SecurityFocus Linux Newsletter #290

Conrad Schilbe <[email protected]> Thu, 15 Jun 2006 10:06:54 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #290
----------------------------------------

This issue is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Retain or restrain access logs?
II.  LINUX VULNERABILITY SUMMARY
       1. DokuWiki Remote PHP Script Code Injection Vulnerability
       2. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
       3. GD Graphics Library Remote Denial of Service Vulnerability
       4. Asterisk IAX2 Remote Buffer Overflow Vulnerability
       5. FreeType TTF File Remote Buffer Overflow Vulnerability
       6. FreeType TTF File Remote Denial of Service Vulnerability
       7. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
       8. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
       9. Courier Mail Server Username Encoding Remote Denial Of Service Vulnerability
       10. 0verkill UDP Datagram Remote Denial of Service Vulnerability
       11. WordPress Username Remote PHP Code Injection Vulnerability
       12. Nullsoft SHOUTcast Multiple HTML Injection Vulnerabilities
       13. IBM DB2 Universal Database Multiple Denial of Service Vulnerabilities
       14. KDE ArtsWrapper Local Privilege Escalation Vulnerability
       15. KDE KDM Session Type Symbolic Link Vulnerability
       16. Sendmail Malformed MIME Message Denial Of Service Vulnerability
       17.  Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
       18. wv2 Remote Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. Application level proxy for POP3/SMTP protocol
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Retain or restrain access logs?
By Mark Rasch
A recent proposal by the U.S. Department of Justice that would mandate Internet Service Providers to retain certain records represents a dangerous trend of turning private companies into proxies for law enforcement or intelligence agencies against the interests of their clients or customers.
http://www.securityfocus.com/columnists/406


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. DokuWiki Remote PHP Script Code Injection Vulnerability
BugTraq ID: 18289
Remote: Yes
Date Published: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18289
Summary:
DokuWiki is prone to a remote PHP code-injection vulnerability. 

An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.

DokuWiki versions 2006-06-04 and prior are vulnerable; other versions may also be affected.

2. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
BugTraq ID: 18290
Remote: Yes
Date Published: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18290
Summary:
SpamAssassin is prone to an arbitrary-command-execution vulnerability. This issue is due to an error in the application when processing a specially formatted input message when certain switches are set. 

An attacker can exploit this issue to execute arbitrary comannds on the vulnerable computer with the privileges of the affected application.

3. GD Graphics Library Remote Denial of Service Vulnerability
BugTraq ID: 18294
Remote: Yes
Date Published: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18294
Summary:
The GD Graphics Library is prone to a denial-of-service vulnerability. Attackers can trigger an infinite-loop condition when the library tries to handle malformed image files.

This issue allows attackers to consume excessive CPU resources on computers that use the affected software. This may deny service to legitimate users.

GD version 2.0.33 is vulnerable to this issue; other versions may also be affected.

4. Asterisk IAX2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18295
Remote: Yes
Date Published: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18295
Summary:
Asterisk is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the server, denying further service to legitimate users.

5. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Date Published: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

6. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Date Published: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.

This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

7. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
BugTraq ID: 18331
Remote: Yes
Date Published: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18331
Summary:
The tiff2pdf utility is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying service to legitimate users.

8. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
BugTraq ID: 18332
Remote: No
Date Published: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18332
Summary:
GDM is susceptible to an authentication-bypass vulnerability when users try to access the 'Configure Login Manager' option.

This issue allows local attackers to execute the 'Configure Login Manager' option with superuser privileges without entering valid superuser credentials. This allows them to make unauthorized configuration changes, which in turn grants them administrative access to affected computers, facilitating their complete compromise.

9. Courier Mail Server Username Encoding Remote Denial Of Service Vulnerability
BugTraq ID: 18345
Remote: Yes
Date Published: 2006-06-09
Relevant URL: http://www.securityfocus.com/bid/18345
Summary:
Courier Mail Server is prone to a remote denial-of-service vulnerability because it fails to properly handle certain usernames in email messages.

A remote attacker may exploit this issue to consume excessive CPU resources, potentially denying service to legitimate users.

Versions of the Courier MTA prior to 0.53.2 are vulnerable to this issue.

10. 0verkill UDP Datagram Remote Denial of Service Vulnerability
BugTraq ID: 18353
Remote: Yes
Date Published: 2006-06-09
Relevant URL: http://www.securityfocus.com/bid/18353
Summary:
A denial-of-service vulnerability affects 0verkill. This issue is due to the application's failure to properly handle certain UDP datagrams.

The vulnerability allows remote attackers from external networks to crash the application, denying further service to legitimate users.

0verkill version 0.16 is vulnerable to this issue; other versions may also be affected.

11. WordPress Username Remote PHP Code Injection Vulnerability
BugTraq ID: 18372
Remote: Yes
Date Published: 2006-06-12
Relevant URL: http://www.securityfocus.com/bid/18372
Summary:
WordPress is prone to a remote PHP code-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.

For a successful exploit of this issue, the MySQL password used in the application must be either blank or trivial to guess.

12. Nullsoft SHOUTcast Multiple HTML Injection Vulnerabilities
BugTraq ID: 18376
Remote: Yes
Date Published: 2006-06-12
Relevant URL: http://www.securityfocus.com/bid/18376
Summary:
Nullsoft SHOUTcast is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

These issues affect version 1.9.5; other versions may also be vulnerable.

13. IBM DB2 Universal Database Multiple Denial of Service Vulnerabilities
BugTraq ID: 18428
Remote: Yes
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18428
Summary:
IBM DB2 Universal Database is prone to multiple denial-of-service vulnerabilities. 

An attacker may be able to exploit these issues to cause the database to crash or hang, effectively denying service to legitimate users.

These issues affect DB2 versions prior to 8 FixPak 12 also known as version 8.2 FixPak 5.

14. KDE ArtsWrapper Local Privilege Escalation Vulnerability
BugTraq ID: 18429
Remote: No
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18429
Summary:
KDE's artswrapper utility is susceptible to a local privilege-escalation vulnerability because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

15. KDE KDM Session Type Symbolic Link Vulnerability
BugTraq ID: 18431
Remote: No
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18431
Summary:
KDM is prone to a vulnerability that may permit symbolic-link attacks when processing the user's session type.

An attacker with local access could potentially exploit this issue to view files and obtain privileged information.

A successful attack would most likely result in the loss of confidentiality and the theft of privileged information.

16. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

17.  Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18436
Remote: Yes
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18436
Summary:
Horde is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

18. wv2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18437
Remote: Yes
Date Published: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18437
Summary:
The wv2 library is susceptible to a remote buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library to parse malicious Microsoft Word files.

Version 0.2.2 of the wv2 library is vulnerable to this issue; other versions may also be affected.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Application level proxy for POP3/SMTP protocol
http://www.securityfocus.com/archive/91/435551

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus