SecurityFocus Linux Newsletter #243

Conrad Schilbe <[email protected]> Tue, 19 Jul 2005 18:03:29 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #243
----------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer is a free service that gives you the ability to track and manage attacks. Analyzer automatically correlates attacks from various Firewall and network based Intrusion Detection Systems, giving you a comprehensive view of your computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------
I.   FRONT AND CENTER
        1. If it isn't broken...
        2. Microsoft and Claria, together at last?
        3. Introduction to IPAudit
II.  LINUX VULNERABILITY SUMMARY
        1. Linux Kernel IA32 ExecVE Local Buffer Overflow Vulnerability
        2. DHCPCD Remote Denial of Service Vulnerability
        3. Backup Manager Insecure Temporary File Creation Vulnerability
        4. Nokia Affix BTFTP Client Filename Remote Buffer Overflow Vulnerability
        5. Nokia Affix BTSRV/BTOBEX Remote Command Execution Vulnerability
        6. Linux-HA Heartbeat Insecure Temporary File Creation Vulnerability
        7. MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
        8. MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
        9. MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability
        10. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
        11. SquirrelMail Variable Handling Vulnerability
        12. NetPanzer Remote Denial of Service Vulnerability
        13. BitDefender Antivirus & Antispam for Linux and FreeBSD Mail Servers Scan Evasion Vulnerability
        14. Easy Software Products CUPS Access Control List Bypass Vulnerability
        15. Macromedia JRun Unauthorized Session Access Vulnerability
        16. Sybase EAServer Remote Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
        1. SID HIDS 0.4.2 released
        2. Passwords on Linux systems(for all flavors)
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. If it isn't broken...
By Jason Miller
The recently introduced zlib vulnerability is both widespread and significant, but it also brings to light some of the real advantages of open source software.
http://www.securityfocus.com/columnists/341

2. Microsoft and Claria, together at last?
By Scott Granneman
Microsoft is looking to buy Claria, the nefarious spyware company that created Gator, and it's an absolute slap in the face to all Windows users concerned about security.
http://www.securityfocus.com/columnists/340

3. Introduction to IPAudit
By Paul Asadoorian
This article described the usefulness of IPAudit, a network took similar to Netflow that is used to discover botnets, compromised hosts, and other security issues on larger networks.
http://www.securityfocus.com/infocus/1842


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Linux Kernel IA32 ExecVE Local Buffer Overflow Vulnerability
BugTraq ID: 14205
Remote: No
Date Published: 2005-07-11
Relevant URL: http://www.securityfocus.com/bid/14205
Summary:
The Linux kernel is susceptible to a local buffer overflow vulnerability. This issue is due to a race condition in an ia32 emulation system call that leads to a memory copy operation that overflows a previously allocated memory buffer.

During the time between two function calls to obtain buffer sizes, there exists a window of opportunity for attackers to alter memory contents. This race condition allows local attackers to overwrite critical kernel memory, facilitating kernel-level machine code execution and privilege escalation.

On multiprocessor computers, attackers can directly alter the memory contents to exploit this race condition. On uniprocessor computers, a blocking function call allows attackers to exploit the race condition.

Versions of Linux 2.4 prior to 2.4.32-pre1, and Linux 2.4, prior to 2.6.7 are susceptible to this issue.

This vulnerability only affects computers running on either the ia64, or the amd64 hardware platforms with ia32 emulation enabled.

2. DHCPCD Remote Denial of Service Vulnerability
BugTraq ID: 14206
Remote: Yes
Date Published: 2005-07-11
Relevant URL: http://www.securityfocus.com/bid/14206
Summary:
dhcpcd is prone to a remote denial of service vulnerability.

The issue presents itself when the application handles malformed data and accesses out of bounds memory.

dhcpcd 1.3.22pl4 is reported to be affected.  It is possible that older versions are vulnerable as well.

3. Backup Manager Insecure Temporary File Creation Vulnerability
BugTraq ID: 14210
Remote: No
Date Published: 2005-07-11
Relevant URL: http://www.securityfocus.com/bid/14210
Summary:
Backup Manager is affected by an insecure temporary file creation vulnerability.

The issue arises when a user burns a CDR.  This issue may allow an attacker to create a malicious symbolic link that will be written to by the vulnerable utility when an unsuspecting user executes it.

Backup Manager versions prior to 0.5.8b are affected.

4. Nokia Affix BTFTP Client Filename Remote Buffer Overflow Vulnerability
BugTraq ID: 14230
Remote: Yes
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14230
Summary:
The Nokia Affix btftp client software is prone to a remote client-side buffer overflow vulnerability. The issue exists due to a lack of sufficient boundary checks that are performed on filename data before this data is copied into a finite memory buffer.

This issue may be exploited by an attacker that is under control of an OBEX File Transfer server, to execute arbitrary code in the context of the affected clients that connect to the malicious server, and request a directory listing.



5. Nokia Affix BTSRV/BTOBEX Remote Command Execution Vulnerability
BugTraq ID: 14232
Remote: Yes
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14232
Summary:
Nokia Affix btsrv/btobex are reported prone to a remote command execution vulnerability. The issue exists due to a lack of input sanitization that is performed before using attacker-controlled data in a 'system()' call.

Because the affected services run with superuser privileges, this issue may be exploited to fully compromise a target computer that is running the affected software.


6. Linux-HA Heartbeat Insecure Temporary File Creation Vulnerability
BugTraq ID: 14233
Remote: No
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14233
Summary:
heartbeat creates temporary files in an insecure manner.

A local attacker would most likely take advantage of this vulnerability by creating a malicious symbolic link in a directory where the temporary files will be created. When the program attempts to perform an operation on a temporary file, it will instead perform the operation on the file pointed to by the malicious symbolic link.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

7. MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
BugTraq ID: 14236
Remote: Yes
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14236
Summary:
The Kerberos 5 Key Distribution Center (KDC) implementation is affected by a remote single-byte heap overflow vulnerability.

A remote unauthenticated attacker can exploit this vulnerability by sending malformed data through a request over TCP or UDP to an affected computer.  This may result in memory corruption and lead to an overflow condition.

If arbitrary code execution occurs, the attacker may gain complete access to an entire Kerberos realm.

All MIT Kerberos 5 releases up to and including krb5-1.4.1 are vulnerable.  Third party application servers employing Kerberos 5 may be affected as well.


8. MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
BugTraq ID: 14239
Remote: Yes
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14239
Summary:
MIT Kerberos 5 is prone to a remote double-free vulnerability; the issue can be triggered by remote attackers prior to any authentication whatsoever. The issue exists in the 'revcauth_common()' helper function.

A remote attacker may trigger this issue prior to authentication. Because of the code path taken in the vulnerable function, exploitation may be hindered. However, it is conjectured that this issue may be ultimately leveraged to execute arbitrary code in the context of the affected service.

It should be noted that successful exploitation of this issue on a Kerberos Key Distribution Center (KDC) computer, may result in the compromise of an entire Kerberos realm.


9. MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability
BugTraq ID: 14240
Remote: Yes
Date Published: 2005-07-12
Relevant URL: http://www.securityfocus.com/bid/14240
Summary:
The Kerberos 5 Key Distribution Center (KDC) implementation is affected by a remote denial of service vulnerability.  This issue arises because the application attempts to free uninitialized memory at a random address when handling a remote request over TCP.

Specifically, the vulnerability arises when the application handles a principle name consisting of zero components.

All MIT Kerberos 5 releases up to and including krb5-1.4.1 are vulnerable. Third party application servers employing Kerberos 5 may be affected as well.

10. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
BugTraq ID: 14242
Remote: Yes
Date Published: 2005-07-13
Relevant URL: http://www.securityfocus.com/bid/14242
Summary:
The Mozilla Foundation has released 12 security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, and Thunderbird.

These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, bypass security checks, execute script code in the context of targeted Web sites to disclose confidential information; other attacks are also possible.

These vulnerabilities have been addressed in Firefox version 1.0.5, Mozilla Suite 1.7.9. Mozilla Thunderbird has not been fixed at this time.

The issues described here will be split into individual BIDs as further analysis is completed. This BID will then be retired.

Reportedly, Netscape is also vulnerable to the issue described in MFSA 2005-47. Due to the nature of Netscape's fork from the Mozilla codebase, it is likely that Netscape is also affected by most, or all of the issues that affect Mozilla Firefox. This has not been confirmed at this time.

11. SquirrelMail Variable Handling Vulnerability
BugTraq ID: 14254
Remote: Yes
Date Published: 2005-07-13
Relevant URL: http://www.securityfocus.com/bid/14254
Summary:
SquirrelMail is affected by an insecure variable handling vulnerability.

It was reported that an attacker can exploit this vulnerability to disclose and manipulate users' preferences, write arbitrary files in the context of 'www-data', carry out cross-site scripting and various other attacks.

Due to a lack of information, further details cannot be described at the moment.  This BID will be update when more information becomes available.

12. NetPanzer Remote Denial of Service Vulnerability
BugTraq ID: 14257
Remote: Yes
Date Published: 2005-07-13
Relevant URL: http://www.securityfocus.com/bid/14257
Summary:
netPanzer is affected by a remote denial of service vulnerability.

A successful attack can crash the server and deny service to legitimate users.

netPanzer 0.8 and prior versions are affected by this vulnerability.

13. BitDefender Antivirus & Antispam for Linux and FreeBSD Mail Servers Scan Evasion Vulnerability
BugTraq ID: 14262
Remote: Yes
Date Published: 2005-07-14
Relevant URL: http://www.securityfocus.com/bid/14262
Summary:
BitDefender Antivirus & Antispam for Linux and FreeBSD Mail Servers is susceptible to an antivirus scan evasion vulnerability.

This vulnerability allows malicious content to pass undetected, leading to a false sense of security.  A malicious attachment may be opened by a vulnerable user facilitating a malicious code infection.

BitDefender Antivirus & Antispam for Linux and FreeBSD Mail Servers versions 1.6.1 and prior are affected by this issue.

14. Easy Software Products CUPS Access Control List Bypass Vulnerability
BugTraq ID: 14265
Remote: Yes
Date Published: 2005-07-14
Relevant URL: http://www.securityfocus.com/bid/14265
Summary:
CUPS is susceptible to an ACL (Access Control List) bypass vulnerability. This issue is due to a failure of the application to properly apply ACLs to incoming print jobs.

This vulnerability allows attackers to bypass configured ACLs, allowing them to print jobs on printers, skipping any configured authentication checks or IP restrictions.

15. Macromedia JRun Unauthorized Session Access Vulnerability
BugTraq ID: 14271
Remote: Yes
Date Published: 2005-07-15
Relevant URL: http://www.securityfocus.com/bid/14271
Summary:
Macromedia JRun is affected by a vulnerability that may allow a user's session to be shared with another user.

Under certain circumstances, two users may share the same session facilitating various attacks including a compromise of the user's account.

It should be noted that this issue cannot be triggered by an attacker and occurs rarely.

JRun 4.0, ColdFusion MX 7.0 Enterprise Multi-Server Edition, and ColdFusion MX 6.1 Enterprise with JRun are affected by this vulnerability.

16. Sybase EAServer Remote Buffer Overflow Vulnerability
BugTraq ID: 14287
Remote: Yes
Date Published: 2005-07-15
Relevant URL: http://www.securityfocus.com/bid/14287
Summary:
Sybase EAServer is affected by a remote buffer overflow vulnerability.

The vulnerability exists in the server's WebConsole.  A successful attack can result in overflowing a finite sized buffer and ultimately leading to arbitrary code execution in the context of the 'jagsrv.exe' process.  This may allow the attacker to gain elevated privileges.

It should be noted that an attacker needs to provide authentication credentials prior to carrying out this attack.


III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. SID HIDS 0.4.2 released
http://www.securityfocus.com/archive/91/405592

2. Passwords on Linux systems(for all flavors)
http://www.securityfocus.com/archive/91/404696

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer is a free service that gives you the ability to track and manage attacks. Analyzer automatically correlates attacks from various Firewall and network based Intrusion Detection Systems, giving you a comprehensive view of your computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130