SecurityFocus Linux Newsletter #294

Peter Laborge <[email protected]> Tue, 11 Jul 2006 16:51:58 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #294
----------------------------------------

This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your
security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com

------------------------------------------------------------------
I.   FRONT AND CENTER
        1. Basic journey of a packet
II.  LINUX VULNERABILITY SUMMARY
        1. Communigate Pro Server Pop Denial of Service Vulnerability
        2. Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
        3. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        4. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
        5. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
        6. Sparklet Remote Format String Vulnerability
        7. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
        8. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
        9. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
        10. Samba Internal Data Structures Denial of Service Vulnerability
III. LINUX FOCUS LIST SUMMARY
        1. smtp proxy that takes in smtp auth?
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Basic journey of a packet
By Don Parker
The purpose of this introductory article is to look at basic look at the journey of a packet across the Internet, from packet creation to switches, routers, NAT, and so on. This topic is recommended for those who are new to the networking and security field and may not have a basic understanding of the underlying process.
http://www.securityfocus.com/infocus/1870


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Communigate Pro Server Pop Denial of Service Vulnerability
BugTraq ID: 18770
Remote: Yes
Date Published: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18770
Summary:
CommuniGate Pro Server is prone to a remote denial-of-service vulnerability. This issue reportedly resides in the application's Pop component.

2. Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
BugTraq ID: 18782
Remote: Yes
Date Published: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18782
Summary:
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 1.3 Final is affected; other versions may also be vulnerable to this issue.

3. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Date Published: 2006-07-06
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel versions 2.6.17.3 and prior are affected by this issue.

4. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Date Published: 2006-07-06
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain elevated privileges, which may lead to a complete compromise.

Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be affected as well.

5. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
BugTraq ID: 18850
Remote: No
Date Published: 2006-07-05
Relevant URL: http://www.securityfocus.com/bid/18850
Summary:
Ubuntu Linux passwd may allow local attackers to gain elevated privileges. A successful attack may lead to a complete compromise.

6. Sparklet Remote Format String Vulnerability
BugTraq ID: 18862
Remote: Yes
Date Published: 2006-07-06
Relevant URL: http://www.securityfocus.com/bid/18862
Summary:
Sparklet is prone to a remote format-string vulnerability.

This is issue arises when the application displays a text string on the client screen during a match.

A successful exploit could result in executing arbitrary code or crashing the application.

Versions 0.9.4try3 and previous versions are vulnerable to this issue.

7. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
BugTraq ID: 18874
Remote: No
Date Published: 2006-07-06
Relevant URL: http://www.securityfocus.com/bid/18874
Summary:
Linux kernel is prone to a local privilege-escalation vulnerability.

A local attacker may gain elevated privileges by creating a coredump file in a directory that they do not have write access to.

A successful attack may result in a complete compromise.

Linux kernel versions prior to 2.6.17.4 are vulnerable.

8. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
BugTraq ID: 18877
Remote: Yes
Date Published: 2006-07-07
Relevant URL: http://www.securityfocus.com/bid/18877
Summary:
Gimp is prone to a buffer-overflow vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by forcing the application to read raw data from a malicious image file, with the privileges of the user running the GIMP application.

9. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
BugTraq ID: 18906
Remote: Yes
Date Published: 2006-07-10
Relevant URL: http://www.securityfocus.com/bid/18906
Summary:
The sipXtapi product is reported to be prone to a remote buffer-overflow vulnerability. This issue presents itself when the application handles a specially crafted 'CSeq' value.

A successful attack may lead to unauthorized remote access in the context of a user running an affected application that uses the vulnerable library.

Reports indicate that sipXtapi versions that were released prior to March 24, 2006 are vulnerable to this issue. Certain PingTel products and versions of AOL Triton may be affected because they employ the vulnerable library.

10. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Date Published: 2006-07-10
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources ultimately crashing the affected application.

This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. smtp proxy that takes in smtp auth?
http://www.securityfocus.com/archive/91/439444

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your
security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com