SecurityFocus Linux Newsletter #329
[email protected] 20 Mar 2007 20:54:39 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #329
----------------------------------------
This Issue is Sponsored by: Black Hat
Attend Black Hat Europe, March 27-30 in Amsterdam, Europe's premier techn=
ical event for ICT security experts. Featuring 10 hands-on training cours=
es and 20 Briefings presentations with lots of new content - the best of =
Black Hat! See security solutions from 8 top sponsors including Microsof=
t and Google, and network with 400 colleagues from 30 nations. To down=
load the preview program visit www.blackhat.com/html/bh-europe-07/marketi=
ng/bh-eu-07-preview-LR.pdf.=20
For general information or to register visit:=20
http://www.blackhat.com
------------------------------------------------------------------
I. FRONT AND CENTER
1. Blanket Discovery for Stolen Laptops
II. LINUX VULNERABILITY SUMMARY
1. KTorrent Multiple Remote Vulnerabilities
2. Xine DirectShow Loader Remote Buffer Overflow Vulnerability
3. Linux Kernel Netfilter NFNetLink_Log Multiple NULL Pointer Dere=
ference Vulnerabilities
4. PHProjekt Multiple SQL Injection Vulnerabilities
5. PHProjekt Arbitrary File Upload Vulnerability
6. Adobe JRun Unspecified Denial Of Service Vulnerability
7. MiniGZip Controls File_Compress Buffer Overflow Vulnerability
8. Xen QEMU VNC Server Arbitrary Information Disclosure Vulnerabil=
ity
9. Sun Java System Web Server Certificate Revocation Access Contro=
l Bypass Vulnerability
10. Multiple Cisco Products Online Help Cross Site Scripting Vulne=
rability
11. Sun Java System Web Server Unspecified Unauthorized Access Vul=
nerability
12. Computer Associates BrightStor ARCServe BackUp Tape Engine Mul=
tiple Vulnerabilities
13. LibWPD Library Multiple Buffer Overflow Vulnerabilities
14. Rhapsody IRC Multiple Remote Vulnerabilities
15. Linux Security Auditing Tool Insecure Temporary File Creation =
Vulnerability
16. File(1) Command File_PrintF Integer Underflow Vulnerability
17. Lookup Insecure Temporary File Creation Vulnerability
18. Asterisk SIP Invite Message Remote Denial of Service Vulnerabi=
lity
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Blanket Discovery for Stolen Laptops
By Mark Rasch
Mark Rasch discusses the legal issues behind the discovery and recovery o=
f stolen laptops that use LoJack-style homing devices to announce their l=
ocation, and the location of the thieves, anywhere in the world.
http://www.securityfocus.com/columnists/438
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. KTorrent Multiple Remote Vulnerabilities
BugTraq ID: 22930
Remote: Yes
Date Published: 2007-03-12
Relevant URL: http://www.securityfocus.com/bid/22930
Summary:
KTorrent is prone to multiple remote vulnerabilities, including a directo=
ry-traversal vulnerability and an unspecified vulnerability when processi=
ng messages with invalid chunk indexes.=20
Very little information is known about one of these issues. This BID will=
be updated as soon as more information becomes available.
An attacker can exploit the directory-traversal issue to overwrite arbitr=
ary files on the user's system. Presumably, the unspecified vulnerability=
when processing messages with invalid chunk indexes will allow attackers=
to execute arbitrary code or to cause a denial of service, but this has =
not been confirmed.
Versions prior to 2.1.2 are vulnerable to these issues.
2. Xine DirectShow Loader Remote Buffer Overflow Vulnerability
BugTraq ID: 22933
Remote: Yes
Date Published: 2007-03-12
Relevant URL: http://www.securityfocus.com/bid/22933
Summary:
Xine is prone to a remote buffer-overflow vulnerability because the appli=
cation fails to perform boundary checks before copying user-supplied inpu=
t into finite-sized buffers.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the application and to compromise a=
ffected computers.
3. Linux Kernel Netfilter NFNetLink_Log Multiple NULL Pointer Dereference=
Vulnerabilities
BugTraq ID: 22946
Remote: No
Date Published: 2007-03-13
Relevant URL: http://www.securityfocus.com/bid/22946
Summary:
The Linux kernel is prone to multiple NULL-pointer dereference vulnerabil=
ities.
A local attacker can exploit these issues to crash the affected kernel, d=
enying service to legitimate users.
4. PHProjekt Multiple SQL Injection Vulnerabilities
BugTraq ID: 22955
Remote: Yes
Date Published: 2007-03-14
Relevant URL: http://www.securityfocus.com/bid/22955
Summary:
PHProjekt is prone to multiple SQL-injection vulnerabilities because the =
application fails to properly sanitize user-supplied input before using i=
t in an SQL query.=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase implementation.
=20
PHProjekt 5.2.0 and prior versions are vulnerable to these issues.
5. PHProjekt Arbitrary File Upload Vulnerability
BugTraq ID: 22956
Remote: Yes
Date Published: 2007-03-14
Relevant URL: http://www.securityfocus.com/bid/22956
Summary:
PHProjekt is prone to an arbitrary file-upload vulnerability.
=20
Exploiting this issue could allow an attacker to upload and execute arbit=
rary script code in the context of the affected webserver process. This m=
ay help the attacker compromise the application; other attacks are possib=
le.
Versions prior to 5.2.1 are vulnerable to this issue.
6. Adobe JRun Unspecified Denial Of Service Vulnerability
BugTraq ID: 22958
Remote: Yes
Date Published: 2007-03-13
Relevant URL: http://www.securityfocus.com/bid/22958
Summary:
Adobe JRun is prone to a denial-of-service vulnerability because the appl=
ication fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.
This issue affects Microsoft IIS 6 installations running JRun 4 Updater 6=
.
7. MiniGZip Controls File_Compress Buffer Overflow Vulnerability
BugTraq ID: 22964
Remote: No
Date Published: 2007-03-14
Relevant URL: http://www.securityfocus.com/bid/22964
Summary:
The 'minigzip' tool is prone to a buffer-overflow vulnerability because i=
t fails to bounds-check user-supplied data before copying it into an insu=
fficiently sized buffer.=20
A local attacker can exploit this issue to execute arbitrary code with th=
e privileges of the user running the affected application. Failed exploit=
attempts will result in a denial of service.
8. Xen QEMU VNC Server Arbitrary Information Disclosure Vulnerability
BugTraq ID: 22967
Remote: Yes
Date Published: 2007-03-14
Relevant URL: http://www.securityfocus.com/bid/22967
Summary:
Xen is prone to an unspecified vulnerability that lets attackers obtain a=
rbitrary information. The issue stems from a flaw in the VNC server code =
in QEMU.
=20
An attacker can exploit this issue to access sensitive information that m=
ay aid in further attacks.
9. Sun Java System Web Server Certificate Revocation Access Control Bypas=
s Vulnerability
BugTraq ID: 22973
Remote: Yes
Date Published: 2007-03-15
Relevant URL: http://www.securityfocus.com/bid/22973
Summary:
Sun Java System Web Server is prone to a vulnerability that lets attacker=
s bypass access controls.=20
An attacker may leverage this issue to access a secure webserver using a =
revoked certificate. Such unauthorized access may help the attacker launc=
h other attacks.
10. Multiple Cisco Products Online Help Cross Site Scripting Vulnerabilit=
y
BugTraq ID: 22982
Remote: Yes
Date Published: 2007-03-15
Relevant URL: http://www.securityfocus.com/bid/22982
Summary:
Multiple Cisco products are prone to a cross-site scripting vulnerability=
because they fail to properly sanitize user-supplied input.=20
An attacker may leverage this issue by enticing a victim into following a=
maliciously crafted URI.
Attackers may leverage this issue to execute arbitrary script code in the=
browser of an unsuspecting user in the context of the affected site. Thi=
s may help the attacker steal cookie-based authentication credentials and=
launch other attacks.
This issue is being tracked by Cisco IDs: CSCsh91761, CSCsh52300, CSCsh9=
1884, CSCsi12435, CSCsh91901, CSCsi10405, CSCsh91953, CSCsh93070, CSCsh93=
854, CSCek71039, CSCsh95009, CSCsi10818, CSCsi10674, CSCsi10982, CSCsi137=
43, CSCsi13763.
11. Sun Java System Web Server Unspecified Unauthorized Access Vulnerabil=
ity
BugTraq ID: 22993
Remote: Yes
Date Published: 2007-03-16
Relevant URL: http://www.securityfocus.com/bid/22993
Summary:
Sun Java System Web Server is prone to a vulnerability that lets attacker=
s gain unauthorized access to sensitive information.=20
An attacker may leverage this issue to access data stored on the host run=
ning the webserver. Such unauthorized access may help the attacker launch=
other attacks.
12. Computer Associates BrightStor ARCServe BackUp Tape Engine Multiple V=
ulnerabilities
BugTraq ID: 22994
Remote: Yes
Date Published: 2007-03-15
Relevant URL: http://www.securityfocus.com/bid/22994
Summary:
Computer Associates BrightStor ARCServe BackUp Tape Engine service is pro=
ne to multiple vulnerabilities.
=20
Exploiting these issues can result in denial-of-service conditions or rem=
ote code execution.
13. LibWPD Library Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 23006
Remote: Yes
Date Published: 2007-03-16
Relevant URL: http://www.securityfocus.com/bid/23006
Summary:
The libwpd library is prone to multiple buffer-overflow vulnerabilities b=
ecause it fails to adequately check boundaries on user-supplied input.
A successful exploit could let a remote attacker execute arbitrary code i=
n the context of an application using the affected library.
Version 0.8.7 is vulnerable; other versions prior to 0.8.9 may also be af=
fected.
14. Rhapsody IRC Multiple Remote Vulnerabilities
BugTraq ID: 23011
Remote: Yes
Date Published: 2007-03-17
Relevant URL: http://www.securityfocus.com/bid/23011
Summary:
Rhapsody IRC is prone to multiple remote vulnerabilities, including multi=
ple buffer-overflow issues and format-string issues.
Exploiting these issues allows remote attackers to execute arbitrary mach=
ine code in the context of the affected application. Failed exploit attem=
pts will likely crash applications, denying service to legitimate users.
15. Linux Security Auditing Tool Insecure Temporary File Creation Vulnera=
bility
BugTraq ID: 23014
Remote: No
Date Published: 2007-03-19
Relevant URL: http://www.securityfocus.com/bid/23014
Summary:
The Linux Security Auditing Tool creates temporary files in an insecure m=
anner.
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.
Version 0.9.2 is vulnerable to this issue; other versions may also be aff=
ected.
16. File(1) Command File_PrintF Integer Underflow Vulnerability
BugTraq ID: 23021
Remote: Yes
Date Published: 2007-03-19
Relevant URL: http://www.securityfocus.com/bid/23021
Summary:
The file(1) command is prone to an integer-underflow vulnerability becaus=
e the command fails to adequately handle user-supplied data.
An attacker can leverage this issue to corrupt heap memory and execute ar=
bitrary code with the privileges of a user running the command. A success=
ful attack may result in the compromise of affected computers. Failed att=
empts will likely cause denial-of-service conditions.
Versions prior to 4.20 are vulnerable.
17. Lookup Insecure Temporary File Creation Vulnerability
BugTraq ID: 23026
Remote: No
Date Published: 2007-03-19
Relevant URL: http://www.securityfocus.com/bid/23026
Summary:
Lookup creates temporary files in an insecure manner.=20
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
Successfully exploiting a symlink attack may allow the attacker to overwr=
ite or corrupt sensitive files. This may result in a denial of service; o=
ther attacks may also be possible.
Lookup version 1.4 is vulnerable to this issue; other versions may also b=
e affected.
18. Asterisk SIP Invite Message Remote Denial of Service Vulnerability
BugTraq ID: 23031
Remote: Yes
Date Published: 2007-03-19
Relevant URL: http://www.securityfocus.com/bid/23031
Summary:
Asterisk is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to cause the application to=
crash, effectively denying service to legitimate users.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat
Attend Black Hat Europe, March 27-30 in Amsterdam, Europe's premier techn=
ical event for ICT security experts. Featuring 10 hands-on training cours=
es and 20 Briefings presentations with lots of new content - the best of =
Black Hat! See security solutions from 8 top sponsors including Microsof=
t and Google, and network with 400 colleagues from 30 nations. To down=
load the preview program visit www.blackhat.com/html/bh-europe-07/marketi=
ng/bh-eu-07-preview-LR.pdf.=20
For general information or to register visit:=20
http://www.blackhat.com