SecurityFocus Linux Newsletter #267
Peter Laborge <[email protected]> Wed, 04 Jan 2006 11:09:56 -0700
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #267
----------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------
I. FRONT AND CENTER
1. Zero-day holiday
II. LINUX VULNERABILITY SUMMARY
1. Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
2. TkDiff Insecure Temporary File Creation Vulnerability
3. Debian DHIS-TOOLS-DNS Insecure Temporary File Creation Vulnerability
4. BZFlag Unterminated Callsign Denial Of Service Vulnerability
5. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
6. Gentoo Linux XnView Insecure RPATH Vulnerability
7. MTink Home Environment Variable Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. Obsidis n°1 released!
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Zero-day holiday
By Kelly Martin
A few hundred million Windows XP machines lay vulnerable on the Web today, a week after a zero-day exploit was discovered. Meanwhile, new approaches and ideas from the academic world - that focus exclusively on childen - may give us hope for the future after all.
http://www.securityfocus.com/columnists/377
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16061
Remote: No
Date Published: 2005-12-26
Relevant URL: http://www.securityfocus.com/bid/16061
Summary:
Bugzilla creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
2. TkDiff Insecure Temporary File Creation Vulnerability
BugTraq ID: 16064
Remote: No
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16064
Summary:
TkDiff creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
TkDiff 4.1 and prior versions are vulnerable to this issue.
3. Debian DHIS-TOOLS-DNS Insecure Temporary File Creation Vulnerability
BugTraq ID: 16065
Remote: No
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16065
Summary:
Debian dhis-tools-dns creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
dhis-tools-dns 5.0 is vulnerable to this issue.
4. BZFlag Unterminated Callsign Denial Of Service Vulnerability
BugTraq ID: 16066
Remote: Yes
Date Published: 2005-12-25
Relevant URL: http://www.securityfocus.com/bid/16066
Summary:
BZFlag is prone to a denial of service vulnerability.
This vulnerability may be triggered by a malformed callsign message.
5. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 16076
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16076
Summary:
The Ethereal GTP protocol dissector is prone to remotely exploitable denial of service vulnerability.
Successful exploitation will cause a denial of service condition in the Ethereal application.
Further details are not currently available. This BID will be updated as more information is disclosed.
6. Gentoo Linux XnView Insecure RPATH Vulnerability
BugTraq ID: 16087
Remote: No
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16087
Summary:
Gentoo Linux XnView is susceptible to an insecure RPATH vulnerability.
This issue may allow local attackers to execute code with the privileges of a user that executes the application.
Gentoo Linux XnView versions prior to 1.70-r1 are vulnerable to this issue.
7. MTink Home Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 16095
Remote: No
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16095
Summary:
A buffer overflow vulnerability affects MTink. This vulnerability may permit local attackers to execute arbitrary code with superuser privileges.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Obsidis n°1 released!
http://www.securityfocus.com/archive/91/420151
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
V. SPONSOR INFORMATION
------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130