SecurityFocus Linux Newsletter #287
Peter Laborge <[email protected]> Tue, 23 May 2006 15:25:45 -0600
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #287
----------------------------------------
This issue is sponsored by: Lancope
"Revolutionize the way you view your network security"
How do you protect what you can't see? Stop protecting while blind. Gain network visibility now. Learn how Cisco NetFlow gives visibility and enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
ALERT: Download FREE White Paper "Network Behavior Analysis (NBA) in the Enterprise."
http://www.lancope.com/resource/
------------------------------------------------------------------
I. FRONT AND CENTER
1. Protection from prying NSA eyes
2. Malicious cryptography, part two
II. LINUX VULNERABILITY SUMMARY
1. Genecys Remote Buffer Overflow and Denial Of Service Vulnerabilities
2. Quagga BGPD Local Denial Of Service Vulnerability
3. Raydium Multiple Remote Buffer Overflow and Denial Of Service Vulnerabilities
4. Caucho Resin Viewfile Information Disclosure Vulnerability
5. Hitachi EUR Unspecified SQL Injection Vulnerability
6. MP3Info Unspecified Buffer Overflow Vulnerability
7. Libextractor Multiple Heap Buffer Overflow Vulnerabilities
8. Linux Kernel __SetLease Local Denial of Service Vulnerability
9. Invision Power Board Multiple Arbitrary PHP Code Execution Vulnerabilities
10. KPhone Local Information Disclosure Vulnerability
11. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
12. Nagios Remote Content-Length Integer Overflow Vulnerability
13. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
14. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
III. LINUX FOCUS LIST SUMMARY
1. Linux's security
2. Version 0.8 of OSSEC HIDS is now available (for Unix and Windows)
3. SF new column announcement: The quest for ring 0 (fwd)
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Protection from prying NSA eyes
By Mark Rasch
From the U.S. Fourth Amendment, the Stored Communications Act and U.S. wiretap laws to the Pen-register statute, Mark Rasch looks at legal protections available to the telecommunication companies and individual Americans in the wake of the NSA's massive spying program.
http://www.securityfocus.com/columnists/403
2. Malicious cryptography, part two
By Frederic Raynal
This two-part article series looks at how cryptography is a double-edged sword: it is used to make us safer, but it is also being used for malicious purposes within sophisticated viruses. Part two continues the discussion of armored viruses and then looks at a Bradley worm - a worm that uses cryptography in such a way that it cannot be analyzed. Then it is shown how Skype can be used for malicious purposes, with a crypto-virus that is very difficult to detect.
http://www.securityfocus.com/infocus/1866
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Genecys Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17969
Remote: Yes
Date Published: 2006-05-13
Relevant URL: http://www.securityfocus.com/bid/17969
Summary:
Genecys is susceptible to multiple remote vulnerabilities.
A buffer-overflow vulnerability and denial-of-service vulnerability affect Genecys and potentially allow remote attackers to execute arbitrary machine code and to crash the affected application.
Version 0.2 and prior, as well as the CVS version, are vulnerable to these issues; other versions may also be affected.
2. Quagga BGPD Local Denial Of Service Vulnerability
BugTraq ID: 17979
Remote: No
Date Published: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17979
Summary:
Quagga is prone to a local denial-of-service vulnerability.
An attacker can exploit this issue by using commands that cause the consumption of a large amount of CPU resources.
An attacker may cause the application to crash, thus denying service to legitimate users.
Version 0.98.3 is vulnerable; other versions may also be affected.
3. Raydium Multiple Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17986
Remote: Yes
Date Published: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17986
Summary:
Raydium is susceptible to multiple remote vulnerabilities:
- Multiple buffer-overflow vulnerabilities in both client and server instances.
- A format-string vulnerability in both client and server instances.
- A NULL-pointer dereference denial-of-service vulnerability in both client and server instances.
- A buffer-overflow vulnerability in client instances.
These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected client and server instances of games that use the affected game engine software. Attackers may also crash vulnerable instances, denying service to legitimate users.
4. Caucho Resin Viewfile Information Disclosure Vulnerability
BugTraq ID: 18007
Remote: Yes
Date Published: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/18007
Summary:
Resin is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve the contents of arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
5. Hitachi EUR Unspecified SQL Injection Vulnerability
BugTraq ID: 18015
Remote: Yes
Date Published: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18015
Summary:
Hitachi EUR is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
6. MP3Info Unspecified Buffer Overflow Vulnerability
BugTraq ID: 18016
Remote: Yes
Date Published: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18016
Summary:
MP3Info is prone to a buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Version 0.8.4 of MP3Info is vulnerable to this issue; other versions may also be affected.
7. Libextractor Multiple Heap Buffer Overflow Vulnerabilities
BugTraq ID: 18021
Remote: Yes
Date Published: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18021
Summary:
The libextractor library is affected by multiple buffer-overflow vulnerabilities. The software fails to perform sufficient boundary checks of user-supplied input before copying it to insufficiently sized memory buffers.
An attacker exploits these issues by enticing a vulnerable user to open a malformed file using an application that employs libextractor.
This issue allows attackers to execute arbitrary machine code in the context of applications that use the affected library, aiding them in the remote compromise of affected computers.
Version 0.5.13 of libextractor is vulnerable to these issues; other versions may also be affected.
8. Linux Kernel __SetLease Local Denial of Service Vulnerability
BugTraq ID: 18033
Remote: No
Date Published: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the '__setlease' function.
This vulnerability allows local users to leak kernel memory, potentially resulting in a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.16.
9. Invision Power Board Multiple Arbitrary PHP Code Execution Vulnerabilities
BugTraq ID: 18040
Remote: Yes
Date Published: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18040
Summary:
Invision Power Board is prone to multiple remote code-execution vulnerabilities. These issues may allow an attacker to gain unauthorized access to a vulnerable computer by executing arbitrary PHP code.
These issues affect versions 2.1.6 and 2.0.4; earlier versions are also vulnerable.
10. KPhone Local Information Disclosure Vulnerability
BugTraq ID: 18049
Remote: No
Date Published: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18049
Summary:
KPhone is susceptible to a local information-disclosure vulnerability. This issue is due to the application's failure to ensure that files containing sensitive information are properly secured.
This issue allows local attackers to gain access to potentially sensitive information, including SIP configuration and passwords. This may aid them in further attacks.
KPhone version 4.2 is vulnerable to this issue; other versions may also be affected.
11. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
BugTraq ID: 18056
Remote: Yes
Date Published: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/18056
Summary:
Cyrus IMAPD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly verify user-supplied input before copying it into a finite-sized buffer.
Successful exploits may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.
Cyrus IMAPD version 2.3.2 is reported to be vulnerable. Other versions may be affected as well.
12. Nagios Remote Content-Length Integer Overflow Vulnerability
BugTraq ID: 18059
Remote: Yes
Date Published: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/18059
Summary:
Nagios is prone to a remote integer-overflow vulnerability. The application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3.1 are vulnerable to this issue.
This issue is very similar to BID 17879 (Nagios Remote Negative Content-Length Buffer Overflow Vulnerability), but is a separate issue.
13. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Date Published: 2006-05-20
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability.
This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users.
Kernel versions prior to 2.6.16.18 are vulnerable to this issue.
14. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Date Published: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Linux's security
http://www.securityfocus.com/archive/91/434109
2. Version 0.8 of OSSEC HIDS is now available (for Unix and Windows)
http://www.securityfocus.com/archive/91/433778
3. SF new column announcement: The quest for ring 0 (fwd)
http://www.securityfocus.com/archive/91/433658
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by: Lancope
"Revolutionize the way you view your network security"
How do you protect what you can't see? Stop protecting while blind. Gain network visibility now. Learn how Cisco NetFlow gives visibility and enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
ALERT: Download FREE White Paper "Network Behavior Analysis (NBA) in the Enterprise."
http://www.lancope.com/resource/