SecurityFocus Linux Newsletter #324

[email protected] 14 Feb 2007 00:41:05 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #324
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving hackers complete access to all your backend systems! Firewalls =
and IDS will not stop such attacks because SQL Injections are NOT seen as=
 intruders. Download this *FREE* white paper from SPI Dynamics for a comp=
lete guide to protection!=20

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Ci=
NE

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Mouse-Trapped
       2. Nothing to Fear... ?
II.  LINUX VULNERABILITY SUMMARY
       1. Mozilla Bugzilla HTML Injection And Information disclosure Vuln=
erabilities
       2. PostgreSQL Information Disclosure and Denial of Service Vulnera=
bilities
       3. Samba Deferred CIFS File Open Denial of Service Vulnerability
       4. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerab=
ility
       5. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow V=
ulnerabilities
       6. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerab=
ility
       7. RARLAB Unrar Password Protected Archives Buffer Overflow Vulner=
ability
       8. Trend Micro Antivirus UPX Compressed PE File Buffer Overflow Vu=
lnerability
       9. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
       10. March Networks Digital Video Recorders Unspecified Denial of S=
ervice Vulnerability
       11. MoinMoin Multiple Cross-Site Scripting Vulnerabilities
       12. MoniMoni Multiple Cross Site Scripting Vulnerabilities
       13. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulner=
ability
       14. Adobe JRun Administrator Console Cross-Site Scripting Vulnerab=
ility
III. LINUX FOCUS LIST SUMMARY
       1. Did I get hacked?
       2. administrator permissions mail server
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Mouse-Trapped
By Mark Rasch
Substitute teacher Julie Amero faces up to 40 years in prison for exposin=
g kids to porn using a classroom computer, but the facts strongly suggest=
 that she was wrongfully convicted. Many issues remain, from the need for=
 an independent computer forensics investigation and the presence of spyw=
are and adware on the machine, to bad or incomplete legal work on both si=
des of this criminal case.
http://www.securityfocus.com/columnists/434

2. Nothing to Fear... ?
By Scott Granneman
Scott Granneman looks at the use of fear in computer security, from misle=
ading media reports and gross exaggeration by industry leaders to the use=
 of fear in order to sell new computers and software.
http://www.securityfocus.com/columnists/433


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabili=
ties
BugTraq ID: 22380
Remote: Yes
Date Published: 2007-02-03
Relevant URL: http://www.securityfocus.com/bid/22380
Summary:
Bugzilla is prone to an information-disclosure and an HTML-injection vuln=
erability because the application fails to properly sanitize user-supplie=
d input and to protect sensitive information from unauthorized users.

Attackers may exploit these issues to execute script code in the context =
of the affected site or to obtain sensitive information. Arbitrary code e=
xecution may allow attackers to steal cookie-based authentication credent=
ials or to control how the site is rendered to the user. Other attacks ar=
e also possible.

Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerabilit=
y; only the development snapshot version 2.23.3  is vulnerable to the inf=
ormation-disclosure issue.

2. PostgreSQL Information Disclosure and Denial of Service Vulnerabilitie=
s
BugTraq ID: 22387
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulne=
rabilities; fixes are available.

An attacker can exploit these vulnerabilities to cause the backend databa=
se to crash and reveal sensitive information. This may lead to other atta=
cks.=20

 These issues affect versions 8.0, 8.1, and 8.2. The second issue describ=
ed also affects version 7.3 and 7.4.

3. Samba Deferred CIFS File Open Denial of Service Vulnerability
BugTraq ID: 22395
Remote: No
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22395
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources,=
 ultimately crashing the affected application.

This issue affects Samba versions 3.0.6 through 3.0.23d, inclusive.

4. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
BugTraq ID: 22403
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22403
Summary:
Samba is prone to a remote format-string vulnerability because the applic=
ation fails to properly sanitize user-supplied input before including it =
in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of users running the affected applicat=
ion. This facilitates the remote compromise of affected computers.

Samba versions 3.06 to 3.0.23d are vulnerable.

5. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnerab=
ilities
BugTraq ID: 22410
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22410
Summary:
Samba is prone to multiple remote buffer-overflow vulnerabilities because=
 the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20

An attacker may exploit these issues to execute arbitrary code with super=
user privileges, completely compromising affected computers. Failed explo=
it attempts will result in a denial of service.
=20
These issues affects versions 3.0.21 to 3.0.23d.

6. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BugTraq ID: 22428
Remote: Yes
Date Published: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22428
Summary:
Konquerer is prone to a cross-site scripting vulnerability because the ap=
plication fails to sufficiently sanitize user-supplied data.

Exploiting this issue may help the attacker steal cookie-based authentica=
tion credentials and launch other attacks.

All versions of KDE up to and including KDE 3.5.6 are vulnerable to this =
issue. Apple Safari web browser is also vulnerable to this issue.

7. RARLAB Unrar Password Protected Archives Buffer Overflow Vulnerability
BugTraq ID: 22447
Remote: Yes
Date Published: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22447
Summary:
Unrar is prone to a stack-based buffer-overflow vulnerability because it =
fails to properly bounds-check user-supplied input before copying it to a=
n insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user opening the archive.

This issue affects version 3.60 for Linux and 3.61 for Windows; prior ver=
sions may also be affected.

8. Trend Micro Antivirus UPX Compressed PE File Buffer Overflow Vulnerabi=
lity
BugTraq ID: 22449
Remote: Yes
Date Published: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22449
Summary:
Trend Micro Antivirus is prone to a buffer-overflow vulnerability because=
 it fails to properly bounds-check user-supplied data before copying it t=
o an insufficiently sized memory buffer.=20

This issue occurs when the application processes compressed UPX files.=20

Successsful exploits will result in attacker-supplied arbitrary code runn=
ing with elevated privileges, resulting in the complete compromise of aff=
ected computers. Failed exploit attempts will likely cause denial-of-serv=
ice conditions.

This issue affects all Trend Micro products and versions using the Scan E=
ngine and Pattern File technology.

9. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
BugTraq ID: 22496
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22496
Summary:
PHP version 5.2.0 and prior is prone to multiple security vulnerabilities=
. Successful exploits could allow an attacker to write files in unauthori=
zed locations, cause a denial-of-service condition, and potentially execu=
te code.

These issues are reported to affect PHP 4.4.4 and prior versions in the 4=
 branch, and 5.2.0 and prior versions in the 5 branch; other versions may=
 also be vulnerable.

10. March Networks Digital Video Recorders Unspecified Denial of Service =
Vulnerability
BugTraq ID: 22497
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22497
Summary:
March Networks Digital Video Recorders (DVR) are prone to an unspecified =
denial-of-service vulnerability.

A successful attack can deny service for legitimate users on the affected=
 device.

Currently, few technical details are available for this issue. This BID w=
ill be updated as new information is disclosed.

All March Networks DVR 3000 and 4000 series devices are reported vulnerab=
le.

11. MoinMoin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22506
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22506
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e the application fails to properly sanitize user-supplied input.=20

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user. This may help the attacker steal co=
okie-based authentication credentials and launch other attacks.

12. MoniMoni Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 22515
Remote: Yes
Date Published: 2007-02-12
Relevant URL: http://www.securityfocus.com/bid/22515
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.
=20
Version 1.5.7 is vulnerable; other versions may also be affected.

13. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
BugTraq ID: 22539
Remote: No
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22539
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A successful attack can allow local attackers to trigger a crash and deny=
 service to legitimate users.
=20
Kernel versions 2.6.x are vulnerable.

14. Adobe JRun Administrator Console Cross-Site Scripting Vulnerability
BugTraq ID: 22547
Remote: Yes
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22547
Summary:
Adobe JRun is prone to a cross-site scripting vulnerability because it fa=
ils to sufficiently sanitize user-supplied input.

An attacker could exploit this vulnerability to execute arbitrary script =
code in the context of the affected website. This may allow the attacker =
to steal cookie-based authentication credentials and to launch other atta=
cks.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940

2. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving hackers complete access to all your backend systems! Firewalls =
and IDS will not stop such attacks because SQL Injections are NOT seen as=
 intruders. Download this *FREE* white paper from SPI Dynamics for a comp=
lete guide to protection!=20

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Ci=
NE