SecurityFocus Linux Newsletter #264
Peter Laborge <[email protected]> Tue, 13 Dec 2005 17:01:35 -0700
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #264
----------------------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper
The newest web app vulnerability. Blind SQL Injection!
Even if your web application does not return error messages, it may still be open to a Blind SQL Injection Attack.
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and
manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a
complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701300000003Har
------------------------------------------------------------------
I. FRONT AND CENTER
1. Trusting software
2. Users inundated with pop-ups
II. LINUX VULNERABILITY SUMMARY
1. Nodezilla Evl_Data Directory Unauthorized Access Vulnerability
2. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
3. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
4. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
5. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
6. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
7. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
8. Multiple Vendor BIOS Password Persistence Weakness
9. cURL / libcURL URL Parser Buffer Overflow Vulnerability
10. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
11. Apache MPM Worker.C Denial Of Service Vulnerability
12. Courier Mail Server Unauthorized Access Vulnerability
13. Lyris ListManager Command Execution Vulnerability
14. Lyris Listmanager TCLHTTPd Service Multiple Information Disclosure Vulnerabilities
15. Lyris ListManager Hidden Variable Information Disclosure Vulnerability
16. Contenido CMS Unspecified Remote Command Execution Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. Security, Distributed firewalling application...long ;-)
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Trusting software
By Jason Miller
rust is in everything we do, from the important to the mundane. Whether it's open-source or closed-source, how do we evaluate what software, companies and projects are safe to trust?
http://www.securityfocus.com/columnists/373
2. Users inundated with pop-ups
By Scott Granneman
There are many examples where users are now being inundated with pop-up messages asking them to respond to things they don't know about or don't understand, and it leads to weaker security overall.
http://www.securityfocus.com/columnists/374
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Nodezilla Evl_Data Directory Unauthorized Access Vulnerability
BugTraq ID: 15704
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15704
Summary:
Nodezilla is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to restrict access to sensitive files.
An attacker can exploit this issue to gain access to sensitive and privileged information. Information obtained may aid the malicious user in further attacks against the vulnerable application and possibly the underlying system.
2. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
It is reported that this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well. Applications using embedded xpdf code may be vulnerable to this issue as well.
kpdf reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.
3. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
It is reported that this issue presents itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well. Applications using embedded xpdf code may be vulnerable to this issue as well.
pdftohtml also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
kpdf reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.
4. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
It is reported that this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well. Applications using embedded xpdf code may be vulnerable to this issue as well.
pdftohtml also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
kpdf reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.
5. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
It is reported that this issue presents itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well. Applications using embedded xpdf code may be vulnerable to this issue as well.
pdftohtml also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
kpdf reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.
6. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial of service vulnerability.
Local attackers can exploit this to corrupt kernel memory or free non-allocated memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.
7. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15735
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15735
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
8. Multiple Vendor BIOS Password Persistence Weakness
BugTraq ID: 15751
Remote: No
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15751
Summary:
Multiple BIOS (Basic Input-Output System) vendors fail to clear the keyboard buffer after reading the BIOS password during the system startup process.
This issue is reported to affect Insyde BIOS V190, and AWARD BIOS Modular 4.50pg. Other versions and platforms are also likely affected.
Depending on the operating system running on affected computers, the memory region may or may not be available for user-level access. With Linux operating systems, superuser access is required. With Microsoft Windows operating systems, non-privileged users may access the keyboard buffer region.
Attackers that obtain the BIOS password may then utilize it for further attacks.
9. cURL / libcURL URL Parser Buffer Overflow Vulnerability
BugTraq ID: 15756
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15756
Summary:
cURL and libcURL are prone to a buffer overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user supplied data before using it in a finite sized buffer.
The issues occur when the URL parser function handles an excessively long URL string.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, this may facilitate a compromise of the underlying system.
10. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
BugTraq ID: 15761
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15761
Summary:
phpMyAdmin is prone to a vulnerability that permits an attacker to overwrite global variables.
An attacker can exploit this issue to overwrite the global variables with arbitrary input. Through control of the global variables, the attacker may be able to include arbitrary remote and local files depending on the current PHP version. Various other attacks are also possible.
11. Apache MPM Worker.C Denial Of Service Vulnerability
BugTraq ID: 15762
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15762
Summary:
Apache is prone to a memory leak, causing a denial of service vulnerability.
Apache is prone to a memory leak, causing a denial of service vulnerability.
An attacker may consume excessive memory resources, resulting in a denial of service condition affecting legitimate users.
Apache 2.x versions are vulnerable; other versions may also be affected.
12. Courier Mail Server Unauthorized Access Vulnerability
BugTraq ID: 15771
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15771
Summary:
Courier Mail Server is prone to an unauthorized access vulnerability. This issue occurs because accounts that have been deactivated may still be able to log onto the server.
13. Lyris ListManager Command Execution Vulnerability
BugTraq ID: 15786
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15786
Summary:
Lyris ListManager is prone to a CRLF injection vulnerability.
Attackers may exploit this weakness to execute list manager administrative commands, and manipulate the structure of outgoing messages. For example, it may be possible for attackers to set the recipient to an arbitrary value.
Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.
14. Lyris Listmanager TCLHTTPd Service Multiple Information Disclosure Vulnerabilities
BugTraq ID: 15788
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15788
Summary:
The Lyris ListManager TCLHTTPd Service is prone to multiple vulnerabilities.
An attacker may obtain unathorized access to sensitive information, and view arbitrary TML source code on the affected computer.
Versions 5.0 through 8.8a are affected; other versions may also be vulnerable.
15. Lyris ListManager Hidden Variable Information Disclosure Vulnerability
BugTraq ID: 15789
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15789
Summary:
Lyris ListManager is prone to an information disclosure vulnerability.
This vulnerability may be used to disclose the software version and software installation path, which may be helpful in further attacks.
Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.
16. Contenido CMS Unspecified Remote Command Execution Vulnerability
BugTraq ID: 15790
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15790
Summary:
Contenido CMS is prone to an unspecified remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary commands in the context of the Web server process. This may facilitate a compromise of the underlying system; other attacks are also possible.
It should be notes that the "allow_url_fopen" and "register_globals" PHP variables must be enabled to exploit this vulnerability.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Security, Distributed firewalling application...long ;-)
http://www.securityfocus.com/archive/91/418029
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper
The newest web app vulnerability. Blind SQL Injection!
Even if your web application does not return error messages, it may still be open to a Blind SQL Injection Attack.
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and
manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a
complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701300000003Har