SecurityFocus Linux Newsletter #247

Peter Laborge <[email protected]> Tue, 16 Aug 2005 16:54:38 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #247
----------------------------------------

New Partnership Announcement: SecurityFocus and ITinfosecure 
  
SecurityFocus and ITinfosecure have teamed up to provide its customers with the most comprehensive vendor-neutral IT security resource on the web! Users will now be able to visit SecurityFocus.com to access information on the latest IT security products through their partnership with ITinfosecure.com with their Product Search feature. Combining this tool with SecurityFocus.s comprehensive information of the latest IT security news and vulnerability information ensures SecurityFocus remains the most comprehensive and trusted source of security information on the Internet.   
  
Visit SecurityFocus today at http://www.securityfocus.com

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Jose Nazario discusses worms
       2. Packet forensics using TCP
II.  LINUX VULNERABILITY SUMMARY
       1. Wine WineLauncher.IN Local Insecure File Creation Vulnerability
       2. Linux Kernel Non-Zero Keyring Local Denial of Service Vulnerability
       3. Linux Kernel Session Keyring Allocation Local Denial of Service Vulnerability
       4. AWStats Referrer Arbitrary Command Execution Vulnerability
       5. Easy Software Products CUPS Denial of Service Vulnerability
       6. XPDF Loca Table Verification Remote Denial of Service Vulnerability
       7. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
       8. GNOME Evolution Multiple Format String Vulnerabilities
       9. Veritas Backup Exec For Windows And NetWare Arbitrary File Download Vulnerability
       10. Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
       11. PHPBB BBCode IMG Tag Script Injection Vulnerability
       12. FUDForum Tree View Access Validation Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. Certifications
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
       1. Jose Nazario discusses worms
       2. Packet forensics using TCP


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Wine WineLauncher.IN Local Insecure File Creation Vulnerability
BugTraq ID: 14496
Remote: No
Date Published: 2005-08-08
Relevant URL: http://www.securityfocus.com/bid/14496
Summary:
A local insecure file creation vulnerability affects Wine. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.

The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

This issue is reported in version 20050725; other version may also be affected.

2. Linux Kernel Non-Zero Keyring Local Denial of Service Vulnerability
BugTraq ID: 14517
Remote: No
Date Published: 2005-08-09
Relevant URL: http://www.securityfocus.com/bid/14517
Summary:
The Linux kernel is reported prone to a local denial of service vulnerability.

This issue arises if a user attempts to add a keyring that does not contain an empty payload.

A successful attack can allow a local attacker to deny service to legitimate users due to a kernel oops.

3. Linux Kernel Session Keyring Allocation Local Denial of Service Vulnerability
BugTraq ID: 14521
Remote: No
Date Published: 2005-08-09
Relevant URL: http://www.securityfocus.com/bid/14521
Summary:
The Linux kernel is reported prone to a local denial of service vulnerability.

Specifically, the vulnerability presents itself when a user attempts to allocate a new session keyring and some exceptional conditions arise.

This can allow a local attacker to deny service to legitimate users.

4. AWStats Referrer Arbitrary Command Execution Vulnerability
BugTraq ID: 14525
Remote: Yes
Date Published: 2005-08-09
Relevant URL: http://www.securityfocus.com/bid/14525
Summary:
AWStats is affected by an arbitrary command execution vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of this vulnerability will permit an attacker to execute arbitrary Perl code on the system hosting the affected application in the security context of the Web server process.  This may aid in further attacks against the underlying system; other attacks are also possible.

It should be noted this vulnerability is only possible if the affected application has at least one URLPlugin enabled.

5. Easy Software Products CUPS Denial of Service Vulnerability
BugTraq ID: 14527
Remote: Yes
Date Published: 2005-08-09
Relevant URL: http://www.securityfocus.com/bid/14527
Summary:
CUPS is affected by a denial of service vulnerability.  This issue manifests when the application fails to do proper bounds checking when handling malformed PDF files.  

An attacker can exploit this vulnerability by supplying a malformed PDF file to the affected application resulting in an endless loop, thus denying service to legitimate users.


6. XPDF Loca Table Verification Remote Denial of Service Vulnerability
BugTraq ID: 14529
Remote: Yes
Date Published: 2005-08-09
Relevant URL: http://www.securityfocus.com/bid/14529
Summary:
XPDF is prone to a remote denial of service vulnerability.

The vulnerability presents itself when the application attempts to verify the validity of a malformed 'loca' table in PDF files.

This issue can result in disk consumption and ultimately lead to a denial of service condition.

kpdf, gpdf and CUPS are vulnerable to this issue as well.

7. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
BugTraq ID: 14531
Remote: Yes
Date Published: 2005-08-10
Relevant URL: http://www.securityfocus.com/bid/14531
Summary:
Gaim is prone to multiple vulnerabilities affecting the AIM and ICQ protocols.  These issues may allow remote attackers to trigger a buffer overflow or a denial of service condition.

All versions of Gaim 1.x are considered to be vulnerable at the moment.

8. GNOME Evolution Multiple Format String Vulnerabilities
BugTraq ID: 14532
Remote: Yes
Date Published: 2005-08-10
Relevant URL: http://www.securityfocus.com/bid/14532
Summary:
Evolution is affected by multiple format string vulnerabilities.

These issues can allow remote attackers to execute arbitrary code in the context of the client.

Evolution versions 1.5 to 2.3.6.1 are affected.

9. Veritas Backup Exec For Windows And NetWare Arbitrary File Download Vulnerability
BugTraq ID: 14551
Remote: Yes
Date Published: 2005-08-12
Relevant URL: http://www.securityfocus.com/bid/14551
Summary:
Veritas Backup Exec for Windows Servers, Veritas Backup Exec for NetWare Servers, NetBackup for NetWare Media Server Option, and Remote Agents for Windows, Unix/Linux, and NetWare servers are prone to a vulnerability regarding the unauthorized downloading of arbitrary files.  

A remote attacker can exploit this vulnerability to download arbitrary files, aiding them in further attack.

A Metasploit Framework exploit is available and there are reports of this vulnerability currently being exploited in the wild.

10. Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
BugTraq ID: 14554
Remote: No
Date Published: 2005-08-12
Relevant URL: http://www.securityfocus.com/bid/14554
Summary:
Kaspersky Anti-Virus for Unix File Servers is susceptible to two local insecure default permission vulnerabilities. These issues are due to the application failing to secure newly created directories upon installation.

The first insecure directory is used by the 'kavmonitor' binary to log actions of the anti-virus scanner. Attackers may exploit this vulnerability to delete or alter log files to obscure attack traces, or use symbolic links to cause the affected utility to overwrite arbitrary files with superuser privileges.

The second insecure directory is used to hold licensing data for the product. Attackers may delete or alter the license key files, causing the 'keepup2date' utility to fail. This utility is used by the application to keep the anti-virus signatures updated.

These vulnerabilities are reported in version 5.5-2 of Kaspersky Anti-Virus for Unix. Other versions may also be affected.

11. PHPBB BBCode IMG Tag Script Injection Vulnerability
BugTraq ID: 14555
Remote: Yes
Date Published: 2005-08-12
Relevant URL: http://www.securityfocus.com/bid/14555
Summary:
phpBB is prone to a script injection vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied input in bbcode '[IMG]' tags included in a user signature.

Successful exploitation of this vulnerability could permit the injection of arbitrary HTML or script code into the browser of an unsuspecting user in the context of the affected site. 

This issue is reported to affect phpBB version 2.0.17; earlier versions may also be vulnerable. 

12. FUDForum Tree View Access Validation Vulnerability
BugTraq ID: 14556
Remote: Yes
Date Published: 2005-08-12
Relevant URL: http://www.securityfocus.com/bid/14556
Summary:
FUDforum is prone to an access validation vulnerability.  This issue is due to a failure in the application to perform proper access validation before granting access to private forums.

An attacker can exploit this vulnerability to obtain posts from private forums.  This may result in a loss of confidentiality.  Information obtained may also be used in further attacks.

This issue is reported to affect FUDforum version 2.6.15; earlier versions may also be vulnerable.

It should be noted this issue is only possible if the 'Tree View' feature is enabled.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Certifications
http://www.securityfocus.com/archive/91/408062

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
New Partnership Announcement: SecurityFocus and ITinfosecure 
  
SecurityFocus and ITinfosecure have teamed up to provide its customers with the most comprehensive vendor-neutral IT security resource on the web! Users will now be able to visit SecurityFocus.com to access information on the latest IT security products through their partnership with ITinfosecure.com with their Product Search feature. Combining this tool with SecurityFocus.s comprehensive information of the latest IT security news and vulnerability information ensures SecurityFocus remains the most comprehensive and trusted source of security information on the Internet.   
  
Visit SecurityFocus today at http://www.securityfocus.com