SecurityFocus Linux Newsletter #323
[email protected] 7 Feb 2007 20:04:35 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #323
----------------------------------------
This Issue is Sponsored by: Watchfire
The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online des=
pite security executives' efforts to prevent malicious attacks. This whit=
epaper identifies the most common methods of attacks that we have seen, a=
nd outlines a guideline for developing secure web applications. Download =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008fG=
l
------------------------------------------------------------------
I. FRONT AND CENTER
1. PHP Security From The Inside
II. LINUX VULNERABILITY SUMMARY
1. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerabil=
ity
2. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vul=
nerability
3. Linux Kernel ListXATTR Local Denial of Service Vulnerability
4. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerabili=
ty
5. Computer Associates BrightStor ARCServe BackUp LGServer Remote =
Heap Buffer Overflow Vulnerability
6. Computer Associates BrightStor ARCServe BackUp LGServer Remote =
Stack Buffer Overflow Vulnerability
7. Gentoo Linux Acme Thttpd File Access Information Dislosure Vuln=
erability
8. Wireshark Multiple Protocol Denial of Service Vulnerabilities
9. Computer Associates BrightStor ARCserve Backup Catirpc.EXE Den=
ial Of Service Vulnerability
10. Mozilla Bugzilla HTML Injection And Information disclosure Vul=
nerabilities
11. PostgreSQL Information Disclosure and Denial of Service Vulner=
abilities
12. Samba Deferred CIFS File Open Denial of Service Vulnerability
13. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnera=
bility
14. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow =
Vulnerabilities
15. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnera=
bility
III. LINUX FOCUS LIST SUMMARY
1. administrator permissions mail server
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. PHP Security From The Inside
By Federico Biancuzzi
Stefan Esser is the founder of both the Hardened-PHP Project and the PHP =
Security Response Team (which he recently left). Federico Biancuzzi discu=
ssed with him how the PHP Security Response Team works, why he resigned f=
rom it, what features he plans to add to his own hardening patch, the int=
eraction between Apache and PHP, the upcoming "Month of PHP bugs" initiat=
ive, and common mistakes in the design of well-known applications such as=
WordPress.
http://www.securityfocus.com/columnists/432
2. Introduction to Windows Integrity Control
By Tony Bradley, CISSP-ISSAP
This article takes a look at the Windows Integrity Control (WIC) capabili=
ties in Windows Vista by examining how it protects objects such as files =
and folders on Vista computers, the different levels of protection it off=
ers, and how administrators can control WIC using the ICACLS command-line=
tool.
http://www.securityfocus.com/infocus/1887
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
BugTraq ID: 22289
Remote: Yes
Date Published: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22289
Summary:
The GD graphics library is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions =
in applications implementing the affected library. Arbitrary code executi=
on may also be possible; this has not been confirmed.
2. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 22308
Remote: Yes
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22308
Summary:
NX Server is prone to a denial-of-service vulnerability.
=20
An attacker can exploit this issue to crash the server, effectively denyi=
ng service to legitimate users.
=20
NX Server versions prior to 2.1.0-18 are vulnerable.
3. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.
Successful exploits will result in denial-of-service conditions or potent=
ially privilege escalation.
4. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
BugTraq ID: 22317
Remote: No
Date Published: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22317
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.
A local attacker can exploit this issue to corrupt data and cause the ker=
nel to become unresponsive, denying further service to legitimate users.
5. Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Bu=
ffer Overflow Vulnerability
BugTraq ID: 22340
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22340
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote heap-=
based buffer-overflow vulnerability because it fails to adequately bounds=
-checks user-supplied data prior to copying it to an insufficiently sized=
buffer.
A successful exploit will allow an attacker to execute arbitrary code wit=
h SYSTEM-level privileges.
Note that only applications on the Windows operating system are affected.
6. Computer Associates BrightStor ARCServe BackUp LGServer Remote Stack B=
uffer Overflow Vulnerability
BugTraq ID: 22342
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22342
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote stack=
-based buffer-overflow vulnerability because the application fails to pro=
perly bounds-check user-supplied data prior to copying it to an insuffici=
ently sized buffer.
A successful exploit will allow an attacker to execute arbitrary code wit=
h SYSTEM-level privileges.
Note that only applications on the Windows operating system are affected.
7. Gentoo Linux Acme Thttpd File Access Information Dislosure Vulnerabili=
ty
BugTraq ID: 22349
Remote: Yes
Date Published: 2007-01-31
Relevant URL: http://www.securityfocus.com/bid/22349
Summary:
Acme Thttpd distributed with Gentoo Linux is prone to a vulnerability tha=
t allows attackers to access arbitrary files. This issue is due to a conf=
iguration error.
=20
Remote attackers may exploit this issue to access arbitrary files that ar=
e readable by the 'thttpd' process. Information disclosed may lead to oth=
er attacks.
8. Wireshark Multiple Protocol Denial of Service Vulnerabilities
BugTraq ID: 22352
Remote: Yes
Date Published: 2007-02-01
Relevant URL: http://www.securityfocus.com/bid/22352
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may permit attackers to cause crashes and deny se=
rvice to legitimate users of the application.
Wireshark versions prior to 0.99.5 are affected.
9. Computer Associates BrightStor ARCserve Backup Catirpc.EXE Denial Of =
Service Vulnerability
BugTraq ID: 22365
Remote: Yes
Date Published: 2007-02-01
Relevant URL: http://www.securityfocus.com/bid/22365
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a denial-of=
-service vulnerability because the application mishandles unexpected user=
-supplied input.
=20
A remote attacker may exploit this issue to cause denial-of-service condi=
tions.
10. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabil=
ities
BugTraq ID: 22380
Remote: Yes
Date Published: 2007-02-03
Relevant URL: http://www.securityfocus.com/bid/22380
Summary:
Bugzilla is prone to an information-disclosure and an HTML-injection vuln=
erability because the application fails to properly sanitize user-supplie=
d input and to protect sensitive information from unauthorized users.
Attackers may exploit these issues to execute script code in the context =
of the affected site or to obtain sensitive information. Arbitrary code e=
xecution may allow attackers to steal cookie-based authentication credent=
ials or to control how the site is rendered to the user. Other attacks ar=
e also possible.
Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerabilit=
y; only the development snapshot version 2.23.3 is vulnerable to the inf=
ormation-disclosure issue.
11. PostgreSQL Information Disclosure and Denial of Service Vulnerabiliti=
es
BugTraq ID: 22387
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulne=
rabilities; fixes are available.
An attacker can exploit these vulnerabilities to cause the backend databa=
se to crash and reveal sensitive information. This may lead to other atta=
cks.=20
These issues affect versions 8.0, 8.1, and 8.2. The second issue describ=
ed also affects version 7.3 and 7.4.
12. Samba Deferred CIFS File Open Denial of Service Vulnerability
BugTraq ID: 22395
Remote: No
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22395
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume excessive memory resources,=
ultimately crashing the affected application.
This issue affects Samba versions 3.0.6 through 3.0.23d, inclusive.
13. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
BugTraq ID: 22403
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22403
Summary:
Samba is prone to a remote format-string vulnerability because the applic=
ation fails to properly sanitize user-supplied input before including it =
in the format-specifier argument of a formatted-printing function.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of users running the affected applicat=
ion. This facilitates the remote compromise of affected computers.
Samba versions 3.06 to 3.0.23d are vulnerable.
14. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnera=
bilities
BugTraq ID: 22410
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22410
Summary:
Samba is prone to multiple remote buffer-overflow vulnerabilities because=
the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20
An attacker may exploit these issues to execute arbitrary code with super=
user privileges, completely compromising affected computers. Failed explo=
it attempts will result in a denial of service.
=20
These issues affects versions 3.0.21 to 3.0.23d.
15. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BugTraq ID: 22428
Remote: Yes
Date Published: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22428
Summary:
Konquerer is prone to a cross-site scripting vulnerability because the ap=
plication fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentica=
tion credentials and launch other attacks.
All versions of KDE up to and including KDE 3.5.6 are vulnerable to this =
issue. Apple Safari web browser is also vulnerable to this issue.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online des=
pite security executives' efforts to prevent malicious attacks. This whit=
epaper identifies the most common methods of attacks that we have seen, a=
nd outlines a guideline for developing secure web applications. Download =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008fG=
l