Domain Hijacked By German Pornography Site
By Brian McWilliams, Newsbytes
Due to a domain registration snafu, two Internet addresses used by the
U.S. Navy for recruiting new sailors have recently been commandeered by
other sites, including a pornography site.
http://online.securityfocus.com/news/434
4. Microsoft's Privacy Czar on the 'Trust Model'
By Jane Black, Business Week
If you're concerned about privacy, you can't ignore Microsoft. The
Colossus of Redmond is at the center of setting standards for the way
information is used and shared online. Last year, it released a new
version of its Internet Explorer browser embedded with the Platform for
Privacy Preferences, a specification that enables the browser to
automatically understand a Web site's privacy practices (see BW Online,
12/14/01, Microsoft's Cookie Monster). Then in January, Bill Gates
announced the Trustworthy Computing Initiative, a companywide effort to
make Microsoft products more secure and privacy-friendly.
http://online.securityfocus.com/news/433
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. IPWatch 1.1
by Bruce Buhler and Wayne Larmon
Relevant URL:
http://www.scrounge.org/ipwatch/
Platforms: Linux
Summary:
IPWatch will reconfigure your machine after an IP change by reinitializing
the hostname, restarting the system logging facilities to use the new
hostname, restarting your firewall, and updating your dynamic hostname (it
supports yi.org, homepc.org, justlinux.com, dhs.org, dyndns.org, and
dyndns.com). It will also restart your network if your machine loses
connectivity. In both cases, email is sent with a full log of everything
that's been done (including your new IP address).
2. Sophie v1.35
by Vanja Hrustic
Relevant URL:
http://www.vanja.com/tools/
Platforms: FreeBSD, HP-UX, Linux, OpenBSD, POSIX
Summary:
Sophie is a daemon which uses 'libsavi' library from Sophos anti virus
vendor ( http://www.sophos.com ). On startup, Sophie initializes SAPI
(Sophos Anti-Virus Interface), loads virus patterns into memory, opens
local UNIX domain socket, and waits for someone to connect and instructs
it which path to scan. Since the database is loaded in RAM, scanning is
very fast. (Note: speed of scanning also depends on SAVI settings and size
of the file.) It works on Linux, Solaris (Sparc/x86), HP-UX, and FreeBSD.
It was made as a part of 'Virge' project, which is a mail/attachment/virus
scanning tool, written in C.
3. XORCrypt v2.0
by Ramsey G. Brenner
Relevant URL:
http://rgbrenner.cjb.net/xorcrypt.html
Platforms: POSIX, UNIX
Summary:
XORCrypt is an OTP encryption suite. It is (almost) a complete OTP
solution. It includes programs to create keys, create fake keys, encrypt,
and decrypt.
4. sysklogd-sql v1.4.1
by ronnocol
Relevant URL:
http://www.monkeymental.com/nuke/
Platforms: Linux, POSIX
Summary:
sysklogd-sql is a port of the sysklogd daemon that can log data to a MySQL
database running either on the same machine or a remote database server.
The SQL configuration is done in the standard syslog.conf file for easy
administration and configuration. Also included is a set of sample PHP
scripts to query the data from the syslog database. In a large
environment, you can set up a central logging server, or configure a
secure syslog environment that will make it very difficult to tamper with
the syslog data.
5. COMU Privacy Guard 1.0
by Faruk
Relevant URL:
http://projects.comu.edu.tr/cpg/
Platforms: Linux, POSIX
Summary:
CPG (COMU Privacy Guard) is a Web-based shell for GNU Privacy Guard. It
enables users to perform the main functions of GnuPG on the Web.
6. Easy Firewall Generator 1.05
by Scott Morizot
Relevant URL:
http://morizot.net/firewall/
Platforms: Linux, POSIX
Summary:
Easy Firewall Generator is a PHP Web application that generates an
iptables firewall script. The generated script is designed for a single
system connected to the Internet or a system acting as a gateway/firewall
for a small private network. The generator prompts recursively for a
variety of options. When the selected options form a complete set, it
generates and returns a ciommented firewall script based on those options.
The generator includes documentation on iptables and each option.
V. SECURITY JOBS SUMMARY
------------------------
1. Opening - Experienced Wireless Security Architect (Dallas, TX) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. Looking in Denver (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
3. Job Lead -- TX-Dallas-Data Security Administrator (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Senior Security Analyst (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. Security Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
6. NJ/NYC area consulting gig wanted (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
7. Chicago-based Application Security Architect with extensive API experience LOCAL candidates only PLEASE (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Updated posting for Chicago-based Unix Network Security Engineer ! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. Looking for position in Berkshire / Reading UK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/E3B1FC8B7461D4119C6D0800091857CECF1B12@ROGUE
10. WireX Support Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. Seeking an Information Security Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. List Closure till Friday (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. ClearTrust/Single Signon Security Engineer position in NY (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. SR. CORRELATION ENGINEER (Austin, TX) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
15. Seattle Based InfoSec Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
VI. INCIDENTS LIST SUMMARY
-------------------------
1. GET /proxy-test.php (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
2. odd scans? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Worms and CScript/WScript (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/3CF0CDA0.218.3EF112@localhost
4. Strange scans (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. strange .ch scan by 195.141.86.145 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/v04220807b91550147edd@[192.168.1.15]
6. continues SCAN Proxy attempt (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
7. odd scans? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. Decrease in 1433 Scans? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
9. Decrease in 1433 Scans? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
10. 1999-2000 oops (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
11. Interesting scan to ports 1999-2000 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
12. Worms and CScript/WScript (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
13. Strange scan on 1433 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
14. Strange scan on 1433 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/002001c200fa$aa3c2e90$6600a8c0@jamesdesktop
15. Increased connects to Port 1433 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
16. Increased connects to Port 1433 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
17. exploited win2k box, not quite sure how: (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
18. FW: exploited win2k box, not quite sure how: (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
19. exploited win2k box, not quite sure how: (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/8644B3FDA9EAD411931D00B0D0688638CFC86A@ISLAND-SERVER
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. On-Line Games and Privacy Issues (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
2. WinNT and previously used passwords (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000701c20508$2dd1da00$6301a8c0@visp
3. Sendmail file locking - PoC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
4. [DER ADV#8] - Local off by one in CVSD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. MacOS X 10.1.4 MAC Address Spoofing (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. Verizon Call Intercept (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/00d701c2044c$b1c616d0$47479d40@nuthatch
7. addition: CVS off by one (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
8. XSS And Headers... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
9. WinNT and previously used passwords (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/008b01c20420$bcfc4870$47479d40@nuthatch
10. High APAR - Microsoft: Microsoft Security Bulletin MS02-024: Authentication Flaw in Windows Debugger can Lead to Elevated Privileges (Q320206) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/OF862753BF.466457D7-ONC2256BC4.002B94F4-C2256BC4.002BC5BD@telaviv.ibm.com
11. game console hacking thread (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. COWS continuation (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. OT? Are chroots immune to buffer overflows? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. OT? Are chroots immune to buffer overflows? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. Online Games Consoles and Security Implications (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
16. Security holes in OpenBB (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Online Games Consoles and Security Implications (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
18. TRU64 /bin/chsh overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
19. boegADT (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
20. Xerox DocuTech problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
21. [NGSEC] ngGame #1 - Web Authentication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
22. GIF87a (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/2920A54BC742D4119F390000949A1D5D45C2AA@wwmessd136
23. saving .asx target file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
24. TRU64 /usr/sbin/quot overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
25. TRU64 /usr/bin/passwd overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
26. Generating shellcode (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
27. saving .asx target file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
28. The Cross Site Scripting FAQ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
29. Evolution of Cross-Site Scripting Attacks (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
30. Generating shellcode (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
31. ps under FreeBSD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
32. Radar Detectors interfere with Texaco VSAT terminals? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Q320206 and SP4 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
2. Q320206 and SP4 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/761DBCC144B6334A81251171C684A6FB7CEB56@mailserver-2k.fireapple.com
3. No browsing group (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. Hfnetchk scans every file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
5. No browsing group (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. IIS 5.0 and Netscape Authentication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/3D6694DB1788D311BA3E00508B5DFFE7036F935D@aklmessage01
7. SQL Spider question (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/01a101c201c3$765ca9f0$0b0aa8c0@baserem2
8. Hfnetchk scans every file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
9. hotfix overwrite; hfnetchk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
10. IIS 5.0 and Netscape Authentication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. SQL Spider. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
12. About ping request? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
13. MS02-18 causes Exchange problems ?? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
14. SecurityFocus Microsoft Newsletter # 87 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
15. About ping request? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/EDF560E8C1E4A0439EA7828DDC95AFDF66C17B@nt-cleopsapp44.ntl-city.com
16. Hotfixes overwritten? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. UseLogin and X11Forwarding (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/B6F40DC5FF58A44F8FCB30384BE3D6E4750560@emacil-exch01.emacdigital.com
2. UseLogin and X11Forwarding (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
3. C2 security standards (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/867E01F52CF2D311B0D90008C75D6561138CF825@CRMAXSVR02
4. BSM tool (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
5. ICMP_MASKREQ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
6. C2 security standards (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. How to get rid of spoofed IP-Address responses (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
2. What Is hosts2-ns (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
3. Linux Hardening (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
4. How to get rid of spoofed IP-Address responses (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
5. protecting DHCP servers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
6. protecting DHCP servers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------