SecurityFocus Linux Newsletter #302

Peter Laborge <[email protected]> Tue, 05 Sep 2006 16:39:57 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #302
----------------------------------------

This Issue is Sponsored By: Qualys

Free One-Time PCI Scan
Qualys PCI compliance solution - starting at $495 per year. Qualys' solution enables online merchants and service providers to self certify for the Payment Card Industy (PCI) Data Security Standard. Get a Free PCI Report on one External Facing IP.

http://newsletter.industrybrains.com/c?fe;1;5e792;ddf3;264;1e60;da4

------------------------------------------------------------------
I.   FRONT AND CENTER
        1. Disclosure survey
II.  LINUX VULNERABILITY SUMMARY
        1. Cybozu Garoon Multiple SQL Injection Vulnerabilities
        2. Xbiff 2 Insecure Permissions Information Disclosure Vulnerability
        3. GTetrinet Index Out of Bounds Unspecified Remote Code Execution Vulnerability
        4. Lyris ListManager Unauthorized Administrative User Addition Vulnerability
        5. CAPI4Hylafax Remote Arbitrary Command Execution Vulnerability
        6. Webmin and Usermin HTML Injection and Information Disclosure Vulnerability
        7. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
III. LINUX FOCUS LIST SUMMARY
        1. Write-protect sctors?
        2. Write-protect sctors?
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Disclosure survey
By Federico Biancuzzi
Federico Biancuzzi surveys statements from some of the world's largest software companies about vulnerability disclosure, interviews two security companies who pay for vulnerabilities, and then talks with three prominent, independent researchers about their thoughts on choosing a responsible disclosure process. In three parts.
http://www.securityfocus.com/columnists/415


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Cybozu Garoon Multiple SQL Injection Vulnerabilities
BugTraq ID: 19731
Remote: Yes
Date Published: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19731
Summary:
Cybozu Garoon is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database implementation, or gain administrative access to the application.

These issues affect versions prior to 2.1.1.

2. Xbiff 2 Insecure Permissions Information Disclosure Vulnerability
BugTraq ID: 19762
Remote: No
Date Published: 2006-08-30
Relevant URL: http://www.securityfocus.com/bid/19762
Summary:
Xbiff 2 is prone to an information-disclosure vulnerability due to insecure file permissions.

A successful attack can allow a local attacker to retrieve credentials and potentially gain access to a user's mail. This could lead to other attacks as well.

Xbiff 2 version 1.9 for Linux is reportedly vulnerable; other versions may be affected as well.

3. GTetrinet Index Out of Bounds Unspecified Remote Code Execution Vulnerability
BugTraq ID: 19766
Remote: Yes
Date Published: 2006-08-30
Relevant URL: http://www.securityfocus.com/bid/19766
Summary:
GTetrinet is prone to an unspecified remote vulnerability. This issue is reportedly due to multiple out-of-bounds index-access flaws.

A remote attacker may exploit this issue to execute arbitrary machine code on the affected computer with the privileges of the user running the vulnerable application.

Very little information is currently available on this vulnerability. This BID will be updated as more information becomes available.

4. Lyris ListManager Unauthorized Administrative User Addition Vulnerability
BugTraq ID: 19784
Remote: Yes
Date Published: 2006-08-30
Relevant URL: http://www.securityfocus.com/bid/19784
Summary:
Lyris ListManager is prone to a design flaw that facilitates the addition of an unauthorized administrative user. The issue derives from the use of hidden form fields in the 'add administrator' form.

Attackers with administrative privileges to a Lyris list may exploit this vulnerability to add administrative users to arbitrary lists hosted on the same server. For example, an administrator for List-A can maliciously modify hidden form fields when conventionally adding an administrative user, causing that user to be added as an administrator to List-B.

Version 8.95 is vulnerable; other versions may also be affected.

5. CAPI4Hylafax Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 19801
Remote: Yes
Date Published: 2006-09-01
Relevant URL: http://www.securityfocus.com/bid/19801
Summary:
CAP4Hylafax is prone to an arbitrary command-execution vulnerability.

An attacker can exploit this vulnerability to execute arbitrary commands in the context of the affected application.

6. Webmin and Usermin HTML Injection and Information Disclosure Vulnerability
BugTraq ID: 19820
Remote: Yes
Date Published: 2006-09-02
Relevant URL: http://www.securityfocus.com/bid/19820
Summary:
Webmin and Usermin are prone to a HTML-injection and information disclosure vulnerability.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user and gain sensitive information.

Usermin versions prior to 1.226 and Webmin versions prior to 1.296 are vulnerable to this issue.

7. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Date Published: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is susceptible to a vulnerability that may allow an RSA signature to be forged. It is possible to forge a PKCS #1 v1.5 signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships which depend on these credentials. Possibly posing as a trusted party and signing a certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are affected by this vulnerability. Updates are available.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Write-protect sctors?
http://www.securityfocus.com/archive/91/444603

2. Write-protect sctors?
http://www.securityfocus.com/archive/91/444500

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------

This Issue is Sponsored By: Qualys

Free One-Time PCI Scan
Qualys PCI compliance solution - starting at $495 per year. Qualys' solution enables online merchants and service providers to self certify for the Payment Card Industy (PCI) Data Security Standard. Get a Free PCI Report on one External Facing IP.

http://newsletter.industrybrains.com/c?fe;1;5e792;ddf3;264;1e60;da4