SecurityFocus Linux Newsletter #324
[email protected] 14 Feb 2007 00:41:05 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #324
----------------------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving hackers complete access to all your backend systems! Firewalls =
and IDS will not stop such attacks because SQL Injections are NOT seen as=
intruders. Download this *FREE* white paper from SPI Dynamics for a comp=
lete guide to protection!=20
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Ci=
NE
------------------------------------------------------------------
I. FRONT AND CENTER
1. Mouse-Trapped
2. Nothing to Fear... ?
II. LINUX VULNERABILITY SUMMARY
1. Mozilla Bugzilla HTML Injection And Information disclosure Vuln=
erabilities
2. PostgreSQL Information Disclosure and Denial of Service Vulnera=
bilities
3. Samba Deferred CIFS File Open Denial of Service Vulnerability
4. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerab=
ility
5. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow V=
ulnerabilities
6. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerab=
ility
7. RARLAB Unrar Password Protected Archives Buffer Overflow Vulner=
ability
8. Trend Micro Antivirus UPX Compressed PE File Buffer Overflow Vu=
lnerability
9. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
10. March Networks Digital Video Recorders Unspecified Denial of S=
ervice Vulnerability
11. MoinMoin Multiple Cross-Site Scripting Vulnerabilities
12. MoniMoni Multiple Cross Site Scripting Vulnerabilities
13. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulner=
ability
14. Adobe JRun Administrator Console Cross-Site Scripting Vulnerab=
ility
III. LINUX FOCUS LIST SUMMARY
1. Did I get hacked?
2. administrator permissions mail server
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Mouse-Trapped
By Mark Rasch
Substitute teacher Julie Amero faces up to 40 years in prison for exposin=
g kids to porn using a classroom computer, but the facts strongly suggest=
that she was wrongfully convicted. Many issues remain, from the need for=
an independent computer forensics investigation and the presence of spyw=
are and adware on the machine, to bad or incomplete legal work on both si=
des of this criminal case.
http://www.securityfocus.com/columnists/434
2. Nothing to Fear... ?
By Scott Granneman
Scott Granneman looks at the use of fear in computer security, from misle=
ading media reports and gross exaggeration by industry leaders to the use=
of fear in order to sell new computers and software.
http://www.securityfocus.com/columnists/433
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabili=
ties
BugTraq ID: 22380
Remote: Yes
Date Published: 2007-02-03
Relevant URL: http://www.securityfocus.com/bid/22380
Summary:
Bugzilla is prone to an information-disclosure and an HTML-injection vuln=
erability because the application fails to properly sanitize user-supplie=
d input and to protect sensitive information from unauthorized users.
Attackers may exploit these issues to execute script code in the context =
of the affected site or to obtain sensitive information. Arbitrary code e=
xecution may allow attackers to steal cookie-based authentication credent=
ials or to control how the site is rendered to the user. Other attacks ar=
e also possible.
Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerabilit=
y; only the development snapshot version 2.23.3 is vulnerable to the inf=
ormation-disclosure issue.
2. PostgreSQL Information Disclosure and Denial of Service Vulnerabilitie=
s
BugTraq ID: 22387
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulne=
rabilities; fixes are available.
An attacker can exploit these vulnerabilities to cause the backend databa=
se to crash and reveal sensitive information. This may lead to other atta=
cks.=20
These issues affect versions 8.0, 8.1, and 8.2. The second issue describ=
ed also affects version 7.3 and 7.4.
3. Samba Deferred CIFS File Open Denial of Service Vulnerability
BugTraq ID: 22395
Remote: No
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22395
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume excessive memory resources,=
ultimately crashing the affected application.
This issue affects Samba versions 3.0.6 through 3.0.23d, inclusive.
4. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
BugTraq ID: 22403
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22403
Summary:
Samba is prone to a remote format-string vulnerability because the applic=
ation fails to properly sanitize user-supplied input before including it =
in the format-specifier argument of a formatted-printing function.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of users running the affected applicat=
ion. This facilitates the remote compromise of affected computers.
Samba versions 3.06 to 3.0.23d are vulnerable.
5. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnerab=
ilities
BugTraq ID: 22410
Remote: Yes
Date Published: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22410
Summary:
Samba is prone to multiple remote buffer-overflow vulnerabilities because=
the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20
An attacker may exploit these issues to execute arbitrary code with super=
user privileges, completely compromising affected computers. Failed explo=
it attempts will result in a denial of service.
=20
These issues affects versions 3.0.21 to 3.0.23d.
6. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BugTraq ID: 22428
Remote: Yes
Date Published: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22428
Summary:
Konquerer is prone to a cross-site scripting vulnerability because the ap=
plication fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentica=
tion credentials and launch other attacks.
All versions of KDE up to and including KDE 3.5.6 are vulnerable to this =
issue. Apple Safari web browser is also vulnerable to this issue.
7. RARLAB Unrar Password Protected Archives Buffer Overflow Vulnerability
BugTraq ID: 22447
Remote: Yes
Date Published: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22447
Summary:
Unrar is prone to a stack-based buffer-overflow vulnerability because it =
fails to properly bounds-check user-supplied input before copying it to a=
n insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user opening the archive.
This issue affects version 3.60 for Linux and 3.61 for Windows; prior ver=
sions may also be affected.
8. Trend Micro Antivirus UPX Compressed PE File Buffer Overflow Vulnerabi=
lity
BugTraq ID: 22449
Remote: Yes
Date Published: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22449
Summary:
Trend Micro Antivirus is prone to a buffer-overflow vulnerability because=
it fails to properly bounds-check user-supplied data before copying it t=
o an insufficiently sized memory buffer.=20
This issue occurs when the application processes compressed UPX files.=20
Successsful exploits will result in attacker-supplied arbitrary code runn=
ing with elevated privileges, resulting in the complete compromise of aff=
ected computers. Failed exploit attempts will likely cause denial-of-serv=
ice conditions.
This issue affects all Trend Micro products and versions using the Scan E=
ngine and Pattern File technology.
9. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
BugTraq ID: 22496
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22496
Summary:
PHP version 5.2.0 and prior is prone to multiple security vulnerabilities=
. Successful exploits could allow an attacker to write files in unauthori=
zed locations, cause a denial-of-service condition, and potentially execu=
te code.
These issues are reported to affect PHP 4.4.4 and prior versions in the 4=
branch, and 5.2.0 and prior versions in the 5 branch; other versions may=
also be vulnerable.
10. March Networks Digital Video Recorders Unspecified Denial of Service =
Vulnerability
BugTraq ID: 22497
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22497
Summary:
March Networks Digital Video Recorders (DVR) are prone to an unspecified =
denial-of-service vulnerability.
A successful attack can deny service for legitimate users on the affected=
device.
Currently, few technical details are available for this issue. This BID w=
ill be updated as new information is disclosed.
All March Networks DVR 3000 and 4000 series devices are reported vulnerab=
le.
11. MoinMoin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22506
Remote: Yes
Date Published: 2007-02-09
Relevant URL: http://www.securityfocus.com/bid/22506
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e the application fails to properly sanitize user-supplied input.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user. This may help the attacker steal co=
okie-based authentication credentials and launch other attacks.
12. MoniMoni Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 22515
Remote: Yes
Date Published: 2007-02-12
Relevant URL: http://www.securityfocus.com/bid/22515
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.
=20
Version 1.5.7 is vulnerable; other versions may also be affected.
13. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
BugTraq ID: 22539
Remote: No
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22539
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.
A successful attack can allow local attackers to trigger a crash and deny=
service to legitimate users.
=20
Kernel versions 2.6.x are vulnerable.
14. Adobe JRun Administrator Console Cross-Site Scripting Vulnerability
BugTraq ID: 22547
Remote: Yes
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22547
Summary:
Adobe JRun is prone to a cross-site scripting vulnerability because it fa=
ils to sufficiently sanitize user-supplied input.
An attacker could exploit this vulnerability to execute arbitrary script =
code in the context of the affected website. This may allow the attacker =
to steal cookie-based authentication credentials and to launch other atta=
cks.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940
2. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving hackers complete access to all your backend systems! Firewalls =
and IDS will not stop such attacks because SQL Injections are NOT seen as=
intruders. Download this *FREE* white paper from SPI Dynamics for a comp=
lete guide to protection!=20
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Ci=
NE