SecurityFocus Linux Newsletter #260

Peter Laborge <[email protected]> Tue, 15 Nov 2005 16:48:57 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #260
----------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Sony's legal issues
       2. Linux worm overrated
II.  LINUX VULNERABILITY SUMMARY
       1. Asterisk Voicemail Unauthorized Access Vulnerability
       2. Debian Horde Default Administrator Password Vulnerability
       3. Jed Wing CHM Lib LZX Decompression Method Buffer Overflow Vulnerability
       4. F-Secure Anti-Virus Gatekeeper and Gateway for Linux Local Privilege Escalation Vulnerability
       5. GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
       6. Linux-FTPD-SSL FTP Server Remote Buffer Overflow Vulnerability
       7. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
       8. Linux Kernel Sysctl Unregistration Local Denial of Service Vulnerability
       9. YaBB Image Upload HTML Injection Vulnerability
       10. SpamAssassin Bus Error Spam Detection Bypass Vulnerability
       11. IBM DB2 Content Manager Multiple Denial of Service Vulnerabilities
       12. IPCop Backup Key Information Disclosure Vulnerability
       13. IPCop Backup File Replacement Race Condition Vulnerability
       14. RealNetworks RealOne Player/RealPlayer RM File Remote Stack Based Buffer Overflow Vulnerability
       15. RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability 
       16. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
       17. Lynx URI Handlers Arbitrary Command Execution Vulnerability
       18. PHPSysInfo Multiple Input Validation Vulnerabilities
       19. RealNetworks RealPlayer Unspecified Malformed Image Skin File Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. SF new column announcement: Linux worm overrated
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Sony's legal issues
By Mark Rasch
Sony is in the spotlight over the rootkit they distribute on some of their music CDs, and it brings up interesting legal issues relating to EULAs and enforcement by the FTC.
http://www.securityfocus.com/columnists/369

2. Linux worm overrated
By Daniel Hanson
The latest and greatest Linux worm isn't the most elegant or fastest spreading worm, or even one that's difficult to stop, but it still offers a warning for Web developers and administrators everywhere.
http://www.securityfocus.com/columnists/368


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Asterisk Voicemail Unauthorized Access Vulnerability
BugTraq ID: 15336
Remote: Yes
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15336
Summary:
Asterisk is prone to an unauthorized access vulnerability.  This issue is due to a failure in the application to properly verify user-supplied input.

Successful exploitation will grant an attacker access to a victim users voicemail, and any '.wav/.WAV' files currently on the affected system.

2. Debian Horde Default Administrator Password Vulnerability
BugTraq ID: 15337
Remote: Yes
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15337
Summary:
The default Horde3 installation for Debian has a blank administrator password.

A local or remote attacker can exploit this vulnerability to gain administrative access to the affected application.  This may aid an attacker in further attacks against the underlying system; other attacks are also possible.

This issue is specific to Debian Linux installations of the Horde3 application.

3. Jed Wing CHM Lib LZX Decompression Method Buffer Overflow Vulnerability
BugTraq ID: 15338
Remote: Yes
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15338
Summary:
CHM lib is susceptible to a buffer overflow vulnerability.

Reports indicate that this issue affects the LZX decompression method.  It is conjectured that the vulnerability is remote in nature and allows attackers to execute arbitrary machine code in the context of the application that utilizes the CHM lib library. 

Further details are not available at the moment.  This BID will be updated when more information becomes available.

4. F-Secure Anti-Virus Gatekeeper and Gateway for Linux Local Privilege Escalation Vulnerability
BugTraq ID: 15339
Remote: No
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15339
Summary:
F-Secure Anti-Virus products are susceptible to a local privilege escalation vulnerability. This issue is due to insecure setuid-superuser binary permissions.

This vulnerability allows local attackers to gain superuser privileges, leading to complete compromise of the affected computer.

5. GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 15341
Remote: Yes
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15341
Summary:
GNU gnump3d is prone to an unspecified cross-site scripting vulnerability.  An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue is similar to that discussed in BID 15226 (GNU gnump3d Error Page Cross-Site Scripting Vulnerability) but is a seperate issue.

6. Linux-FTPD-SSL FTP Server Remote Buffer Overflow Vulnerability
BugTraq ID: 15343
Remote: Yes
Date Published: 2005-11-07
Relevant URL: http://www.securityfocus.com/bid/15343
Summary:
Linux-FTPD-SSL FTP Server is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input data prior to copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the vulnerable server application, typically with superuser privileges.

7. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
BugTraq ID: 15358
Remote: Yes
Date Published: 2005-11-08
Relevant URL: http://www.securityfocus.com/bid/15358
Summary:
PHP is prone to a denial of service vulnerability.

This issue occurs when parsing EXIF image data in corrupt JPEG files.

An attacker can exploit this vulnerability to crash the system, effectively denying service to legitimate users.

8. Linux Kernel Sysctl Unregistration Local Denial of Service Vulnerability
BugTraq ID: 15365
Remote: No
Date Published: 2005-11-09
Relevant URL: http://www.securityfocus.com/bid/15365
Summary:
Linux Kernel is reported prone to a local denial of service vulnerability.  

This issue arises from a failure to properly unregister kernel resources when network devices are removed.

This issue allows local attackers to deny service to legitimate users. It is conjectured that it may also be possible to execute arbitrary code in the context of the kernel, but this has not been confirmed.

9. YaBB Image Upload HTML Injection Vulnerability
BugTraq ID: 15368
Remote: Yes
Date Published: 2005-11-09
Relevant URL: http://www.securityfocus.com/bid/15368
Summary:
YaBB is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is only present when using the Microsoft Internet Explorer Web browser.


10. SpamAssassin Bus Error Spam Detection Bypass Vulnerability
BugTraq ID: 15373
Remote: Yes
Date Published: 2005-11-09
Relevant URL: http://www.securityfocus.com/bid/15373
Summary:
SpamAssassin is prone to a vulnerability that could bypass spam detection.  This issue is due to a failure in the application to handle exceptional conditions.

An attacker can exploit this vulnerability to crash a child process, effectively permitting the email to bypass detection and go through.

11. IBM DB2 Content Manager Multiple Denial of Service Vulnerabilities
BugTraq ID: 15376
Remote: Yes
Date Published: 2005-11-10
Relevant URL: http://www.securityfocus.com/bid/15376
Summary:
IBM DB2 Content Manager is prone to multiple vulnerabilities. These issues may allow attackers to carry out denial of service attacks.

The vulnerabilities affect versions prior to Content Manager Version 8.2 Fix Pack 10. 

12. IPCop Backup Key Information Disclosure Vulnerability
BugTraq ID: 15377
Remote: No
Date Published: 2005-11-10
Relevant URL: http://www.securityfocus.com/bid/15377
Summary:
IPCop is prone to an information disclosure vulnerability.  IPCop is prone to an information disclosure vulnerability.  The problem is due to how the application stores the key to encrypted backup files.

An attacker can exploit this vulnerability to decrypt backup files.  Information obtained may aid in further attacks; other attacks may also be possible.

It may be possible for an attacker to exploit this vulnerability to overwrite arbitrary backup files.  However, the attacker must have access to the 'nobody' user account, either through legitimate means, or through some other latent vulnerability.  The attacker may also be able to overwrite arbitrary files with superuser privileges through exploitation of this issue.

13. IPCop Backup File Replacement Race Condition Vulnerability
BugTraq ID: 15378
Remote: No
Date Published: 2005-11-10
Relevant URL: http://www.securityfocus.com/bid/15378
Summary:
IPCop is prone to a race condition that could permit the replacement of a backup file.  This issue is due to the application changing the ownership on the file before it in encrypts it.

A local attacker must have access to the 'nobody' user account, either through legitimate means, or through some other latent vulnerability to exploit this issue.

Successful exploitation will replace the backup file with arbitrary attacker-supplied data.  If the backup file is restored, system information may be overwritten with arbitrary data using superuser privileges.

14. RealNetworks RealOne Player/RealPlayer RM File Remote Stack Based Buffer Overflow Vulnerability
BugTraq ID: 15381
Remote: Yes
Date Published: 2005-11-10
Relevant URL: http://www.securityfocus.com/bid/15381
Summary:
RealNetworks RealPlayer and RealOne Player are reported prone to a remote stack based buffer overflow vulnerability.  The issue exists due to a lack of boundary checks performed by the application when parsing RM (Real Media) files.  A remote attacker may execute arbitrary code on a vulnerable computer to gain unauthorized access.

This vulnerability is reported to exist in RealNetworks products for Microsoft Windows, Linux, and Apple Mac platforms.

15. RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability 
BugTraq ID: 15382
Remote: Yes
Date Published: 2005-11-10
Relevant URL: http://www.securityfocus.com/bid/15382
Summary:
A heap overflow vulnerability exists in RealPlayer on Windows platforms.

The issue arises when 'DUNZIP32.DLL' is called to handle a malformed file.

A successful attack can allow the attacker to gain unauthorized access to a vulnerable computer.

16. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 15394
Remote: No
Date Published: 2005-11-11
Relevant URL: http://www.securityfocus.com/bid/15394
Summary:
Sudo is prone to a security bypass vulnerability that could lead to arbitrary code execution.  This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB' and 'PERL5OPT' environment variables when tainting is ignored.

An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.

An attacker must have the ability to run Perl scripts through Sudo to exploit this vulnerability.

17. Lynx URI Handlers Arbitrary Command Execution Vulnerability
BugTraq ID: 15395
Remote: Yes
Date Published: 2005-11-11
Relevant URL: http://www.securityfocus.com/bid/15395
Summary:
Lynx is prone to an arbitrary command execution vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

A remote attacker can exploit this vulnerability by tricking a victim user to follow a malicious link, thus enabling the attacker to execute arbitrary commands in the context of the victim user.

18. PHPSysInfo Multiple Input Validation Vulnerabilities
BugTraq ID: 15396
Remote: Yes
Date Published: 2005-11-11
Relevant URL: http://www.securityfocus.com/bid/15396
Summary:
phpSysInfo is prone to multiple input validation vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

phpSysInfo is prone to cross-site scripting, HTTP response splitting and arbitrary  local file inclusion vulnerabilities.

An attacker can exploit these vulnerabilities to steal cookie-based authentication credentials, aid in phishing style attacks and retrieve privileged or sensitive information; other attacks are also possible.

19. RealNetworks RealPlayer Unspecified Malformed Image Skin File Buffer Overflow Vulnerability
BugTraq ID: 15398
Remote: Yes
Date Published: 2005-11-12
Relevant URL: http://www.securityfocus.com/bid/15398
Summary:
RealNetworks RealPlayer is prone to an unspecified vulnerability that may let remote attackers execute arbitrary code.  

This issue may be triggered by a malformed image in a skin file.  The cause of the issue is reportedly a stack-based buffer overflow.  It is possible to exploit this issue by enticing a victim user to open a malicious skin file containing a malformed image.

This affects some RealPlayer 10/10.5 releases on Windows platforms.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. SF new column announcement: Linux worm overrated
http://www.securityfocus.com/archive/91/416253

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130