SecurityFocus Linux Newsletter #335
[email protected] 1 May 2007 22:49:16 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #335
----------------------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008uP=
d
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Time for a new certification
II. LINUX VULNERABILITY SUMMARY
1. Courier-IMAP XMAILDIR Shell Command Injection Vulnerability
2. Linux Kernel L2CAP and HCI Setsockopt Memory Leak Information D=
isclosure Vulnerability
3. OpenSSH S/Key Remote Information Disclosure Vulnerability
4. PostgreSQL SECURITY DEFINER Function Local Privilege Escalation=
Vulnerability
5. Computer Associates BrightStor ArcServe Media Server Multiple R=
emote Buffer Overflow Vulnerabilities
6. Cisco NetFlow Collection Engine Remote Default Account Vulnerab=
ility
7. Asterisk ManagerInterface Manager.Conf Remote Denial of Service=
Vulnerability
8. Clam AntiVirus ClamAV PDF Handling Remote Denial Of Service Vul=
nerability
9. Moinmoin Index.PHP Cross-Site Scripting Vulnerability
10. Linux Kernel NETLINK_FIB_LOOKUP Local Denial of Service Vulner=
ability
11. GIMP RAS File Buffer Overflow Vulnerability
12. Iputils Rarpd Remote Denial Of Service Vulnerability
13. Linux Kernel UTrace Unspecified Local Denial of Service Vulner=
ability
14. VIM Feedkeys and Writefile Functions Remote Code Execution Vul=
nerabilities
15. Sun Java Web Start Unauthorized Access Vulnerability
16. VMware Multiple Denial Of Service Vulnerabilities
17. X.Org X Window System Xserver XRender Extension Divide by Zero=
Denial of Service Vulnerability
18. Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerab=
ility
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Time for a new certification
By Don Parker
I wrote a column for Securityfocus some time ago that aired my concerns o=
ver GIAC dropping the practical portion of their certification process. T=
hat column resulted in a lot of feedback, with most agreeing about how GI=
AC bungled what was up till then, the best certification around.
http://www.securityfocus.com/columnists/443
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Courier-IMAP XMAILDIR Shell Command Injection Vulnerability
BugTraq ID: 23589
Remote: Yes
Date Published: 2007-04-22
Relevant URL: http://www.securityfocus.com/bid/23589
Summary:
Courier-IMAP is prone to a shell-command-injection vulnerability.
Commands executed through this vulnerability could permit an attacker to =
gain access to a vulnerable system.
Courier-IMAP versions for Gentoo prior to 4.0.6-r2 are vulnerable to this=
issue.
2. Linux Kernel L2CAP and HCI Setsockopt Memory Leak Information Disclosu=
re Vulnerability
BugTraq ID: 23594
Remote: No
Date Published: 2007-04-23
Relevant URL: http://www.securityfocus.com/bid/23594
Summary:
Linux Kernel is prone to an information-disclosure vulnerability because =
it fails to handle unexpected user-supplied input.
Successful exploits will allow attackers to view portions of kernel memor=
y. Information harvested may be used in further attacks.
Kernel versions 2.4.34.2 and prior are vulnerable to this issue.
3. OpenSSH S/Key Remote Information Disclosure Vulnerability
BugTraq ID: 23601
Remote: Yes
Date Published: 2007-04-23
Relevant URL: http://www.securityfocus.com/bid/23601
Summary:
OpenSSH contains an information-disclosure vulnerability when S/Key authe=
ntication is enabled. This issue occurs because the application fails to =
properly obscure the existence of valid usernames in authentication attem=
pts.
Exploiting this vulnerability allows remote users to test for the existen=
ce of valid usernames. Knowledge of system users may aid in further attac=
ks.
4. PostgreSQL SECURITY DEFINER Function Local Privilege Escalation Vulner=
ability
BugTraq ID: 23618
Remote: No
Date Published: 2007-04-24
Relevant URL: http://www.securityfocus.com/bid/23618
Summary:
PostgreSQL is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to escalate privileges in th=
e context of the 'security_definer' function.=20
PostgreSQL versions prior to 8.2.4, 8.1.9, 8.0.13, 7.4.17, and 7.3.19 are=
vulnerable to this issue.
5. Computer Associates BrightStor ArcServe Media Server Multiple Remote B=
uffer Overflow Vulnerabilities
BugTraq ID: 23635
Remote: Yes
Date Published: 2007-04-24
Relevant URL: http://www.securityfocus.com/bid/23635
Summary:
Computer Associates BrightStor ARCServe Media Server is prone to multiple=
remote buffer-overflow vulnerabilities because it fails to properly boun=
ds-check user-supplied data before copying it into an insufficiently size=
d memory buffer.
A remote attacker may exploit these issue to execute arbitrary code with=
SYSTEM-level privileges. Successful exploits can result in a complete co=
mpromise of affected computers. Failed exploit attempts will likely cause=
denial-of-service conditions.
6. Cisco NetFlow Collection Engine Remote Default Account Vulnerability
BugTraq ID: 23647
Remote: Yes
Date Published: 2007-04-25
Relevant URL: http://www.securityfocus.com/bid/23647
Summary:
Cisco NetFlow Collection Engine (NFC) is prone to a default-account vulne=
rability. This issue stems from a design flaw that makes an insecure acco=
unt available to remote users.
Successfully exploiting this issue allows remote attackers to gain admini=
strative access to the vulnerable application and user-level access to th=
e hosting operating system.
Versions of Cisco NFC prior to 6.0 are vulnerable to this issue.
Cisco is tracking this issue as Cisco Bug ID CSCsh75038.
7. Asterisk ManagerInterface Manager.Conf Remote Denial of Service Vulner=
ability
BugTraq ID: 23649
Remote: Yes
Date Published: 2007-04-25
Relevant URL: http://www.securityfocus.com/bid/23649
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because the=
application fails to properly handle exceptional conditions.=20
Exploiting this issue allows remote attackers to cause the application to=
crash, effectively denying service to legitimate users.
8. Clam AntiVirus ClamAV PDF Handling Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 23656
Remote: Yes
Date Published: 2007-04-25
Relevant URL: http://www.securityfocus.com/bid/23656
Summary:
ClamAV is prone to a denial-of-service vulnerability.
A successful attack may allow an attacker to cause denial-of-service cond=
itions.
9. Moinmoin Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 23676
Remote: Yes
Date Published: 2007-04-26
Relevant URL: http://www.securityfocus.com/bid/23676
Summary:
Moinmoin is prone to a cross-site scripting vulnerability because the app=
lication fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
Moinmoin 1.5.7 is vulnerable; other versions may also be affected.
10. Linux Kernel NETLINK_FIB_LOOKUP Local Denial of Service Vulnerability
BugTraq ID: 23677
Remote: No
Date Published: 2007-04-26
Relevant URL: http://www.securityfocus.com/bid/23677
Summary:
The Linux kernel is prone to a denial-of-service vulnerability. This issu=
e presents itself when a NETLINK message is misrouted.
A local attacker may exploit this issue to trigger an infinite-recursion =
stack-based overflow in the kernel. This results in a denial of service t=
o legitimate users.
Versions prior to 2.6.20.8 are vulnerable.
11. GIMP RAS File Buffer Overflow Vulnerability
BugTraq ID: 23680
Remote: Yes
Date Published: 2007-04-26
Relevant URL: http://www.securityfocus.com/bid/23680
Summary:
GIMP is prone to a buffer-overflow vulnerability because it fails to prop=
erly bounds-check user-supplied input data before copying it to an insuff=
iciently sized memory buffer.
Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of the affected application.
GIMP 2.2.14 is vulnerable to this issue; other versions may also be affec=
ted.
12. Iputils Rarpd Remote Denial Of Service Vulnerability
BugTraq ID: 23706
Remote: Yes
Date Published: 2007-04-30
Relevant URL: http://www.securityfocus.com/bid/23706
Summary:
The 'iputils rarpd' program is affected by a remote denial-of-service vul=
nerability because the software fails to properly handle certain network =
packets.
A successful attack allows a remote attacker to crash the application, de=
nying further service to legitimate users.
13. Linux Kernel UTrace Unspecified Local Denial of Service Vulnerability
BugTraq ID: 23720
Remote: No
Date Published: 2007-04-30
Relevant URL: http://www.securityfocus.com/bid/23720
Summary:
The Linux kernel is prone to a denial-of-service vulnerability that stems=
from a flaw in 'utrace' support.
A local attacker may exploit this issue to cause the affected kernel to c=
rash, effectively denying service to legitimate users.
14. VIM Feedkeys and Writefile Functions Remote Code Execution Vulnerabil=
ities
BugTraq ID: 23725
Remote: Yes
Date Published: 2007-04-30
Relevant URL: http://www.securityfocus.com/bid/23725
Summary:
VIM is prone to multiple vulnerabilities that permit a remote attacker to=
execute arbitrary code.=20
An attacker could exploit these issues by enticing a victim to load a mal=
icious file. A successful exploit could result in the execution of arbitr=
ary code within the context of the affected application.
15. Sun Java Web Start Unauthorized Access Vulnerability
BugTraq ID: 23728
Remote: Yes
Date Published: 2007-04-29
Relevant URL: http://www.securityfocus.com/bid/23728
Summary:
Sun Java Web Start is prone to a vulnerability that may allow remote atta=
ckers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows untrusted applicat=
ions to gain read/write privileges to local files on a vulnerable compute=
r.
The following versions for Windows, Solaris and Linux platforms are vuln=
erable:
Java Web Start in JDK and JRE 5.0 Update 10 and earlier
Java Web Start in SDK and JRE 1.4.2_13 and earlier
16. VMware Multiple Denial Of Service Vulnerabilities
BugTraq ID: 23732
Remote: Yes
Date Published: 2007-05-01
Relevant URL: http://www.securityfocus.com/bid/23732
Summary:
VMware is prone to multiple denial-of-service vulnerabilities. =20
An attacker can exploit these issues to cause denial-of-service conditio=
ns.
Versions prior to 5.5.4 Build 44386 are vulnerable to these issues.
17. X.Org X Window System Xserver XRender Extension Divide by Zero Denial=
of Service Vulnerability
BugTraq ID: 23741
Remote: Yes
Date Published: 2007-05-01
Relevant URL: http://www.securityfocus.com/bid/23741
Summary:
X.Org X Window System Xserver is prone to a denial-of-service vulnerabilt=
y. This issue is due to a failure of the software to properly handle exce=
ptional conditions.
Attackers with the ability to connect to a vulnerable X server may exploi=
t this issue to crash the targeted server, denying futher service to legi=
timate users.
X.Org X Window System Xserver version 1.3.0 is vulnerable to this issue; =
other versions may also be affected.
18. Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
BugTraq ID: 23742
Remote: Yes
Date Published: 2007-05-01
Relevant URL: http://www.securityfocus.com/bid/23742
Summary:
Red Hat Sendmail is prone to a vulnerability that permits an attacker to =
send spoofed emails.
A successful exploit may allow an attacker to impersonate the localhost w=
hen sending an email message.
This issue affects Sendmail on Red Hat systems due to a configuration err=
or. It is not currently known at this time if this issue affects other re=
leased of the software.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008uP=
d