SecurityFocus Linux Newsletter #289
Conrad Schilbe <[email protected]> Tue, 06 Jun 2006 22:59:55 -0600
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #289
----------------------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70130000000CUOm
------------------------------------------------------------------
I. FRONT AND CENTER
1. Browsers, phishing, and user interface design
2. Standards in desktop firewall policies
II. LINUX VULNERABILITY SUMMARY
1. Dia Multiple Unspecified Remote Format String Vulnerabilities
2. Linux Kernel Invalid Proc Memory Access Local Denial of Service Vulnerability
3. Linux Kernel ELF Loader Mismatched Architecture Local Denial of Service Vulnerability
4. Linux Kernel MIPS Ptrace Local Privilege Escalation Vulnerability
5. Linux Kernel MREMAP Local Privilege Escalation Vulnerability
6. Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
7. Rug SSL Certificates Man In The Middle Vulnerability
8. Typespeed Remote Buffer Overflow Vulnerability
9. Snort URIContent Rules Detection Evasion Vulnerability
10. FreeBSD SMBFS CHRoot Security Restriction Bypass Vulnerability
11. GNOME Evolution Email Attachment Denial Of Service Vulnerability
12. Drupal Multiple Input Validation Vulnerabilities
13. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
14. Asterisk IAX2 Remote Denial of Service Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. Application level proxy for POP3/SMTP protocol
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Browsers, phishing, and user interface design
By Scott Granneman
Phishing works for so many reasons, we need to rethink browser and user interface design to provide some real-life security to the average user who doesn't see or understand the security cues.
http://www.securityfocus.com/columnists/405
2. Standards in desktop firewall policies
By Phil Kostenbader and Bob Donnelly
The idea of a common desktop firewall policy in any size organization is a very good thing. It makes responses to external or internal situations such as virus outbreaks or network-oriented propagation of viruses more predictable. In addition to providing a level of protection against port scanning, attacks or software vulnerabilities, it can provide the organizations local security team a baseline or starting point in dealing with such events.
http://www.securityfocus.com/infocus/1867
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Dia Multiple Unspecified Remote Format String Vulnerabilities
BugTraq ID: 18166
Remote: Yes
Date Published: 2006-05-30
Relevant URL: http://www.securityfocus.com/bid/18166
Summary:
Dia is prone to multiple unspecified format-string vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input before including it in the format-specifier argument of formatted-printing functions.
A successful attack may crash the application or lead to arbitrary code execution.
Specific information regarding affected versions of Dia is not currently available; this BID will be updated as further information is disclosed.
2. Linux Kernel Invalid Proc Memory Access Local Denial of Service Vulnerability
BugTraq ID: 18173
Remote: No
Date Published: 2006-05-30
Relevant URL: http://www.securityfocus.com/bid/18173
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the 'proc' filesystem.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.4.27.
3. Linux Kernel ELF Loader Mismatched Architecture Local Denial of Service Vulnerability
BugTraq ID: 18174
Remote: No
Date Published: 2006-05-30
Relevant URL: http://www.securityfocus.com/bid/18174
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the ELF object file loader.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.4.25.
4. Linux Kernel MIPS Ptrace Local Privilege Escalation Vulnerability
BugTraq ID: 18176
Remote: No
Date Published: 2006-05-30
Relevant URL: http://www.securityfocus.com/bid/18176
Summary:
The Linux kernel is susceptible to a local privilege-escalation vulnerability. This issue occurs only on MIPS architectures.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
Specific information regarding affected versions is not currently available; this BID will be updated as further information is disclosed.
5. Linux Kernel MREMAP Local Privilege Escalation Vulnerability
BugTraq ID: 18177
Remote: No
Date Published: 2006-05-30
Relevant URL: http://www.securityfocus.com/bid/18177
Summary:
The Linux kernel is susceptible to a local privilege-escalation vulnerability. This issue occurs due to an unspecified flaw in 'mremap'.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
Linux kernel versions prior to 2.4.25 are vulnerable to this issue.
6. Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
BugTraq ID: 18183
Remote: No
Date Published: 2006-05-31
Relevant URL: http://www.securityfocus.com/bid/18183
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the 'proc' filesystem.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions 2.6.15 through 2.6.17-rc5 on multiprocessor computers running SMP kernels. Other kernel versions may also be affected.
7. Rug SSL Certificates Man In The Middle Vulnerability
BugTraq ID: 18193
Remote: Yes
Date Published: 2006-05-31
Relevant URL: http://www.securityfocus.com/bid/18193
Summary:
The rug utility is prone to a man-in-the-middle vulnerability. This issue likely arises due to a design error.
An attacker may exploit this issue to gain access to sensitive contents of encrypted network traffic between the rug client and a server. Depending on the type of information that is disclosed, this issue may lead to other attacks as well.
Note that attackers may be able to exploit this issue from outside the firewall protecting an affected rug client, but firewall protection may make a successful exploit more difficult.
8. Typespeed Remote Buffer Overflow Vulnerability
BugTraq ID: 18194
Remote: Yes
Date Published: 2006-05-31
Relevant URL: http://www.securityfocus.com/bid/18194
Summary:
Typespeed is susceptible to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of affected applications, aiding them in the compromise of affected computers.
Typespeed versions 0.4.1 and 0.4.4 are vulnerable to this issue; other versions may also be affected.
9. Snort URIContent Rules Detection Evasion Vulnerability
BugTraq ID: 18200
Remote: Yes
Date Published: 2006-05-31
Relevant URL: http://www.securityfocus.com/bid/18200
Summary:
Snort is reportedly prone to a vulnerability that may allow malicious packets to bypass detection.
A successful attack can allow attackers to bypass intrusion detection and to carry out attacks against computers protected by Snort.
This vulnerability affects Snort 2.4.4. Other versions may be vulnerable as well.
10. FreeBSD SMBFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 18202
Remote: No
Date Published: 2006-06-01
Relevant URL: http://www.securityfocus.com/bid/18202
Summary:
FreeBSD is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.
The problem affects chroot inside of an SMB-mounted filesystem ('smbfs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and then gain unauthorized access to the filesystem.
Although this issue is identical to the vulnerability described in BID 17735 (Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability), this issue has been assigned a CVE number (CVE-2006-2654).
11. GNOME Evolution Email Attachment Denial Of Service Vulnerability
BugTraq ID: 18212
Remote: Yes
Date Published: 2006-06-01
Relevant URL: http://www.securityfocus.com/bid/18212
Summary:
A denial-of-service vulnerability has been reported in Evolution.
A remote attacker may cause a denial-of-service condition in the application, effectively denying service to legitimate users.
12. Drupal Multiple Input Validation Vulnerabilities
BugTraq ID: 18245
Remote: Yes
Date Published: 2006-06-02
Relevant URL: http://www.securityfocus.com/bid/18245
Summary:
Drupal is prone to multiple input-validation vulnerabilities. The issues include the execution of arbitrary files, cross-site scripting, and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
13. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
BugTraq ID: 18290
Remote: Yes
Date Published: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18290
Summary:
SpamAssassin is prone to an arbitrary-command-execution vulnerability. This issue is due to an error in the application when processing a specially formatted input message when certain switches are set.
An attacker can exploit this issue to execute arbitrary comannds on the vulnerable computer with the privileges of the affected application.
14. Asterisk IAX2 Remote Denial of Service Vulnerability
BugTraq ID: 18295
Remote: Yes
Date Published: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18295
Summary:
Asterisk is prone to a remote denial-of-service vulnerability. This issue is most likely due to a design error within the application.
This vulnerability allows remote attackers to crash the server, denying further service to legitimate users.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Application level proxy for POP3/SMTP protocol
http://www.securityfocus.com/archive/91/435551
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70130000000CUOm