SecurityFocus Linux Newsletter #325

Peter Laborge <[email protected]> Wed, 21 Feb 2007 09:28:28 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #325
----------------------------------------

This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts. 
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.  
Network with 400 delegates from 25 nations, and see solutions from major sponsors.  

http://www.blackhat.com

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Laptop Losses and Phishing Fruit Salad
II.  LINUX VULNERABILITY SUMMARY
       1. MoinMoin Multiple Cross Site Scripting Vulnerabilities
       2. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
       3. Adobe JRun Administrator Console Cross-Site Scripting Vulnerability
       4. LizardTech DjVu Browser Plug-in Multiple Buffer Overflow Vulnerabilities
       5. HP ServiceGuard For Linux Unspecified Remote Unauthorized Access Vulnerability
       6. ClamAV CAB File Remote Denial of Service Vulnerability
       7. ClamAV MIME Header ID Parameter String Directory Traversal Vulnerability
       8. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
       9. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulnerability
       10. IBM DB2 DB2DIAG.LOG File Local Arbitrary File Overwrite Vulnerability
       11. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflow Vulnerability
       12. Linux Kernel NFSACL Denial of Service Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. Did I get hacked?
       2. administrator permissions mail server
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Laptop Losses and Phishing Fruit Salad
By Dr. Neal Krawetz
Dr. Neal Krawetz takes a look at the numbers behind reports of laptop thefts and phishing attacks, showing inconsistent metrics and the difficulty in using numbers to determine the real level of threat.
http://www.securityfocus.com/columnists/435


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. MoinMoin Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 22515
Remote: Yes
Date Published: 2007-02-12
Relevant URL: http://www.securityfocus.com/bid/22515
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
 
Version 1.5.7 is vulnerable; other versions may also be affected.

2. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
BugTraq ID: 22539
Remote: No
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22539
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A successful attack can allow local attackers to trigger a crash and deny service to legitimate users.
 
Kernel versions 2.6.x are vulnerable.

3. Adobe JRun Administrator Console Cross-Site Scripting Vulnerability
BugTraq ID: 22547
Remote: Yes
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22547
Summary:
Adobe JRun is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.

An attacker could exploit this vulnerability to execute arbitrary script code in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

4. LizardTech DjVu Browser Plug-in Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 22569
Remote: Yes
Date Published: 2007-02-15
Relevant URL: http://www.securityfocus.com/bid/22569
Summary:
DjVu Browser Plug-in is prone to multiple buffer-overflow vulnerabilities because it fails to sufficiently bounds-check user-supplied data.

Exploiting these issues may allow an attacker to execute arbitrary code with the privileges of the user running the application.

DjVu Browser Plug-in versions prior to 6.1.1 are vulnerable.

5. HP ServiceGuard For Linux Unspecified Remote Unauthorized Access Vulnerability
BugTraq ID: 22574
Remote: Yes
Date Published: 2007-02-15
Relevant URL: http://www.securityfocus.com/bid/22574
Summary:
HP Serviceguard for Linux is prone to an unauthorized-access vulnerability.

An attacker can exploit this issue to gain remote unauthorized access to affected computers.

6. ClamAV CAB File Remote Denial of Service Vulnerability
BugTraq ID: 22580
Remote: Yes
Date Published: 2007-02-15
Relevant URL: http://www.securityfocus.com/bid/22580
Summary:
ClamAV is prone to a denial-of-service vulnerability.

An attacker can exploit this vulnerability to prevent the software from scanning certain types of data. When it encounters the data, the application will reject it. This can result in denial-of-service conditions.

Versions prior to 0.90 stable are vulnerable.

7. ClamAV MIME Header ID Parameter String Directory Traversal Vulnerability
BugTraq ID: 22581
Remote: Yes
Date Published: 2007-02-15
Relevant URL: http://www.securityfocus.com/bid/22581
Summary:
ClamAV is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to create or overwrite arbitrary files on vulnerable computers in the context of the affected application. This may aid in further attacks. 

This issue affects ClamAV versions prior to the 0.90 stable release.

8. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
BugTraq ID: 22584
Remote: Yes
Date Published: 2007-02-13
Relevant URL: http://www.securityfocus.com/bid/22584
Summary:
SpamAssassin is prone to a remote denial-of-service vulnerability. 

This issue arises when the application handles excessively long URIs.
 
SpamAssassin versions prior to 3.1.8 are vulnerable to this issue.

9. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulnerability
BugTraq ID: 22613
Remote: Yes
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22613
Summary:
Ekiga is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

A remote attacker may execute arbitrary code with the privileges of the currently logged in user. Failed exploit attempts will result in a denial-of-service. 
 
This issue affects versions prior to 2.0.5.

10. IBM DB2 DB2DIAG.LOG File Local Arbitrary File Overwrite Vulnerability
BugTraq ID: 22614
Remote: No
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22614
Summary:
IBM DB2 is prone to a local arbitrary file-overwrite vulnerability. 

A local attacker can exploit this issue to overwrite arbitrary files. This may result in denial-of-service conditions or permit an attacker to take complete control of a vulnerable computer.

IBM DB2 versions prior to version 9 fix pack 2 are vulnerable to this issue. Windows systems are not vulnerable.

11. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflow Vulnerability
BugTraq ID: 22616
Remote: Yes
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22616
Summary:
Snort IDS and Sourcefire Intrusion Sensor are prone to a stack-based buffer overflow vulnerability because the network intrusion detection (NID) systems fail to handle specially crafted 'DCE' and 'RPC' network packets. 

An attacker can exploit this issue to execute malicious code in the context of the user running the affected application. Failed attempts will likely cause these applications to crash.

12. Linux Kernel NFSACL Denial of Service Vulnerability
BugTraq ID: 22625
Remote: No
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22625
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. 

An attacker can exploit this issue to crash the affected computer, denying service to legitimate users.

This issue affects the Linux kernel 2.6 series up to 2.6.20.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940

2. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website. 

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts. 
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.  
Network with 400 delegates from 25 nations, and see solutions from major sponsors.  

http://www.blackhat.com