SecurityFocus Linux Newsletter #334

[email protected] 25 Apr 2007 00:02:03 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #334
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving=20
hackers complete access to all your backend systems! Firewalls and IDS wi=
ll not stop=20
such attacks because SQL Injections are NOT seen as intruders. Download t=
his *FREE*=20
white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Cn=
8O


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Online Impersonations: No Validation Required
II.  LINUX VULNERABILITY SUMMARY
       1. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabi=
lities
       2. ScramDisk 4 Linux Local Privilege Escalation Vulnerabilities
       3. Lighttpd Multiple Remote Denial of Service Vulnerabilities
       4. Vixie Cron ST_Nlink Check Local Denial of Service Vulnerability
       5. Oracle April 2007 Security Update Multiple Vulnerabilities
       6. McAfee E-Business Administration Server Authentication Packet D=
enial of Service Vulnerability
       7. 3proxy HTTP Proxy Request Buffer Overflow Vulnerability
       8. ProFTPD AUTH Multiple Authentication Module Security Bypass Vul=
nerability
       9. Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
       10. OpenAFS for Microsoft Windows Local Denial of Service Vulnerab=
ility
       11. Courier-IMAP XMAILDIR Shell Command Injection Vulnerability
       12. Linux Kernel L2CAP and HCI Setsockopt Memory Leak Information =
Disclosure Vulnerability
       13. OpenSSH S/Key Remote Information Disclosure Vulnerability
       14. PostgreSQL SECURITY DEFINER Function Local Privilege Escalatio=
n Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Online Impersonations: No Validation Required
By Dr. Neal Krawetz
It is said that imitation is the sincerest form of flattery. Unfortunatel=
y, online social networks provide no method for distinguishing an imperso=
nation from the real thing. While your online words and actions may circu=
late for years, so do those of an impersonator.
http://www.securityfocus.com/columnists/441


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 21668
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/21668
Summary:
The Mozilla Foundation has released nine security advisories specifying v=
ulnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- inject arbitrary content
- gain escalated privileges
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

2. ScramDisk 4 Linux Local Privilege Escalation Vulnerabilities
BugTraq ID: 23495
Remote: No
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23495
Summary:
ScramDisk is prone to multiple local privilege-escalation vulnerabilities=
.

Exploiting these issues allows local attackers to attain superuser privil=
eges, which can lead to a complete system compromise.

These issues affect versions prior to 1.0-1.

3. Lighttpd Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 23515
Remote: Yes
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23515
Summary:
Lighttpd is prone to multiple remote denial-of-service vulnerabilities be=
cause the application fails to properly handle unexpected conditions.

Successfully exploiting these issues allows remote attackers to trigger a=
n infinite loop, consuming excessive CPU resources, or to crash affected =
servers via a NULL-pointer dereference. This will deny further service to=
 legitimate users.

Lighttpd versions prior to 1.4.14 are vulnerable.

4. Vixie Cron ST_Nlink Check Local Denial of Service Vulnerability
BugTraq ID: 23520
Remote: No
Date Published: 2007-04-16
Relevant URL: http://www.securityfocus.com/bid/23520
Summary:
Vixie Cron is prone to a local denial-of-service vulnerability.=20

This issue occurs when attackers create hard file links to cron files bel=
onging to both privileged and normal users.

A local attacker may exploit this issue to prevent cron files owned by pr=
ivileged and non-privileged users from being executed at startup or on th=
e next reload of the cron database.

Vixie Cron versions prior to 4.1-r10 are vulnerable.

5. Oracle April 2007 Security Update Multiple Vulnerabilities
BugTraq ID: 23532
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23532
Summary:
Oracle has released a Critical Patch Update advisory for April 2007 to ad=
dress these vulnerabilities for supported releases. Earlier unsupported r=
eleases are likely to be affected by these issues as well.

The issues identified by the vendor affect all security properties of the=
 Oracle products and present local and remote threats. Various levels of =
authorization are needed to leverage some of the issues, but other issues=
 do not require any authorization. The most severe of the vulnerabilities=
 could possibly expose affected computers to complete compromise.

6. McAfee E-Business Administration Server Authentication Packet Denial o=
f Service Vulnerability
BugTraq ID: 23544
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23544
Summary:
McAfee E-Business Administration Server is prone to a remote denial-of-se=
rvice vulnerability because the application fails to properly handle cert=
ain network packets. A successful attack allows a remote attacker to cras=
h the Administration Server, denying further service to legitimate users.

These versions are affected:

E-Business Server 8.5.1 (and earlier) for Windows and Solaris
E-Business Server 8.1.0 (and earlier) for Linux, HP-UX, and AIX

7. 3proxy HTTP Proxy Request Buffer Overflow Vulnerability
BugTraq ID: 23545
Remote: Yes
Date Published: 2007-04-17
Relevant URL: http://www.securityfocus.com/bid/23545
Summary:
3proxy is prone to a buffer-overflow vulnerability because it fails to ad=
equately bounds-check user-supplied data before copying it to an insuffic=
iently sized buffer.

Attackers can exploit this issue to cause denial-of-service conditions an=
d possibly to execute arbitrary code with the privileges of the applicati=
on.

3proxy 0.5 to 0.5.3g and 0.6b-devel before 20070413 are vulnerable to thi=
s issue.

8. ProFTPD AUTH Multiple Authentication Module Security Bypass Vulnerabil=
ity
BugTraq ID: 23546
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/23546
Summary:
ProFTPD is reported prone to a security-restriction-bypass vulnerability =
because of an error in the AUTH API.=20
=20
Attackers may exploit this issue to bypass security controls when multipl=
e modules are configured with disparate authentication policies.=20

ProFTPD 1.2 and 1.3 branches are reported vulnerable; other versions may =
be affected as well.

NOTE: The latest version in the CVS repository reportedly addresses this =
issue.

9. Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
BugTraq ID: 23552
Remote: Yes
Date Published: 2007-04-18
Relevant URL: http://www.securityfocus.com/bid/23552
Summary:
Dovecot is prone to an information-disclosure vulnerability.=20

An attacker can exploit this issue to access sensitive information that m=
ay lead to further attacks.

10. OpenAFS for Microsoft Windows Local Denial of Service Vulnerability
BugTraq ID: 23566
Remote: No
Date Published: 2007-04-19
Relevant URL: http://www.securityfocus.com/bid/23566
Summary:
OpenAFS for Microsoft Windows is prone to a local denial-of-service vulne=
rability because the application fails to properly handle unexpected cond=
itions.

Successfully exploiting this issue allows local attackers to trigger comp=
uter crashes. These crashes will occur every time Windows tries to start,=
 creating a prolonged denial-of-service condition.

Versions of OpenAFS prior to 1.5.19 running on Windows are vulnerable.=20

Note that this issue is present only if MIT Kerberos for Windows is also =
installed on vulnerable computers.

11. Courier-IMAP XMAILDIR Shell Command Injection Vulnerability
BugTraq ID: 23589
Remote: Yes
Date Published: 2007-04-22
Relevant URL: http://www.securityfocus.com/bid/23589
Summary:
Courier-IMAP is prone to a shell-command-injection vulnerability.

Commands executed through this vulnerability could permit an attacker to =
gain access to a vulnerable system.

Courier-IMAP versions for Gentoo prior to 4.0.6-r2 are vulnerable to this=
 issue.

12. Linux Kernel L2CAP and HCI Setsockopt Memory Leak Information Disclos=
ure Vulnerability
BugTraq ID: 23594
Remote: No
Date Published: 2007-04-23
Relevant URL: http://www.securityfocus.com/bid/23594
Summary:
Linux Kernel is prone to an information-disclosure vulnerability because =
it fails to handle unexpected user-supplied input.

Successful exploits will allow attackers to view portions of kernel memor=
y. Information harvested may be used in further attacks.

Kernel versions 2.4.34.2 and prior are vulnerable to this issue.

13. OpenSSH S/Key Remote Information Disclosure Vulnerability
BugTraq ID: 23601
Remote: Yes
Date Published: 2007-04-23
Relevant URL: http://www.securityfocus.com/bid/23601
Summary:
OpenSSH contains an information-disclosure vulnerability when S/Key authe=
ntication is enabled. This issue occurs because the application fails to =
properly obscure the existence of valid usernames in authentication attem=
pts.

Exploiting this vulnerability allows remote users to test for the existen=
ce of valid usernames. Knowledge of system users may aid in further attac=
ks.

14. PostgreSQL SECURITY DEFINER Function Local Privilege Escalation Vulne=
rability
BugTraq ID: 23618
Remote: No
Date Published: 2007-04-24
Relevant URL: http://www.securityfocus.com/bid/23618
Summary:
PostgreSQL is prone to a local privilege-escalation vulnerability.

Exploiting this issue allows local attackers to escalate privileges in th=
e context of the 'security_definer' function.=20

PostgreSQL versions prior to 8.2.4, 8.1.9, 8.0.13, 7.4.17, and 7.3.19 are=
 vulnerable to this issue.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics Whit=
e Paper=20
It's as simple as placing additional SQL commands into a Web Form input b=
ox giving=20
hackers complete access to all your backend systems! Firewalls and IDS wi=
ll not stop=20
such attacks because SQL Injections are NOT seen as intruders. Download t=
his *FREE*=20
white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=3D70160000000Cn=
8O