SecurityFocus Linux Newsletter #299

Conrad Schilbe <[email protected]> Wed, 16 Aug 2006 12:15:33 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #299
----------------------------------------

Are Your IIS Web Servers Under Attack?

Monitor IIS activity and block all unwanted traffic. ThreatSentry Host IPS + Application Firewall protects IIS against new and progressive attack techniques and delivers affordable defense-in-depth. $399 per server. Free 30-day trial.

http://newsletter.industrybrains.com/c?fe;3;53120;4d8;250;1e60;da4

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Dynamic Linking in Linux and Windows, part two
II.  LINUX VULNERABILITY SUMMARY
       1. DConnect Daemon Listen Thread UDP Remote Buffer Overflow Vulnerability
       2. DConnect Daemon DC Chat Denial of Service Vulnerability
       3. DConnect Daemon Multiple Format String Vulnerabilities
       4. Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
       5. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
       6. XChat Remote Denial of Service Vulnerability
       7. MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities
       8. LessTif Debug Feature Local Arbitrary File Creation Vulnerability
       9. Drupal Bibliography Multiple Input Validation Vulnerabilities
       10. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
       11. Gallery Stats Module Information Disclosure Vulnerability
       12. Ruby on Rails Routing Denial of Service Vulnerability
       13. NCompress Decompress Buffer Underflow Vulnerability
       14. YaBBSE Index.PHP Cross-Site Scripting Vulnerability
       15. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
       16. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities 
       17. Opera Web Browser IRC Chat Client Remote Denial of Service Vulnerability
       18. Novell eDirectory Unspecified Nessus Denial of Service Vulnerability
       19. Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
       20. Linux-HA Heartbeat Remote Denial of Service Vulnerability
       21. PHProjekt Multiple Remote File Include Vulnerabilities
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Dynamic Linking in Linux and Windows, part two
By Reji Thomas and Bhasker Reddy
This article discusses the shared libraries concept in both Windows and Linux, and offers a walk through various data structures to explain how dynamic linking is done in these operating systems.
http://www.securityfocus.com/infocus/1873


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. DConnect Daemon Listen Thread UDP Remote Buffer Overflow Vulnerability
BugTraq ID: 19369
Remote: Yes
Date Published: 2006-08-06
Relevant URL: http://www.securityfocus.com/bid/19369
Summary:
DConnect Daemon is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary code within the context of the application or cause the application to crash causing a denial of service. 

Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.

2. DConnect Daemon DC Chat Denial of Service Vulnerability
BugTraq ID: 19370
Remote: Yes
Date Published: 2006-08-06
Relevant URL: http://www.securityfocus.com/bid/19370
Summary:
DConnect Daemon is prone to a denial-of-service vulnerability. 

This issue occurs because the application fails to handle null-pointer exceptions properly. 

An attacker can exploit this issue to crash the server, causing a denial-of-service.

Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.

3. DConnect Daemon Multiple Format String Vulnerabilities
BugTraq ID: 19371
Remote: Yes
Date Published: 2006-08-06
Relevant URL: http://www.securityfocus.com/bid/19371
Summary:
DConnect Daemon is prone to multiple remote format-string because the application fails to sanitize user-supplied input before passing it to a formatted-output function. 

An attacker can exploit these issues to execute arbitrary code within the context of the server.

Version 0.7.0, CVS July 30, 2006 and prior versions are vulnerable to this issue.

4. Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
BugTraq ID: 19381
Remote: Yes
Date Published: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19381
Summary:
ClamAV is prone to a heap buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer. 

This issue occurs when the application attempts to handle compressed UPX files. 

Exploiting this issue could allow attacker-supplied machine code to execute in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.

ClamAV versions 0.88.2 and 0.88.3 are vulnerable to this issue; prior versions may also be affected.

5. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Date Published: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

6. XChat Remote Denial of Service Vulnerability
BugTraq ID: 19398
Remote: Yes
Date Published: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19398
Summary:
XChat is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected data from malicious IRC users.

This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers send malformed data to unsuspecting users.

XChat version 2.6.7 for Windows is vulnerable to this issue; other versions and platforms may also be affected.

NOTE: The vendor refutes this issue, stating that the exploit has no affect on XChat.

7. MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities
BugTraq ID: 19427
Remote: No
Date Published: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19427
Summary:
MIT Kerberos 5 is prone to multiple local privilege-escalation vulnerabilities because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels or with AIX operating systems.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

8. LessTif Debug Feature Local Arbitrary File Creation Vulnerability
BugTraq ID: 19430
Remote: No
Date Published: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19430
Summary:
LessTif is prone to a local arbitrary file-creation vulnerability. This issue is exposed when an application using the affected library runs with setuid-privileges.

This issue presents itself only when the library is compiled without the 'LESSTIF_PRODUCTION' definition. This occurs when the '--enable-production' configuration option is not selected when the package is built.

When used in conjunction with the 'mtink' binary, exploiting this issue has been demonstrated to gain superuser privileges.

LessTif version 0.93.94 is vulnerable to this issue; other versions may also be affected.

9. Drupal Bibliography Multiple Input Validation Vulnerabilities
BugTraq ID: 19441
Remote: Yes
Date Published: 2006-08-09
Relevant URL: http://www.securityfocus.com/bid/19441
Summary:
Drupal Bibliography module is prone to multiple input-validation vulnerabilities, incuding multiple cross-site scripting and SQL-injection issues, because the application fails to properly sanitize user-supplied input. 

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

Versions prior to 4.6 and 4.7 are vulnerable; other versions may also be affected.

10. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19450
Remote: Yes
Date Published: 2006-08-09
Relevant URL: http://www.securityfocus.com/bid/19450
Summary:
AlsaPlayer is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer. 

An attacker can exploit these issues to execute arbitrary code within the context of the application or cause a denial-of-service condition. 

AlsaPlayer 0.99.76, the CVS version as of 9 Aug 2006, and prior versions are vulnerable to this issue; other versions may also be affected.

11. Gallery Stats Module Information Disclosure Vulnerability
BugTraq ID: 19453
Remote: Yes
Date Published: 2006-08-09
Relevant URL: http://www.securityfocus.com/bid/19453
Summary:
Gallery is prone to an information-disclosure vulnerability because it fails to protect sensitive information. 

An attacker can exploit this issue to gain sensitive information, which could lead to other attacks.

12. Ruby on Rails Routing Denial of Service Vulnerability
BugTraq ID: 19454
Remote: Yes
Date Published: 2006-08-09
Relevant URL: http://www.securityfocus.com/bid/19454
Summary:
Ruby on Rails is prone to a vulnerability in its routing functionality that may result in denial-of-service or data loss issues.

Attackers may exploit this issue by issuing HTTP GET requests to predictable URIs to affected webservers.

This issue affects Ruby on Rails versions 1.1.0, 1.1.1, 1.1.2, 1.1.4, and 1.1.5.

13. NCompress Decompress Buffer Underflow Vulnerability
BugTraq ID: 19455
Remote: Yes
Date Published: 2006-08-09
Relevant URL: http://www.securityfocus.com/bid/19455
Summary:
The ncompress utility is prone to a buffer-underflow vulnerability. When ncompress decompresses data, it fails to perform appropriate bounds checking, which may allow certain decompress operations to underflow an internal buffer. This may cause unpredictable effects on vulnerable systems. 

Version 4.2.4 is reportedly vulnerable to this issue; earlier versions may be affected as well.

14. YaBBSE Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19460
Remote: Yes
Date Published: 2006-08-10
Relevant URL: http://www.securityfocus.com/bid/19460
Summary:
A cross-site scripting vulnerability affects YaBBSE because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

15. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
BugTraq ID: 19475
Remote: Yes
Date Published: 2006-08-10
Relevant URL: http://www.securityfocus.com/bid/19475
Summary:
The Linux kernel is prone to an unspecified remote denial-of-service vulnerability.

This issue allows remote attackers to cause kernel panics, denying service to legitimate users.

No further information is currently available. This BID will be updated as more information is released.

Specific version information is currently unavailable. Kernel versions in the 2.6 series are currently considered vulnerable.

16. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities 
BugTraq ID: 19486
Remote: Yes
Date Published: 2006-08-11
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and data-modification vulnerabilities because the application fails to properly sanitize user-supplied input.

Successful exploits may allow an authenticated remote attacker to read and write email attachments or preferences from other users. This may lead to other attacks.

17. Opera Web Browser IRC Chat Client Remote Denial of Service Vulnerability
BugTraq ID: 19491
Remote: Yes
Date Published: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19491
Summary:
Opera Web Browser IRC chat client is prone to a remote denial-of-service vulnerability. 

A successful attack can allow the attacker to trigger a crash in the client and deny service to legitimate users. 

This issue affects Opera Web Browser 9. Other versions may be vulnerable as well.

18. Novell eDirectory Unspecified Nessus Denial of Service Vulnerability
BugTraq ID: 19498
Remote: Yes
Date Published: 2006-08-11
Relevant URL: http://www.securityfocus.com/bid/19498
Summary:
The Novell eDirectory Server is prone to an unspecified denial-of-service vulnerability. The system experiences high CPU usage when it is subjected to a Nessus scan. 

The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.

19. Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
BugTraq ID: 19499
Remote: Yes
Date Published: 2006-08-11
Relevant URL: http://www.securityfocus.com/bid/19499
Summary:
The Novell eDirectory Server is prone to an information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.

The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.

20. Linux-HA Heartbeat Remote Denial of Service Vulnerability
BugTraq ID: 19516
Remote: Yes
Date Published: 2006-08-13
Relevant URL: http://www.securityfocus.com/bid/19516
Summary:
Linux-HA Heartbeat is prone to a remote denial-of-service vulnerability.

Successfully exploiting this issue results in crashing the master control process. This may result in the failure of services depending on the application's functionality.

21. PHProjekt Multiple Remote File Include Vulnerabilities
BugTraq ID: 19541
Remote: Yes
Date Published: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19541
Summary:
Multiple remote file include vulnerabilities affect PHProjekt. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in a PHP 'include()' function call. 

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. 

Version 5.1 of PHProjekt is vulnerable to this issue; previous versions may be affected as well.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
Are Your IIS Web Servers Under Attack?

Monitor IIS activity and block all unwanted traffic. ThreatSentry Host IPS + Application Firewall protects IIS against new and progressive attack techniques and delivers affordable defense-in-depth. $399 per server. Free 30-day trial.

http://newsletter.industrybrains.com/c?fe;3;53120;4d8;250;1e60;da4