SecurityFocus Linux Newsletter #333

[email protected] 20 Apr 2007 22:34:44 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #333
----------------------------------------

This Issue is Sponsored by: Kapersky Lab

Try Kaspersky Antivirus 6.0 Software
Download Kaspersky's Award-Winning antivirus & antispyware solution with =
anti-spam and firewall Free

http://newsletter.industrybrains.com/c?fe;1;5f04b;1000f;345;0;da4


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. The Politics of E-Mail
II.  LINUX VULNERABILITY SUMMARY
       1. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabi=
lities
       2. IPSec-Tools Remote Denial Of Service Vulnerability
       3. RETIRED: Freetype Font Files Integer Overflow Vulnerability
       4. Adobe Macromedia ColdFusion Insecure File Permissions Vulnerabi=
lity
       5. BFTPD Multiple Commands Remote Denial Of Service Vulnerabilitie=
s
       6. Quagga BGPD UPDATE Message Remote Denial Of Service Vulnerabili=
ty
       7. IBM Lotus Domino Web Access Active Content Filter HTML Injectio=
n Vulnerability
       8. MadWifi Auth Frame IBSS Remote Denial of Service Vulnerability
       9. MADWiFi IEEE80211_Output.C Unencrypted Data Packet Multiple Vul=
nerabilities
       10. Opera Web Browser Running Adobe Flash Player Unspecified Vulne=
rability
       11. Drupal Database Administration Module Multiple HTML-injection =
Vulnerabilities
       12. WebKalk2 Engine.Inc.PHP Remote File Include Vulnerability
       13. FreeRadius EAP-TTLS Tunnel Memory Leak Remote Denial Of Servic=
e Vulnerability
       14. Clam AntiVirus ClamAV Multiple Remote Vulnerabilities
       15. ScramDisk 4 Linux Local Privilege Escalation Vulnerabilities
       16. Lighttpd Multiple Remote Denial of Service Vulnerabilities
       17. Vixie Cron ST_Nlink Check Local Denial of Service Vulnerabilit=
y
       18. Oracle April 2007 Security Update Multiple Vulnerabilities
       19. McAfee E-Business Administration Server Authentication Packet =
Denial of Service Vulnerability
       20. 3proxy HTTP Proxy Request Buffer Overflow Vulnerability
       21. ProFTPD AUTH Multiple Authentication Module Security Bypass Vu=
lnerability
       22. Dovecot Zlib Plugin Remote Information Disclosure Vulnerabilit=
y
       23. OpenAFS for Microsoft Windows Local Denial of Service Vulnerab=
ility
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. The Politics of E-Mail
By Mark Rasch
It's springtime in Washington, D.C. The cherry blossoms have bloomed, the=
 tourists descended, and on both sides of Pennsylvania Avenue a new "scan=
dal" is erupting.
http://www.securityfocus.com/columnists/440


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 21668
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/21668
Summary:
The Mozilla Foundation has released nine security advisories specifying v=
ulnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- inject arbitrary content
- gain escalated privileges
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

2. IPSec-Tools Remote Denial Of Service Vulnerability
BugTraq ID: 23394
Remote: Yes
Date Published: 2007-04-10
Relevant URL: http://www.securityfocus.com/bid/23394
Summary:
IPSec-Tools is affected by a remote denial-of-service vulnerability becau=
se the application fails to properly handle certain network packets.

A successful attack allows a remote attacker to crash the application, de=
nying further service to legitimate users.

IPSec-Tools versions prior to 0.6.7 are vulnerable to this issue.

3. RETIRED: Freetype Font Files Integer Overflow Vulnerability
BugTraq ID: 23402
Remote: No
Date Published: 2007-04-10
Relevant URL: http://www.securityfocus.com/bid/23402
Summary:
Freetype is prone to a local integer-overflow vulnerability because it fa=
ils to adequately bounds-check user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary code with=
 superuser privileges. Failed exploit attempts will likely cause denial-o=
f-service conditions.

This BID has been retired because it is a duplicate of BID 23283.

4. Adobe Macromedia ColdFusion Insecure File Permissions Vulnerability
BugTraq ID: 23405
Remote: No
Date Published: 2007-04-10
Relevant URL: http://www.securityfocus.com/bid/23405
Summary:
Adobe Macromedia ColdFusion is prone to an insecure-file-permissions vuln=
erability. This issue stems from a previous patch that sets unsafe direct=
ory permissions.=20

A local attacker can exploit this issue to gain administrative privileges=
 on the affected computer. A successful exploit would lead to the complet=
e compromise of affected computers.=20

ColdFusion 7.0.2.142559 for Linux is vulnerable to this issue.

5. BFTPD Multiple Commands Remote Denial Of Service Vulnerabilities
BugTraq ID: 23406
Remote: Yes
Date Published: 2007-04-10
Relevant URL: http://www.securityfocus.com/bid/23406
Summary:
BFTPD is prone to multiple remote denial-of-service vulnerabilities becau=
se the application fails to handle exceptional conditions.=20

An attacker can exploit these issues to crash the affected application, d=
enying service to legitimate users.=20

Versions prior to 1.8 are vulnerable to these issues.

6. Quagga BGPD UPDATE Message Remote Denial Of Service Vulnerability
BugTraq ID: 23417
Remote: Yes
Date Published: 2007-04-11
Relevant URL: http://www.securityfocus.com/bid/23417
Summary:
Quagga is prone to a remote denial-of-service vulnerability because it fa=
ils to handle a malformed multi-protocol message.

A remote attacker can exploit this issue by submitting a maliciously craf=
ted message to the application.

 Successful exploits will cause the Quagga 'bgpd' daemon to abort, denyin=
g further service to legitimate users.

Quagga 0.99.6 and prior versions (0.99 branch) as well as 0.98.6 and prio=
r versions (0.98 branch) are vulnerable.

7. IBM Lotus Domino Web Access Active Content Filter HTML Injection Vulne=
rability
BugTraq ID: 23421
Remote: Yes
Date Published: 2007-04-11
Relevant URL: http://www.securityfocus.com/bid/23421
Summary:
IBM Lotus Domino Web Access is prone to an HTML-injection vulnerability b=
ecause it fails to sufficiently sanitize user-supplied data.

An attacker could exploit this vulnerability to execute arbitrary script =
code in the browser of an unsuspecting victim in the context of the affec=
ted website. This may allow the attacker to steal cookie-based authentica=
tion credentials and to launch other attacks.

8. MadWifi Auth Frame IBSS Remote Denial of Service Vulnerability
BugTraq ID: 23431
Remote: Yes
Date Published: 2007-04-11
Relevant URL: http://www.securityfocus.com/bid/23431
Summary:
MADWifi is prone to a remote denial-of-service vulnerability because the =
application fails to handle certain AUTH frames from an IBSS node.=20

An attacker can exploit this issue to cause the affected computer to cras=
h, denying further service to legitimate users.

This issue affects MADWifi 0.9.3 and prior versions.

9. MADWiFi IEEE80211_Output.C Unencrypted Data Packet Multiple Vulnerabil=
ities
BugTraq ID: 23434
Remote: No
Date Published: 2007-04-11
Relevant URL: http://www.securityfocus.com/bid/23434
Summary:
MADWiFi is prone to a denial-of-service vulnerability, an information-dis=
closure issue, and a packet-spoofing vulnerability. These issues occur be=
cause of a design error.

An attacker can exploit these issues to spoof network traffic, crash arbi=
trary processes, and gain access to sensitive information.

These issues affect versions prior to 0.9.3.

10. Opera Web Browser Running Adobe Flash Player Unspecified Vulnerabilit=
y
BugTraq ID: 23437
Remote: Yes
Date Published: 2007-04-11
Relevant URL: http://www.securityfocus.com/bid/23437
Summary:
Opera Web Browser is prone to an unspecified vulnerability when running A=
dobe Flash Player.

Currently very little is known regarding this issue. This BID will be upd=
ated as more information becomes available.

Opera Web Browser versions prior to 9.20 are vulnerable.
Adobe Flash Player versions prior to 9.0.28.0 are vulnerable.

11. Drupal Database Administration Module Multiple HTML-injection Vulnera=
bilities
BugTraq ID: 23440
Remote: Yes
Date Published: 2007-04-12
Relevant URL: http://www.securityfocus.com/bid/23440
Summary:
Drupal Database Administration Module is prone to multiple HTML-injection=
 vulnerabilities because it fails to sufficiently sanitize user-supplied =
input before displaying it in dynamically generated content.

To exploit this issue, an attacker must have Site Administrator privilege=
s.

An attacker could exploit this vulnerability to execute arbitrary script =
code in the browser of an unsuspecting victim in the context of the affec=
ted site. This may allow the attacker to steal cookie-based authenticatio=
n credentials and to launch other attacks.

Drupal Database Administration versions prior to 4.7.0-1.2 and all versio=
ns of the 4.6.0 branch are vulnerable to these issues.

12. WebKalk2 Engine.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 23451
Remote: Yes
Date Published: 2007-04-12
Relevant URL: http://www.securityfocus.com/bid/23451
Summary:
WebKalk2 is prone to a remote file-include vulnerability because it fails=
 to sufficiently sanitize user-supplied input.

Exploiting this issue may allow an attacker to compromise the application=
 and the underlying system; other attacks are also possible.

WebKalk2 1.9.0 is vulnerable.

13. FreeRadius EAP-TTLS Tunnel Memory Leak Remote Denial Of Service Vulne=
rability
BugTraq ID: 23466
Remote: Yes
Date Published: 2007-04-12
Relevant URL: http://www.securityfocus.com/bid/23466
Summary:
FreeRADIUS is prone to a denial-of-service vulnerability.=20

This vulnerability presents itself when an attacker sends malformed data =
inside an EAP-TTLS tunnel.

14. Clam AntiVirus ClamAV Multiple Remote Vulnerabilities
BugTraq ID: 23473
Remote: Yes
Date Published: 2007-04-13
Relevant URL: http://www.securityfocus.com/bid/23473
Summary:
ClamAV is prone to a file-descriptor leakage vulnerability and a buffer-o=
verflow vulnerability.

A successful attack may allow an attacker to obtain sensitive information=
, cause denial-of-service conditions, and execute arbitrary code in the c=
ontext of the user running the affected application.

ClamAV versions prior to 0.90.2 are vulnerable to these issues.

15. ScramDisk 4 Linux Local Privilege Escalation Vulnerabilities
BugTraq ID: 23495
Remote: No
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23495
Summary:
ScramDisk is prone to multiple local privilege-escalation vulnerabilities=
.

Exploiting these issues allows local attackers to attain superuser privil=
eges, which can lead to a complete system compromise.

These issues affect versions prior to 1.0-1.

16. Lighttpd Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 23515
Remote: Yes
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23515
Summary:
Lighttpd is prone to multiple remote denial-of-service vulnerabilities be=
cause the application fails to properly handle unexpected conditions.

Successfully exploiting these issues allows remote attackers to trigger a=
n infinite loop, consuming excessive CPU resources, or to crash affected =
servers via a NULL-pointer dereference. This will deny further service to=
 legitimate users.

Lighttpd versions prior to 1.4.14 are vulnerable.

17. Vixie Cron ST_Nlink Check Local Denial of Service Vulnerability
BugTraq ID: 23520
Remote: No
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23520
Summary:
Vixie Cron is prone to a local denial-of-service vulnerability.=20

This issue occurs when attackers create hard file links to cron files bel=
onging to both privileged and normal users.

A local attacker may exploit this issue to prevent cron files owned by pr=
ivileged and non-privileged users from being executed at startup or on th=
e next reload of the cron database.

Vixie Cron versions prior to 4.1-r10 are vulnerable.

18. Oracle April 2007 Security Update Multiple Vulnerabilities
BugTraq ID: 23532
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23532
Summary:
Oracle has released a Critical Patch Update advisory for April 2007 to ad=
dress these vulnerabilities for supported releases. Earlier unsupported r=
eleases are likely to be affected by these issues as well.

The issues identified by the vendor affect all security properties of the=
 Oracle products and present local and remote threats. Various levels of =
authorization are needed to leverage some of the issues, but other issues=
 do not require any authorization. The most severe of the vulnerabilities=
 could possibly expose affected computers to complete compromise.

19. McAfee E-Business Administration Server Authentication Packet Denial =
of Service Vulnerability
BugTraq ID: 23544
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23544
Summary:
McAfee E-Business Administration Server is prone to a remote denial-of-se=
rvice vulnerability because the application fails to properly handle cert=
ain network packets. A successful attack allows a remote attacker to cras=
h the Administration Server, denying further service to legitimate users.

These versions are affected:

E-Business Server 8.5.1 (and earlier) for Windows and Solaris
E-Business Server 8.1.0 (and earlier) for Linux, HP-UX, and AIX

20. 3proxy HTTP Proxy Request Buffer Overflow Vulnerability
BugTraq ID: 23545
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23545
Summary:
3proxy is prone to a buffer-overflow vulnerability because it fails to ad=
equately bounds-check user-supplied data before copying it to an insuffic=
iently sized buffer.

Attackers can exploit this issue to cause denial-of-service conditions an=
d possibly to execute arbitrary code with the privileges of the applicati=
on.

3proxy 0.5 to 0.5.3g and 0.6b-devel before 20070413 are vulnerable to thi=
s issue.

21. ProFTPD AUTH Multiple Authentication Module Security Bypass Vulnerabi=
lity
BugTraq ID: 23546
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/23546
Summary:
ProFTPD is reported prone to a security-restriction-bypass vulnerability =
because of an error in the AUTH API.=20
=20
Attackers may exploit this issue to bypass security controls when multipl=
e modules are configured with disparate authentication policies.=20

ProFTPD 1.2 and 1.3 branches are reported vulnerable; other versions may =
be affected as well.

NOTE: The latest version in the CVS repository reportedly addresses this =
issue.

22. Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
BugTraq ID: 23552
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/23552
Summary:
Dovecot is prone to an information-disclosure vulnerability.=20

An attacker can exploit this issue to access sensitive information that m=
ay lead to further attacks.

23. OpenAFS for Microsoft Windows Local Denial of Service Vulnerability
BugTraq ID: 23566
Remote: No
Date Published: 2007-04-19
Relevant URL: http://www.securityfocus.com/bid/23566
Summary:
OpenAFS for Microsoft Windows is prone to a local denial-of-service vulne=
rability because the application fails to properly handle unexpected cond=
itions.

Successfully exploiting this issue allows local attackers to trigger comp=
uter crashes. These crashes will occur every time Windows tries to start,=
 creating a prolonged denial-of-service condition.

Versions of OpenAFS prior to 1.5.19 running on Windows are vulnerable.=20

Note that this issue is present only if MIT Kerberos for Windows is also =
installed on vulnerable computers.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Kapersky Lab

Try Kaspersky Antivirus 6.0 Software
Download Kaspersky's Award-Winning antivirus & antispyware solution with =
anti-spam and firewall Free

http://newsletter.industrybrains.com/c?fe;1;5f04b;1000f;345;0;da4