SecurityFocus Linux Newsletter #296

Peter Laborge <[email protected]> Tue, 25 Jul 2006 16:03:27 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #296
----------------------------------------

This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com

------------------------------------------------------------------
I.   FRONT AND CENTER
        1. A month of browser bugs
        2. After an Exploit: mitigation and remediation
II.  LINUX VULNERABILITY SUMMARY
        1. Debian GNU/Linux Rssh Security Bypass Vulnerability
        2. Rocks Clusters Local Privilege Escalation Vulnerabilities
        3. Asterisk IAX2 Request Flood Remote Denial of Service Vulnerability
        4. Armagetron Advanced Invalid Values Multiple Remote Denial Of Service Vulnerabilities
        5. Zoho Virtual Office Message HTML Injection Vulnerability
        6. MySQL Server Date_Format Denial Of Service Vulnerability
        7. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
        8. Wireshark Protocol Dissectors Multiple Vulnerabilities
        9. VMware Information Disclosure Vulnerability
        10. RETIRED: VMware SSL Key File Information Disclosure Weakness
        11. FBGS PostScript Filter Bypass Vulnerability
        12. KDE Desktop Screensaver Lock Activation Failure Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. A month of browser bugs
By Scott Granneman
Scott Granneman looks at the virtues and pitfalls of browser fuzzing and the overwhelmingly positive impact it has on the security community.
http://www.securityfocus.com/columnists/411

2. After an Exploit: mitigation and remediation
By Jamie Riden
This article describes a few hardening and alerting methods for Unix servers that help block vectors for various attacks, including two web-based application attacks, DNS issues, and the brute-forcing of SSH passwords. The article then looks at steps to take and lessons learned post-compromise.
http://www.securityfocus.com/infocus/1871


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Debian GNU/Linux Rssh Security Bypass Vulnerability
BugTraq ID: 18999
Remote: No
Date Published: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18999
Summary:
A programming error in the 'util.c' file of the rssh package in Debian GNU/Linux allows rdist and rsync to bypass security.

This vulnerability may facilitate privilege escalation, because the error allows rssh's check for CVS to always succeed. An attacker could use this vulnerability to their advantage and bypass existing security limitations and access controls.

2. Rocks Clusters Local Privilege Escalation Vulnerabilities
BugTraq ID: 19003
Remote: No
Date Published: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19003
Summary:
Rocks Clusters is prone to multiple local privilege-escalation vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input..

These issues allow local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

Rocks Clusters versions 4.1 and prior are vulnerable to these issues.

3. Asterisk IAX2 Request Flood Remote Denial of Service Vulnerability
BugTraq ID: 19009
Remote: Yes
Date Published: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19009
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because it fails to efficiently handle numerous remote requests.

This issue allows remote attackers to consume excessive CPU resources, denying service to legitimate users. The software will become unresponsive to further calls.

Asterisk versions prior to 1.2.10 are vulnerable to this issue.

4. Armagetron Advanced Invalid Values Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 19015
Remote: Yes
Date Published: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19015
Summary:
Multiple denial of service vulnerabilities affect Armagetron Advanced.  These issues are due to a failure of the application to handle malformed network data.

An attacker may leverage these issues to cause a remote denial-of-service condition in affected applications.

5. Zoho Virtual Office Message HTML Injection Vulnerability
BugTraq ID: 19016
Remote: Yes
Date Published: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19016
Summary:
Zoho Virtual Office is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 3.2 Build 3210; other versions may also be vulnerable.

6. MySQL Server Date_Format Denial Of Service Vulnerability
BugTraq ID: 19032
Remote: Yes
Date Published: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19032
Summary:
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.

This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.

Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.

Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.

7. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Date Published: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

8. Wireshark Protocol Dissectors Multiple Vulnerabilities
BugTraq ID: 19051
Remote: Yes
Date Published: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19051
Summary:
Wireshark is prone to multiple vulnerabilities:

- A format string vulnerability.
- An off-by-one vulnerability.
- An infinite loop vulnerability.
- A memory allocation vulnerability.

These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.

9. VMware Information Disclosure Vulnerability
BugTraq ID: 19060
Remote: No
Date Published: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19060
Summary:
VMware is prone to an information-disclosure vulnerability.

This issue is due to insecure permissions being set on SSL key and certificate files.

If an attacker can gain access to SSL key files used to encrypt remote administrative connections, they can decrypt this traffic.

VMware Player for Linux, VMware Workstation for Linux, VMware Server for Linux and VMware Infrastructure 3 are reported to be vulnerable.

10. RETIRED: VMware SSL Key File Information Disclosure Weakness
BugTraq ID: 19062
Remote: No
Date Published: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19062
Summary:
VMware is prone to a weakness that may allow attackers to gain access to SSL key files.

A local attacker could subsequently gain access to the key file and use this to disclose sensitive information, which may aid in carrying out other attacks.

This weakness only arises on Linux platforms.

This BID has been retired as it is a duplicate of BID 19060.

11. FBGS PostScript Filter Bypass Vulnerability
BugTraq ID: 19131
Remote: No
Date Published: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19131
Summary:
The 'fbgs' utility is prone to a filter-bypass vulnerability. This issue occurs because the application fails to filter malicious PostScript commands properly.

An attacker can exploit this issue by deleting user data while displaying a PostScript file.

12. KDE Desktop Screensaver Lock Activation Failure Vulnerability
BugTraq ID: 19152
Remote: No
Date Published: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19152
Summary:
The KDE desktop is prone to a vulnerability that can cause the manual locking of the desktop to fail, or stop the screensaver from activating.

These issues could have a security impact if the user depends on the locking mechanism to secure the desktop.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com