SecurityFocus Linux Newsletter #323

[email protected] 7 Feb 2007 20:04:35 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #323
----------------------------------------

This Issue is Sponsored by: Watchfire

The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online des=
pite security executives' efforts to prevent malicious attacks. This whit=
epaper identifies the most common methods of attacks that we have seen, a=
nd outlines a guideline for developing secure web applications. Download =
today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008fG=
l

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. PHP Security From The Inside
II.  LINUX VULNERABILITY SUMMARY
       1. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerabil=
ity
       2. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vul=
nerability
       3. Linux Kernel ListXATTR Local Denial of Service Vulnerability
       4. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerabili=
ty
       5. Computer Associates BrightStor ARCServe BackUp LGServer Remote =
Heap Buffer Overflow Vulnerability
       6. Computer Associates BrightStor ARCServe BackUp LGServer Remote =
Stack Buffer Overflow Vulnerability
       7. Gentoo Linux Acme Thttpd File Access Information Dislosure Vuln=
erability
       8. Wireshark Multiple Protocol Denial of Service Vulnerabilities
       9. Computer Associates BrightStor ARCserve Backup  Catirpc.EXE Den=
ial Of Service Vulnerability
       10. Mozilla Bugzilla HTML Injection And Information disclosure Vul=
nerabilities
       11. PostgreSQL Information Disclosure and Denial of Service Vulner=
abilities
       12. Samba Deferred CIFS File Open Denial of Service Vulnerability
       13. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnera=
bility
       14. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow =
Vulnerabilities
       15. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnera=
bility
III. LINUX FOCUS LIST SUMMARY
       1. administrator permissions mail server
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. PHP Security From The Inside
By Federico Biancuzzi
Stefan Esser is the founder of both the Hardened-PHP Project and the PHP =
Security Response Team (which he recently left). Federico Biancuzzi discu=
ssed with him how the PHP Security Response Team works, why he resigned f=
rom it, what features he plans to add to his own hardening patch, the int=
eraction between Apache and PHP, the upcoming "Month of PHP bugs" initiat=
ive, and common mistakes in the design of well-known applications such as=
 WordPress.
http://www.securityfocus.com/columnists/432

2. Introduction to Windows Integrity Control
By Tony Bradley, CISSP-ISSAP
This article takes a look at the Windows Integrity Control (WIC) capabili=
ties in Windows Vista by examining how it protects objects such as files =
and folders on Vista computers, the different levels of protection it off=
ers, and how administrators can control WIC using the ICACLS command-line=
 tool.
http://www.securityfocus.com/infocus/1887


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
BugTraq ID: 22289
Remote: Yes
Date Published: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22289
Summary:
The GD graphics library is prone to a buffer-overflow vulnerability.

An attacker can exploit this issue to cause denial-of-service conditions =
in applications implementing the affected library. Arbitrary code executi=
on may also be possible; this has not been confirmed.

2. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 22308
Remote: Yes
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22308
Summary:
NX Server is prone to a denial-of-service vulnerability.
=20
An attacker can exploit this issue to crash the server, effectively denyi=
ng service to legitimate users.
=20
NX Server versions prior to 2.1.0-18 are vulnerable.

3. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

Successful exploits will result in denial-of-service conditions or potent=
ially privilege escalation.

4. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
BugTraq ID: 22317
Remote: No
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22317
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A local attacker can exploit this issue to corrupt data and cause the ker=
nel to become unresponsive, denying further service to  legitimate users.

5. Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Bu=
ffer Overflow Vulnerability
BugTraq ID: 22340
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22340
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote heap-=
based buffer-overflow vulnerability because it fails to adequately bounds=
-checks user-supplied data prior to copying it to an insufficiently sized=
 buffer.

A successful exploit will allow an attacker to execute arbitrary code wit=
h SYSTEM-level privileges.

Note that only applications on the Windows operating system are affected.

6. Computer Associates BrightStor ARCServe BackUp LGServer Remote Stack B=
uffer Overflow Vulnerability
BugTraq ID: 22342
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22342
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote stack=
-based buffer-overflow vulnerability because the application fails to pro=
perly bounds-check user-supplied data prior to copying it to an insuffici=
ently sized buffer.

A successful exploit will allow an attacker to execute arbitrary code wit=
h SYSTEM-level privileges.

Note that only applications on the Windows operating system are affected.

7. Gentoo Linux Acme Thttpd File Access Information Dislosure Vulnerabili=
ty
BugTraq ID: 22349
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22349
Summary:
Acme Thttpd distributed with Gentoo Linux is prone to a vulnerability tha=
t allows attackers to access arbitrary files. This issue is due to a conf=
iguration error.
=20
Remote attackers may exploit this issue to access arbitrary files that ar=
e readable by the 'thttpd' process. Information disclosed may lead to oth=
er attacks.

8. Wireshark Multiple Protocol Denial of Service Vulnerabilities
BugTraq ID: 22352
Remote: Yes
Date Published: 2007-02-01
Relevant URL: http://www.securityfocus.com/bid/22352
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues may permit attackers to cause crashes and deny se=
rvice to legitimate users of the application.

Wireshark versions prior to 0.99.5 are affected.

9. Computer Associates BrightStor ARCserve Backup  Catirpc.EXE Denial Of =
Service Vulnerability
BugTraq ID: 22365
Remote: Yes
Date Published: 2007-02-01
Relevant URL: http://www.securityfocus.com/bid/22365
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a denial-of=
-service vulnerability because the application mishandles unexpected user=
-supplied input.
=20
A remote attacker may exploit this issue to cause denial-of-service condi=
tions.

10. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabil=
ities
BugTraq ID: 22380
Remote: Yes
Date Published: 2007-02-03
Relevant URL: http://www.securityfocus.com/bid/22380
Summary:
Bugzilla is prone to an information-disclosure and an HTML-injection vuln=
erability because the application fails to properly sanitize user-supplie=
d input and to protect sensitive information from unauthorized users.

Attackers may exploit these issues to execute script code in the context =
of the affected site or to obtain sensitive information. Arbitrary code e=
xecution may allow attackers to steal cookie-based authentication credent=
ials or to control how the site is rendered to the user. Other attacks ar=
e also possible.

Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerabilit=
y; only the development snapshot version 2.23.3  is vulnerable to the inf=
ormation-disclosure issue.

11. PostgreSQL Information Disclosure and Denial of Service Vulnerabiliti=
es
BugTraq ID: 22387
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulne=
rabilities; fixes are available.

An attacker can exploit these vulnerabilities to cause the backend databa=
se to crash and reveal sensitive information. This may lead to other atta=
cks.=20

 These issues affect versions 8.0, 8.1, and 8.2. The second issue describ=
ed also affects version 7.3 and 7.4.

12. Samba Deferred CIFS File Open Denial of Service Vulnerability
BugTraq ID: 22395
Remote: No
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22395
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources,=
 ultimately crashing the affected application.

This issue affects Samba versions 3.0.6 through 3.0.23d, inclusive.

13. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
BugTraq ID: 22403
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22403
Summary:
Samba is prone to a remote format-string vulnerability because the applic=
ation fails to properly sanitize user-supplied input before including it =
in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of users running the affected applicat=
ion. This facilitates the remote compromise of affected computers.

Samba versions 3.06 to 3.0.23d are vulnerable.

14. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnera=
bilities
BugTraq ID: 22410
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22410
Summary:
Samba is prone to multiple remote buffer-overflow vulnerabilities because=
 the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20

An attacker may exploit these issues to execute arbitrary code with super=
user privileges, completely compromising affected computers. Failed explo=
it attempts will result in a denial of service.
=20
These issues affects versions 3.0.21 to 3.0.23d.

15. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BugTraq ID: 22428
Remote: Yes
Date Published: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22428
Summary:
Konquerer is prone to a cross-site scripting vulnerability because the ap=
plication fails to sufficiently sanitize user-supplied data.

Exploiting this issue may help the attacker steal cookie-based authentica=
tion credentials and launch other attacks.

All versions of KDE up to and including KDE 3.5.6 are vulnerable to this =
issue. Apple Safari web browser is also vulnerable to this issue.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online des=
pite security executives' efforts to prevent malicious attacks. This whit=
epaper identifies the most common methods of attacks that we have seen, a=
nd outlines a guideline for developing secure web applications. Download =
today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008fG=
l