SecurityFocus Linux Newsletter #340

[email protected] 6 Jun 2007 23:54:05 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #340
----------------------------------------

This Issue is Sponsored by: Norwich University

Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
 and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
 and Department of Homeland Security as a "Center for Academic Excellence=
 in Information Assurance Education"

For more information, visit http://www.msia.norwich.edu/lsec


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Security Analogies
       2. Your Space, My Space, Everybody's Space
II.  LINUX VULNERABILITY SUMMARY
       1. Avira Antivir Antivirus Multiple Remote Vulnerabilities
       2. Mutt Mutt_Gecos_Name Function Local Buffer Overflow Vulnerabili=
ty
       3. Multiple F-Secure Products Packed Executables and Archives Deni=
al of Service Vulnerability
       4. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerabilit=
y
       5. F-Secure Multiple Products Real-time Scanning Component Local P=
rivilege Escalation Vulnerability
       6. Avira Antivir Tar Archive Handling Remote Denial Of Service Vul=
nerability
       7. Mozilla Products Multiple Remote Vulnerabilities
       8. HP System Management Homepage (SMH) Unspecified Cross Site Scri=
pting Vulnerability
       9. PHP Chunk_Split() Function Integer Overflow Vulnerability
       10. Sun Java Runtime Environment Image Parsing Buffer Overflow Vul=
nerability
       11. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnera=
bility
       12. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vul=
nerability
       13. Util-linux Login Security Bypass Vulnerability
       14. Mozilla Firefox Beatnik Extension Remote Script Code Execution=
 Vulnerability
       15. W3M Browser InputAnswer Format String Vulnerability
       16. LHA Insecure Temporary File Creation Vulnerability
       17. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vu=
lnerabilities
III. LINUX FOCUS LIST SUMMARY
       1. Survey on Supercomputer Cluster Security
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Security Analogies
By Scott Granneman
Scott Granneman discusses security analogies and their function in educat=
ing the masses on security concepts.
http://www.securityfocus.com/columnists/445

2. Your Space, My Space, Everybody's Space
By Mark Rasch
Privacy is about protecting data when somebody wants it for some purpose.=
 It is easy to protect data that nobody wants.
http://www.securityfocus.com/columnists/444


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Avira Antivir Antivirus Multiple Remote Vulnerabilities
BugTraq ID: 24187
Remote: Yes
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24187
Summary:
Avira Antivir Antivirus is prone to multiple remote vulnerabilities.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with elevated privileges, facilitating the complete=
 compromise of affected computers. Attackers may also trigger denial-of-s=
ervice conditions by crashing the application or causing infinite loops.

These issues affect:

Avira Antivir AVPack versions prior to 7.03.00.09
Engine versions prior to 7.04.00.24

2. Mutt Mutt_Gecos_Name Function Local Buffer Overflow Vulnerability
BugTraq ID: 24192
Remote: No
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24192
Summary:
Mutt is prone to a local buffer-overflow vulnerability because it fails t=
o properly bounds-check user-supplied input before using it in a memory c=
opy operation.

An attacker can exploit this issue to execute arbitrary code with the wit=
h the privileges of the victim. Failed exploit attempts will result in a =
denial of service.

3. Multiple F-Secure Products Packed Executables and Archives Denial of S=
ervice Vulnerability
BugTraq ID: 24234
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24234
Summary:
Multiple F-Secure products are prone to a denial-of-service vulnerability=
 because the software fails to handle exceptional conditions.=20

An attacker can exploit this issue to cause a denial-of-service conditon.

4. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerability
BugTraq ID: 24235
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24235
Summary:
Multiple F-Secure Anti-Virus applications are prone to a buffer-overflow =
vulnerability when they process certain LHA archive files. This issue occ=
urs because the applications fail to properly check boundaries on user-su=
pplied data before copying it to an insufficiently sized memory buffer.

Successful exploits can allow attackers to execute arbitrary code with th=
e privileges of the vulnerable application. Failed exploit attempts will =
likely result in denial-of-service conditions.

Reports indicate that this vulnerability also occurs when processing malf=
ormed LZH archives, ARJ files, and FSG packed files.

5. F-Secure Multiple Products Real-time Scanning Component Local Privileg=
e Escalation Vulnerability
BugTraq ID: 24237
Remote: No
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24237
Summary:
Multiple F-Secure workstation and file-server products are prone to a loc=
al privilege-escalation vulnerability.
=20
Exploiting this vulnerability allows local attackers to gain superuser or=
 SYSTEM-level privileges, leading to a complete compromise of the affecte=
d computer.

6. Avira Antivir Tar Archive Handling Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 24239
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24239
Summary:
Avira Antivir is prone to a denial-of-service vulnerability because the a=
pplication fails to handle certain TAR archives.

 Remote attackers may exploit this issue by enticing victims into opening=
 maliciously crafted TAR archives.

A successful attack may allow attackers to cause denial-of-service condit=
ions.

7. Mozilla Products Multiple Remote Vulnerabilities
BugTraq ID: 24242
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24242
Summary:
The Mozilla Foundation has released six security advisories specifying vu=
lnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- Execute arbitrary code
- Cause denial-of-service conditions
- Perform cross-site scripting attacks
- Obtain potentially sensitive information
- Spoof legitimate content

Other attacks may also be possible.

8. HP System Management Homepage (SMH) Unspecified Cross Site Scripting V=
ulnerability
BugTraq ID: 24256
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24256
Summary:
HP System Management Homepage is prone to a cross-site scripting vulnerab=
ility.=20

Exploiting this vulnerability may allow an attacker to perform cross-site=
 scripting attacks on unsuspecting users in the context of the affected w=
ebsite. As a result, the attacker may be able to steal cookie-based authe=
ntication credentials and to launch other attacks.

Versions of HP System Management Homepage (SMH) prior to 2.1.2 for Linux =
and Windows are affected.

9. PHP Chunk_Split() Function Integer Overflow Vulnerability
BugTraq ID: 24261
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24261
Summary:
PHP is prone to an integer-overflow vulnerability because it fails to ens=
ure that integer values aren't overrun. Attackers may exploit this issue =
to cause a buffer overflow and to corrupt process memory.

Attackers may be able to execute arbitrary machine code in the context of=
 the affected application. Failed exploit attempts will likely result in =
a denial-of-service condition.

This issue affects versions of PHP prior to 5.2.3.

10. Sun Java Runtime Environment Image Parsing Buffer Overflow Vulnerabil=
ity
BugTraq ID: 24267
Remote: Yes
Date Published: 2007-06-01
Relevant URL: http://www.securityfocus.com/bid/24267
Summary:
The Sun Java Runtime Environment is prone to a buffer-overflow vulnerabil=
ity because the application fails to bounds-check user-supplied data befo=
re copying it into an insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user who invokes a malicious Java applet.

11. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnerability
BugTraq ID: 24287
Remote: No
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24287
Summary:
The 'sudo' utility and the 'ptrace' call are prone to a local privilege-e=
scalation vulnerability.=20

An attacker can exploit this issue to execute arbitrary commands with sup=
eruser privileges. Successfully exploiting this issue will result in the =
complete compromise of affected computers.

12. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 24316
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24316
Summary:
ClamAV is prone to a denial-of-service vulnerability when handling malfor=
med OLE2 files.

A successful attack may allow an attacker to cause denial-of-service cond=
itions.
=20
Versions prior to ClamAV 0.90.3 are affected.

13. Util-linux Login Security Bypass Vulnerability
BugTraq ID: 24321
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24321
Summary:
The 'login' utility (in 'util-linux') is prone to a security-bypass vulne=
rability because the utility fails to properly validate user privileges.

Exploiting this issue can allow an attacker to bypass certain security re=
strictions and potentially gain unauthorized access.

Versions prior to 'util-linux' 2.12 are vulnerable.

14. Mozilla Firefox Beatnik Extension Remote Script Code Execution Vulner=
ability
BugTraq ID: 24324
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24324
Summary:
A remote code-execution vulnerability affects the Beatnik extension for M=
ozilla Firefox because the application fails to validate input errors whe=
n processing RSS feeds.
=20
An attacker may leverage this issue to execute arbitrary code in the cont=
ext of the user account running the affected extension. This may facilita=
te cross-site scripting as well as a compromise of an affected computer.

Beatnik 1.0 is vulnerable; other versions may also be affected.

15. W3M Browser InputAnswer Format String Vulnerability
BugTraq ID: 24332
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24332
Summary:
W3M is prone to a format-string vulnerability because it fails to properl=
y sanitize user-supplied input before passing it as the format specifier =
to a formatted-printing function.

An attack can exploit this issue to execute arbitrary machine code in the=
 context of the user running the affected browser. A successful attack wi=
ll compromise the application. Failed attempts may cause denial-of-servic=
e conditions.

Versions prior to W3M  0.5.2 are vulnerable.

16. LHA Insecure Temporary File Creation Vulnerability
BugTraq ID: 24336
Remote: No
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24336
Summary:
The 'lha' program creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20

Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.

17. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vulnerabi=
lities
BugTraq ID: 24341
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24341
Summary:
Yahoo! Messenger is prone to multiple unspecified remote code-execution v=
ulnerabilities.

No further information is currently available. This BID will be updated a=
s more information is disclosed.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers.

Specific vulnerable Yahoo! Messenger versions are not known, but versions=
 in the 8 series for Microsoft Windows are reportedly affected.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Survey on Supercomputer Cluster Security
http://www.securityfocus.com/archive/91/469540

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Norwich University

Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
 and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
 and Department of Homeland Security as a "Center for Academic Excellence=
 in Information Assurance Education"

For more information, visit http://www.msia.norwich.edu/lsec