SecurityFocus Linux Newsletter #320

[email protected] 17 Jan 2007 00:27:05 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #320
----------------------------------------

This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts.
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.
Network with 400 delegates from 25 nations, and see solutions from major sponsors.

http://www.blackhat.com

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Interview with Bill Cheswick
       2. Wireless Forensics: Tapping the Air - Part Two
II.  LINUX VULNERABILITY SUMMARY
       1. Kaspersky AntiVirus Scan Engine PE File Denial Of Service Vulnerability
       2. Fetchmail Remote Denial of Service Vulnerability
       3. Fetchmail Multiple Password Information Disclosure Vulnerabilities
       4. WordPress Charset Decoding SQL Injection Vulnerability
       5. CenterICQ IJHook.CC Remote Buffer Overflow Vulnerability
       6. X.Org DBE And Render Extensions Multiple Integer Overflow Vulnerabilities
       7. MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
       8. MIT Kerberos Administration Daemon Free Pointers Remote Code Execution Vulnerability
       9. Secure Locate Local Information Disclosure Vulnerability
       10. Snort Backtracking Denial of Service Vulnerability
       11. Snort GRE Packet Decoding Integer Underflow Vulnerability
       12. CA BrightStor ARCserve Backup Message Engine/Tape Engine Remote Buffer Overflow Vulnerability
       13. CA BrightStor ARCserve Backup Tape Engine TCP 6502 Remote Buffer Overflow Vulnerability
       14. Computer Associates BrightStor ARCServe BackUp Tape Engine Remote Code Execution Vulnerability
       15. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE Remote Buffer Overflow Vulnerability
       16. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE Variant Buffer Overflow Vulnerability
       17. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
       18. Neon LibNeon Non-Ascii Character URI Data Denial Of Service Vulnerability
       19. Libgtop2 Library Local Buffer Overflow Vulnerability
       20. FileZilla Multiple Remote Format String Vulnerabilities
       21. BlueZ HIDD Bluetooh HID Command Injection Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. SF new article announcement: Wireless Forensics: Tapping the Air - Part Two (fwd)
       2. SF new column announcement: PHP apps - Security's Low-Hanging Fruit (fwd)
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Interview with Bill Cheswick
By Federico Biancuzzi
Many people have seen Internet maps on walls and in various publications over the years. Federico Biancuzzi interviewed Bill Cheswick, who started the Internet Mapping Project that grew into software to map corporate and government networks. They discussed firewalling, logging, NIDS and IPS, how to fight DDoS, and the future of BGP and DNS.
http://www.securityfocus.com/columnists/429

2. Wireless Forensics: Tapping the Air - Part Two
By Raul Siles, GSE
This two-part series looks at the issues associated with collecting and analyzing network traffic from wireless networks in an accurate and comprehensive way; a discipline known as wireless forensics. Part two focuses on the technical challenges for wireless traffic analysis, advanced anti-forensic techniques that could thwart a forensic investigation, and some legal considerations for both the U.S. and Europe.
http://www.securityfocus.com/infocus/1885


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Kaspersky AntiVirus Scan Engine PE File Denial Of Service Vulnerability
BugTraq ID: 21901
Remote: Yes
Date Published: 2007-01-06
Relevant URL: http://www.securityfocus.com/bid/21901
Summary:
Kaspersky Antivirus is prone to a denial-of-service vulnerability. This issue occurs because the application fails to handle specially crafted portable executable (PE) files.

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

2. Fetchmail Remote Denial of Service Vulnerability
BugTraq ID: 21902
Remote: Yes
Date Published: 2007-01-06
Relevant URL: http://www.securityfocus.com/bid/21902
Summary:
Fetchmail is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions. 

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

3. Fetchmail Multiple Password Information Disclosure Vulnerabilities
BugTraq ID: 21903
Remote: Yes
Date Published: 2007-01-06
Relevant URL: http://www.securityfocus.com/bid/21903
Summary:
Fetchmail is prone to multiple information-disclosure vulnerabilities because the application discloses information about user passwords.

An attacker can exploit these issue to access sensitive information that may aid the attacker in other attacks.

These issues affect versions prior to 6.3.6-rc4

4. WordPress Charset Decoding SQL Injection Vulnerability
BugTraq ID: 21907
Remote: Yes
Date Published: 2007-01-06
Relevant URL: http://www.securityfocus.com/bid/21907
Summary:
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

WordPress 2.0.5 and prior versions are vulnerable.

5. CenterICQ IJHook.CC Remote Buffer Overflow Vulnerability
BugTraq ID: 21932
Remote: Yes
Date Published: 2007-01-08
Relevant URL: http://www.securityfocus.com/bid/21932
Summary:
CenterICQ is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.  

This issue affects versions 4.9.11 up to 4.21.0.

6. X.Org DBE And Render Extensions Multiple Integer Overflow Vulnerabilities
BugTraq ID: 21968
Remote: No
Date Published: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21968
Summary:
X.Org is prone to multiple integer-overflow vulnerabilities.

Attackers can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will likely result in denial-of-service conditions.

7. MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
BugTraq ID: 21970
Remote: Yes
Date Published: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21970
Summary:
MIT Kerberos 5 is prone to a remote code-execution vulnerability. This issue resides in the server-side portion of the Kerberos RPC library. Currently, the 'kadmind' service is known to be vulnerable, but other applications that use this library may also be affected.

An attacker can exploit this issue to execute arbitrary code with administrative privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service. After a Kerberos database computer has been compromised, attackers may gain unauthorized access to
other services that rely on the Kerberos infrastructure for authentication.

8. MIT Kerberos Administration Daemon Free Pointers Remote Code Execution Vulnerability
BugTraq ID: 21975
Remote: Yes
Date Published: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21975
Summary:
MIT Kerberos 5 is prone to a remote code-execution vulnerability.

This issue occurs because of memory-management problems in the abstraction interface of the GSS-API implementation.

An attacker can exploit this issue to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will likely result in a denial-of-service conditions.

This issue also affects third-party applications using the affected API.

9. Secure Locate Local Information Disclosure Vulnerability
BugTraq ID: 21989
Remote: No
Date Published: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21989
Summary:
Secure Locate is prone to a local information-disclosure vulnerability because the utility fails to properly interpret filesystem permissions.
 
 Successfully exploiting this issue allows attackers to gain access to the names of files located in directories they do not have permissions to access. Information that attackers harvest may aid them in further attacks.
 
 Secure Locate 3.1 is vulnerable to this issue; other versions may also be affected.

10. Snort Backtracking Denial of Service Vulnerability
BugTraq ID: 21991
Remote: Yes
Date Published: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21991
Summary:
Snort is prone to a denial-of-service vulnerability because the network intrusion detection (NID) system fails to handle specially crafted network packets. 

An attacker can exploit this issue to cause the affected NID system to consume 100% CPU resources, allowing malicious network traffic to avoid detection.

This issue affects versions prior to 2.6.1.

11. Snort GRE Packet Decoding Integer Underflow Vulnerability
BugTraq ID: 22004
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22004
Summary:
Snort is prone to a denial-of-service vulnerability because the network intrusion detection (NID) system fails to handle specially crafted network packets. 

An attacker can exploit this issue to corrupt the application's log files and possibly to crash the application (depending on its memory layout).

12. CA BrightStor ARCserve Backup Message Engine/Tape Engine Remote Buffer Overflow Vulnerability
BugTraq ID: 22005
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22005
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions. Successful exploits can lead to a complete compromise of affected computers.

This issue affects multiple BrightStor ARCserve Backup application agents and the base product.

13. CA BrightStor ARCserve Backup Tape Engine TCP 6502 Remote Buffer Overflow Vulnerability
BugTraq ID: 22006
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22006
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions.

14. Computer Associates BrightStor ARCServe BackUp Tape Engine Remote Code Execution Vulnerability
BugTraq ID: 22010
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22010
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote code-execution vulnerability due to a design error in the Tape Engine service.

A successful exploit will allow an attacker to execute arbitrary code with SYSTEM-level privileges.

Note that only applications on the Windows operating system are affected.

15. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE Remote Buffer Overflow Vulnerability
BugTraq ID: 22015
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22015
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote stack-based buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions.

NOTE: User interaction is not required to exploit this vulnerability.

16. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE Variant Buffer Overflow Vulnerability
BugTraq ID: 22016
Remote: Yes
Date Published: 2007-01-11
Relevant URL: http://www.securityfocus.com/bid/22016
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote stack-based buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions.

NOTE: User interaction is not required to exploit this vulnerability. 

Although this BID closely resembles BID 22015, it is a separate vulnerability.

17. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
BugTraq ID: 22034
Remote: Yes
Date Published: 2007-01-12
Relevant URL: http://www.securityfocus.com/bid/22034
Summary:
The Libsoup library is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input.

Attackers may exploit this vulnerability to crash an application that relies on the affected library, resulting in a denial-of-service condition.

18. Neon LibNeon Non-Ascii Character URI Data Denial Of Service Vulnerability
BugTraq ID: 22035
Remote: Yes
Date Published: 2007-01-12
Relevant URL: http://www.securityfocus.com/bid/22035
Summary:
The Neon Library is prone to a remote denial-of-service vulnerability. 

This issue occurs when parsing URI data containing non-ASCII characters. 

An attacker can exploit this vulnerability to crash the library, effectively denying service to legitimate users.

Versions 0.26 to 0.26.2 are vulnerable; other versions may also be affected.

NOTE: Only 64-bit systems are affected.

19. Libgtop2 Library Local Buffer Overflow Vulnerability
BugTraq ID: 22054
Remote: No
Date Published: 2007-01-15
Relevant URL: http://www.securityfocus.com/bid/22054
Summary:
Libgtop2 library is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying into an insufficiently sized memory buffer.

An attacker may exploit this issue by enticing victims into viewing a maliciously crafted system process with an application that uses the affected library.

Successful exploits may cause arbitrary code to run with the privileges of the victim. Failed exploit attempts will likely cause denial-of-service conditions.

Versions prior to 2.14.6 are reported vulnerable.

20. FileZilla Multiple Remote Format String Vulnerabilities
BugTraq ID: 22063
Remote: Yes
Date Published: 2007-01-15
Relevant URL: http://www.securityfocus.com/bid/22063
Summary:
FileZilla is prone to multiple remote format-string vulnerabilities because the application fails to properly sanitize user-supplied input before using it in the format-specifier argument to a formatted-printing function.

Exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application.

FileZilla 3 versions prior to beta 5 are vulnerable to these issues.

21. BlueZ HIDD Bluetooh HID Command Injection Vulnerability
BugTraq ID: 22076
Remote: Yes
Date Published: 2007-01-16
Relevant URL: http://www.securityfocus.com/bid/22076
Summary:
BlueZ hidd is prone to a device-command-injection vulnerability.

A remote attacker can exploit this issue to gain control of mouse and keyboard HIDs (human interface device). This will allow the attacker to interact with the targeted computer in the context of the currently logged-in user.

Versions prior to 2.25 are vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. SF new article announcement: Wireless Forensics: Tapping the Air - Part Two (fwd)
http://www.securityfocus.com/archive/91/456372

2. SF new column announcement: PHP apps - Security's Low-Hanging Fruit (fwd)
http://www.securityfocus.com/archive/91/456371

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts.
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.
Network with 400 delegates from 25 nations, and see solutions from major sponsors.

http://www.blackhat.com