SecurityFocus Linux Newsletter #255
Peter Laborge <[email protected]> Tue, 11 Oct 2005 16:59:36 -0600
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #255
----------------------------------------
This Issue is Sponsored By: Qualys
Test your Network Security with QualysGuard
Testing and improving your network security has never been easier. Requiring NO software, QualysGuard will safely and accurately audit your network and provide you with the necessary fixes to proactively guard your network. Try QualysGuard Risk Free with No Obligation.
http://altfarm.mediaplex.com/ad/ck/6148-32572-6929-2
------------------------------------------------------------------
I. FRONT AND CENTER
1. Can writing software be a crime?
II. LINUX VULNERABILITY SUMMARY
1. ProZilla Buffer Overflow Vulnerability
2. GNU CFEngine Insecure Temporary File Creation Vulnerability
3. Bugzilla config.cgi Information Disclosure Vulnerability
4. Bugzilla User-Matching Information Disclosure Vulnerability
5. Weex Log_Flush() Function Remote Format String Vulnerability
6. DIA SVG File Import Remote Arbitrary Code Execution Vulnerability
7. Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
8. Gnome-PTY-Helper UTMP Hostname Spoofing Vulnerability
9. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
10. Sun ONE Directory Server Unspecified Remote Vulnerability
11. Mozilla Firefox IFRAME Handling Denail Of Service Vulnerability
12. Debian Linux Mason Init.d Firewall Loading Failure Vulnerability
13. SuSE YaST Package Repositories Insecure Permissions Vulnerability
14. SUSE Linux Multiple Local Privilege Escalation Vulnerabilities
15. MediaWiki History Database Corruption Vulnerability
16. SUSE Linux PowerSave Daemon Local Denial Of Service Vulnerability
17. HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
18. Xine-Lib Remote CDDB Information Format String Vulnerability
19. HAURI Anti-Virus ALZ Archive Handling Remote Buffer Overflow Vulnerability
20. Multiple Vendor Antivirus Products Malformed Archives Scan Evasion Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. FW: routing_based_on_port/services
2. routing_based_on_port/services
3. Group permissions changed
4. Securing Fedora Core 4
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Can writing software be a crime?
By Mark Rasch
Can writing software be a crime? A recent indictment in San Diego, California indicates that the answer to that question may be yes.
http://www.securityfocus.com/columnists/360
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. ProZilla Buffer Overflow Vulnerability
BugTraq ID: 14993
Remote: Yes
Date Published: 2005-10-01
Relevant URL: http://www.securityfocus.com/bid/14993
Summary:
ProZilla is prone to a buffer overflow vulnerability. This issue is due to the failure of the application to properly bounds check user-supplied input prior to copying it to an insufficiently sized memory buffer.
Arbitrary code execution in the context of the user running the application is possible.
2. GNU CFEngine Insecure Temporary File Creation Vulnerability
BugTraq ID: 14994
Remote: No
Date Published: 2005-10-01
Relevant URL: http://www.securityfocus.com/bid/14994
Summary:
GNU cfengine is prone to an insecure temporary file creation vulnerability. Exploitation may allow arbitrary files to be overwritten.
3. Bugzilla config.cgi Information Disclosure Vulnerability
BugTraq ID: 14995
Remote: Yes
Date Published: 2005-10-01
Relevant URL: http://www.securityfocus.com/bid/14995
Summary:
Bugzilla is prone to an information disclosure issue exposed through config.cgi. This may allow an unauthorized user to access product names that are supposed to be confidential.
Bugzilla versions 2.18rc1 to 2.18.3, 2.19 to 2.20rc2, and 2.21 are affected.
4. Bugzilla User-Matching Information Disclosure Vulnerability
BugTraq ID: 14996
Remote: Yes
Date Published: 2005-10-01
Relevant URL: http://www.securityfocus.com/bid/14996
Summary:
Bugzilla is prone to an information disclosure vulnerability when user-matching is turned on. This could allow an attacker to enumerate usernames on the system.
Bugzilla 2.19.1 to 2.20rc2 and 2.21 are prone to this vulnerability.
5. Weex Log_Flush() Function Remote Format String Vulnerability
BugTraq ID: 14999
Remote: Yes
Date Published: 2005-10-02
Relevant URL: http://www.securityfocus.com/bid/14999
Summary:
Weex is affected by a remote format string vulnerability.
The vulnerability presents itself in the 'log_flush()' function of the 'log.c' file and is exposed when the application attempts to write an error log entry containing format specifiers.
Weex versions 2.6.1 and 2.6.1.5 are reported to be vulnerable.
6. DIA SVG File Import Remote Arbitrary Code Execution Vulnerability
BugTraq ID: 15000
Remote: Yes
Date Published: 2005-10-03
Relevant URL: http://www.securityfocus.com/bid/15000
Summary:
DIA is affected by an arbitrary code execution vulnerability.
This vulnerability presents itself when the application handles a malicious Scalable Vector Graphics (SVG) file.
A successful attack can allow remote attackers to execute arbitrary python code in the context of the application. This may facilitate a remote compromise.
All versions of DIA are suspected to be vulnerable at the moment.
7. Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 15002
Remote: No
Date Published: 2005-10-03
Relevant URL: http://www.securityfocus.com/bid/15002
Summary:
Berkeley MPEG Tools creates temporary files in an insecure manner.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service due to data corruption; other attacks may also be possible.
Berkeley MPEG Tools 1.5b is known to be vulnerable at the moment. Other versions may be affected as well.
8. Gnome-PTY-Helper UTMP Hostname Spoofing Vulnerability
BugTraq ID: 15004
Remote: No
Date Published: 2005-10-03
Relevant URL: http://www.securityfocus.com/bid/15004
Summary:
'gnome-pty-helper' is susceptible to a local UTMP hostname spoofing vulnerability. This issue is due to the failure of the application to properly validate user-supplied data prior to using it to update UTMP records.
This vulnerability allows users to spoof remote hostname information in UTMP records. This may aid attackers by misdirecting administrators and users as to the correct origin of the attacker.
9. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
BugTraq ID: 15009
Remote: Yes
Date Published: 2005-10-04
Relevant URL: http://www.securityfocus.com/bid/15009
Summary:
University Of Washington imap is prone to a buffer overflow vulnerability. This issue is exposed when the application parses mailbox names.
Successful exploitation will permit arbitrary code execution in the context of the server process. Exploitation requires the attacker to authenticate to the service.
10. Sun ONE Directory Server Unspecified Remote Vulnerability
BugTraq ID: 15013
Remote: Yes
Date Published: 2005-10-06
Relevant URL: http://www.securityfocus.com/bid/15013
Summary:
Sun ONE Directory Server is prone to an unspecified remote vulnerability.
The cause of this issue was not specified, however, it was reported that this issue can allow attackers to remotely compromise a vulnerable computer.
Sun ONE Directory Server 5.2 patch 3 and prior versions are affected by this issue. It is possible that Sun Java System Directory Server is vulnerable as well.
Due to a lack of details, further information is not available at the moment. This BID will be updated when more details become available.
11. Mozilla Firefox IFRAME Handling Denail Of Service Vulnerability
BugTraq ID: 15015
Remote: Yes
Date Published: 2005-10-05
Relevant URL: http://www.securityfocus.com/bid/15015
Summary:
Mozilla Firefox is prone to a remote denial of service vulnerability.
The vulnerability presents itself when an affected browser handles a specially crafted IFRAME.
A successful attack may result in crashing the application, or consuming excessive CPU and memory resources of computers running the affected application.
It should be noted that this issue was reported to affect Firefox 1.0.6 and 1.0.7 running on Linux. Other versions running on different platforms may be vulnerable as well.
12. Debian Linux Mason Init.d Firewall Loading Failure Vulnerability
BugTraq ID: 15019
Remote: Yes
Date Published: 2005-10-06
Relevant URL: http://www.securityfocus.com/bid/15019
Summary:
The Debian Linux Mason package is prone to an issue that may cause the firewall not to load at system startup. A startup script is missing from the installation package which performs a required function.
A false sense of security is held by the application owner when the affected computer is restarted.
A remote attacker may exploit this configuration error by connecting to ports that would otherwise be remotely unavailable.
13. SuSE YaST Package Repositories Insecure Permissions Vulnerability
BugTraq ID: 15026
Remote: No
Date Published: 2005-10-07
Relevant URL: http://www.securityfocus.com/bid/15026
Summary:
SuSE YaST is affected by an insecure permissions vulnerability that may allow local users to overwrite package meta files.
The application copies remote repositories including ownership and permissions of the owner of the packages to the local system. If insecure permissions are associated with the packages, this issue could lead to data corruption and other attacks.
This vulnerability can aid in the exploitation of BID 14861 (SuSE YaST Local Buffer Overflow Vulnerability), which requires an attacker to overwrite YaST package meta files prior to exploitation.
14. SUSE Linux Multiple Local Privilege Escalation Vulnerabilities
BugTraq ID: 15040
Remote: No
Date Published: 2005-10-07
Relevant URL: http://www.securityfocus.com/bid/15040
Summary:
Multiple SUSE Linux applications are prone to a local privilege escalation vulnerability. The issue exists because affected binaries handle the
'LD_LIBRARY_PATH' variable in an unsafe manner.
A local attacker may exploit this vulnerability to execute arbitrary code in shared libraries in the context of a user that runs the affected application.
Other unspecified packages are affected; if these other packages contain setuid-superuser privileges, then local escalation of privileges may be possible.
15. MediaWiki History Database Corruption Vulnerability
BugTraq ID: 15041
Remote: Yes
Date Published: 2005-10-07
Relevant URL: http://www.securityfocus.com/bid/15041
Summary:
MediaWiki is prone to a vulnerability that could result in a corruption of the database.
An attacker can exploit this vulnerability to corrupt the most recent revision in the database.
16. SUSE Linux PowerSave Daemon Local Denial Of Service Vulnerability
BugTraq ID: 15042
Remote: No
Date Published: 2005-10-07
Relevant URL: http://www.securityfocus.com/bid/15042
Summary:
SUSE Linux powersave daemon is susceptible to a local denial of service vulnerability. This issue is due to a flaw in the installed permissions of the daemon.
Local attackers may exploit this issue to control the power management daemon, to suspend the computer, denying service to legitimate users. Other attacks may also be possible.
17. HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
BugTraq ID: 15043
Remote: No
Date Published: 2005-10-07
Relevant URL: http://www.securityfocus.com/bid/15043
Summary:
HylaFAX is susceptible to a local insecure UNIX domain socket usage vulnerability. This issue is due to a failure of the application to securely implement UNIX domain network communication.
Attackers may gain access to the contents of fax messages containing potentially sensitive information, or deny fax services to legitimate users. Other attacks may also be possible.
18. Xine-Lib Remote CDDB Information Format String Vulnerability
BugTraq ID: 15044
Remote: Yes
Date Published: 2005-10-08
Relevant URL: http://www.securityfocus.com/bid/15044
Summary:
Xine-lib is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to securely implement a formatted printing function.
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
Xine-lib versions 0.9.13, 1.0, 1.0.1, 1.0.2, and 1.1.0 are reported to be affected. Other versions may also be affected, as well as all applications that utilize a vulnerable version of the library.
19. HAURI Anti-Virus ALZ Archive Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 15045
Remote: Yes
Date Published: 2005-10-06
Relevant URL: http://www.securityfocus.com/bid/15045
Summary:
HAURI Anti-Virus is affected by a remote buffer overflow vulnerability when handling ALZ archives.
An attacker can exploit this issue by crafting a malicious ALZ archive containing a compressed file with a specially crafted file name and sending this archive to a vulnerable computer.
The attacker may exploit this vulnerability to gain unauthorized remote access in the context of the superuser.
This issue is reported to affect products containing 'vrAZMain.dll' version 5.8.22.137; other versions may also be affected.
20. Multiple Vendor Antivirus Products Malformed Archives Scan Evasion Vulnerability
BugTraq ID: 15046
Remote: Yes
Date Published: 2005-10-08
Relevant URL: http://www.securityfocus.com/bid/15046
Summary:
Multiple antivirus products from various vendors are reported prone to a vulnerability that may allow malformed archive files to bypass detection.
This issue arises when an affected application processes a specially altered archive file that contains a fake, misleading MS-DOS executable MZ header.
This issue could result in malicious archives bypassing detection and allowing the contents to be opened by a recipient.
It should be noted that specific information regarding affected packages and versions is currently unavailable. The reporter of this issue used the EICAR test message stored in multiple different malformed archives. It may be possible that some of the reportedly affected packages may actually be immune to this issue.
This BID will be updated as further information is disclosed.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. FW: routing_based_on_port/services
http://www.securityfocus.com/archive/91/412509
2. routing_based_on_port/services
http://www.securityfocus.com/archive/91/412365
3. Group permissions changed
http://www.securityfocus.com/archive/91/412015
4. Securing Fedora Core 4
http://www.securityfocus.com/archive/91/411346
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Qualys
Test your Network Security with QualysGuard
Testing and improving your network security has never been easier. Requiring NO software, QualysGuard will safely and accurately audit your network and provide you with the necessary fixes to proactively guard your network. Try QualysGuard Risk Free with No Obligation.
http://altfarm.mediaplex.com/ad/ck/6148-32572-6929-2