SecurityFocus Linux Newsletter #326

[email protected] 27 Feb 2007 23:29:20 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #326
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

While Ajax can greatly improve the usability of a Web application, it can=
 also=20
create several opportunities for possible attack if the application is no=
t=20
designed with security in mind. Download this SPI Dynamics white paper.=20

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=3D70160000000C=
j51


------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Building Secure Applications: Consistent Logging
II.  LINUX VULNERABILITY SUMMARY
       1. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulner=
ability
       2. IBM DB2 DB2DIAG.LOG File Local Arbitrary File Overwrite Vulnera=
bility
       3. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflo=
w Vulnerability
       4. Linux Kernel NFSACL Denial of Service Vulnerability
       5. Trend Micro ServerProtect Session ID Authentication Bypass Vuln=
erability
       6. IBM DB2 Universal Database Multiple Local Privilege Escalation =
Vulnerabilities
       7. Enigmail Memory Allocation Denial Of Service Vulnerability
       8. Mozilla Thunderbird/SeaMonkey/Firefox Multiple Remote Vulnerabi=
lities
       9. IBM DB2 Fenced UserID Unspecified Authentication Bypass Vulnera=
bility
       10. Debian Apache Root Shell Local Privilege Escalation Vulnerabil=
ities
       11. Linux Kernel Audit Subsystems Local Denial of Service Vulnerab=
ility
       12. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. Did I get hacked?
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Building Secure Applications: Consistent Logging
By Rohit Sethi and Nish Bhalla
This article focuses on developers and discusses how to use consistent ap=
plication-layer logging along with Log4J or Log4net for the real-time det=
ection of attacks.=20
http://www.securityfocus.com/infocus/1888


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulnerability
BugTraq ID: 22613
Remote: Yes
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22613
Summary:
Ekiga is prone to a remote format-string vulnerability because the applic=
ation fails to properly sanitize user-supplied input before including it =
in the format-specifier argument of a formatted-printing function.

A remote attacker may execute arbitrary code with the privileges of the c=
urrently logged-in user. Failed exploit attempts will result in a denial =
of service.=20
=20
This issue affects versions prior to 2.0.5.

2. IBM DB2 DB2DIAG.LOG File Local Arbitrary File Overwrite Vulnerability
BugTraq ID: 22614
Remote: No
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22614
Summary:
IBM DB2 is prone to a local arbitrary file-overwrite vulnerability.=20

A local attacker can exploit this issue to overwrite arbitrary files. Thi=
s may result in denial-of-service conditions or permit an attacker to tak=
e complete control of a vulnerable computer.

IBM DB2 versions prior to version 9 fix pack 2 are vulnerable to this iss=
ue. Windows systems are not vulnerable.

3. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflow Vulne=
rability
BugTraq ID: 22616
Remote: Yes
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22616
Summary:
Snort IDS and Sourcefire Intrusion Sensor are prone to a stack-based buff=
er-overflow vulnerability because the network intrusion detection (NID) s=
ystems fail to handle specially crafted 'DCE' and 'RPC' network packets.=20

An attacker can exploit this issue to execute malicious code in the conte=
xt of the user running the affected application. Failed attempts will lik=
ely cause these applications to crash.

4. Linux Kernel NFSACL Denial of Service Vulnerability
BugTraq ID: 22625
Remote: No
Date Published: 2007-02-19
Relevant URL: http://www.securityfocus.com/bid/22625
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.=20

An attacker can exploit this issue to crash the affected computer, denyin=
g service to legitimate users.

This issue affects the Linux kernel 2.6 series up to 2.6.20.

5. Trend Micro ServerProtect Session ID Authentication Bypass Vulnerabili=
ty
BugTraq ID: 22662
Remote: Yes
Date Published: 2007-02-21
Relevant URL: http://www.securityfocus.com/bid/22662
Summary:
Trend Micro ServerProtect is prone to an authentication-bypass vulnerabil=
ity.

A successful attack can allow an unauthorized attacker to bypass authenti=
cation routines and access the application as any logged-in user. The att=
acker may then carry out other attacks against the vulnerable computer or=
 database.

Note that this vulnerability is not present in any of the Microsoft Windo=
ws versions of Trend Micro ServerProtect.

6. IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnera=
bilities
BugTraq ID: 22677
Remote: No
Date Published: 2007-02-22
Relevant URL: http://www.securityfocus.com/bid/22677
Summary:
IBM DB2 is prone to multiple local privilege escalation vulnerabilities. =
These issues can allow an attacker to completely compromise a vulnerable =
computer.

These issues affect DB2 version 9.1 and 8x running on all supported platf=
orms.

7. Enigmail Memory Allocation Denial Of Service Vulnerability
BugTraq ID: 22684
Remote: Yes
Date Published: 2007-02-23
Relevant URL: http://www.securityfocus.com/bid/22684
Summary:
Enigmail is reportedly affected by a memory-allocation-based DoS vulnerab=
ility.  This issue occurs because the application fails to handle excessi=
vely large encrypted attachments. =20
=20
Exploiting this issue would allow an attacker to cause the affected appli=
cation to crash, denying service to legitimate users.

8. Mozilla Thunderbird/SeaMonkey/Firefox Multiple Remote Vulnerabilities
BugTraq ID: 22694
Remote: Yes
Date Published: 2007-02-23
Relevant URL: http://www.securityfocus.com/bid/22694
Summary:
The Mozilla Foundation has released six security advisories specifying vu=
lnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- Execute arbitrary code
- Cause denial-of-service conditions
- Perform cross-site scripting attacks
- Obtain potentially sensitive information
- Spoof legitimate content

Other attacks may also be possible.

9. IBM DB2 Fenced UserID Unspecified Authentication Bypass Vulnerability
BugTraq ID: 22729
Remote: No
Date Published: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22729
Summary:
IBM DB2 is prone to an unspecified authentication-bypass vulnerability be=
cause it fails to effectively restrict access to certain directories.

An attacker could exploit this issue to gain unauthorized access to privi=
leged directories.=20

Versions prior to 8.1 FixPak 14 and 9.1 FixPak 2 are vulnerable.

10. Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
BugTraq ID: 22732
Remote: No
Date Published: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22732
Summary:
The Debian Apache distribution is prone to a local privilege-escalation v=
ulnerability.

A local attacker can exploit this issue to execute abritrary commands wit=
h superuser privileges. This can result in a complete compromise of the a=
ffected computer.

This issue affects Debian Apache version 1.3.34-4.

11. Linux Kernel Audit Subsystems Local Denial of Service Vulnerability
BugTraq ID: 22737
Remote: No
Date Published: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22737
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A local attacker can exploit this issue to crash the kernel.

Linux kernel versions 2.6.x are vulnerable to this issue.

12. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
BugTraq ID: 22742
Remote: Yes
Date Published: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22742
Summary:
Nullsoft SHOUTcast is prone to an HTML-injection vulnerability because it=
 fails to properly sanitize user-supplied input before using it in dynami=
cally generated content.=20

Attacker-supplied HTML and script code would run in the context of the af=
fected website, potentially allowing an attacker to steal cookie-based au=
thentication credentials or to control how the site is rendered to the us=
er; other attacks are also possible.

This issue affects version 1.9.7 for Microsoft Windows; other versions ma=
y also be vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

While Ajax can greatly improve the usability of a Web application, it can=
 also=20
create several opportunities for possible attack if the application is no=
t=20
designed with security in mind. Download this SPI Dynamics white paper.=20

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=3D70160000000C=
j51