SecurityFocus Linux Newsletter #341

[email protected] 14 Jun 2007 22:40:39 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #341
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cs=
FU


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Embedded Problems
       2. Security Analogies
II.  LINUX VULNERABILITY SUMMARY
       1. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnerab=
ility
       2. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vul=
nerability
       3. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vuln=
erability
       4. Util-linux Login Security Bypass Vulnerability
       5. Mozilla Firefox Beatnik Extension Remote Script Code Execution =
Vulnerability
       6. W3M Browser InputAnswer Format String Vulnerability
       7. LHA Insecure Temporary File Creation Vulnerability
       8. RETIRED: Yahoo! Messenger Multiple Unspecified Remote Code Exec=
ution Vulnerabilities
       9. Linux Kernel Bluetooth Null Pointer Deference Denial Of Service=
 Vulnerability
       10. ClamAV Multiple Unspecified Vulnerabilities
       11. Asterisk SIP Channel Driver UDP Packets Remote Denial of Servi=
ce Vulnerability
       12. Todd Miller Sudo Kerberos Authentication Local Authentication =
Bypass Weakness
       13. Linux Kernel SCTP Connection Denial Of Service Vulnerability
       14. Linux Kernel CPUSet Tasks Memory Leak Information Disclosure V=
ulnerability
       15. Linux Kernel PRNG Entropy Weakness
       16. Novell NetWare Modular Authentication Service Local Informatio=
n Disclosure Vulnerability
       17. Firebird SQL Fbserver Remote Buffer Overflow Vulnerability
       18. OpenOffice RTF File Parser Buffer Overflow Vulnerability
       19. EXIF Library EXIF File Processing Integer Overflow Vulnerabili=
ty
       20. Open ISCSI Multiple Local Denial Of Service Vulnerabilities
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Embedded Problems
By Federico Biancuzzi
Federico Biancuzzi interviews Barnaby Jack to discuss the vector rewrite =
attack, which architectures are vulnerable, how to defend the integrity o=
f the exception vector table, some firmware extraction methods, and what =
bad things you can do on a cheap SOHO router.
http://www.securityfocus.com/columnists/446

2. Security Analogies
By Scott Granneman
Scott Granneman discusses security analogies and their function in educat=
ing the masses on security concepts.
http://www.securityfocus.com/columnists/445


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnerability
BugTraq ID: 24287
Remote: No
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24287
Summary:
The 'sudo' utility and the 'ptrace' call are prone to a local privilege-e=
scalation vulnerability.=20

An attacker can exploit this issue to execute arbitrary commands with sup=
eruser privileges. Successfully exploiting this issue will result in the =
complete compromise of affected computers.

2. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 24289
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24289
Summary:
ClamAV is prone to a denial-of-service vulnerability.

A successful attack may allow an attacker to cause denial-of-service cond=
itions.

3. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vulnerabili=
ty
BugTraq ID: 24316
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24316
Summary:
ClamAV is prone to a denial-of-service vulnerability when handling malfor=
med OLE2 files.

A successful attack may allow an attacker to cause denial-of-service cond=
itions.
=20
Versions prior to ClamAV 0.90.3 are affected.

4. Util-linux Login Security Bypass Vulnerability
BugTraq ID: 24321
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24321
Summary:
The 'login' utility (in 'util-linux') is prone to a security-bypass vulne=
rability because the utility fails to properly validate user privileges.

Exploiting this issue can allow an attacker to bypass certain security re=
strictions and potentially gain unauthorized access.

Versions prior to 'util-linux' 2.12 are vulnerable.

5. Mozilla Firefox Beatnik Extension Remote Script Code Execution Vulnera=
bility
BugTraq ID: 24324
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24324
Summary:
A remote code-execution vulnerability affects the Beatnik extension for M=
ozilla Firefox because the application fails to validate input errors whe=
n processing RSS feeds.
=20
An attacker may leverage this issue to execute arbitrary code in the cont=
ext of the user account running the affected extension. This may facilita=
te cross-site scripting as well as a compromise of an affected computer.

Beatnik 1.0 is vulnerable; other versions may also be affected.

6. W3M Browser InputAnswer Format String Vulnerability
BugTraq ID: 24332
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24332
Summary:
W3M is prone to a format-string vulnerability because it fails to properl=
y sanitize user-supplied input before passing it as the format specifier =
to a formatted-printing function.

An attack can exploit this issue to execute arbitrary machine code in the=
 context of the user running the affected browser. A successful attack wi=
ll compromise the application. Failed attempts may cause denial-of-servic=
e conditions.

Versions prior to W3M  0.5.2 are vulnerable.

7. LHA Insecure Temporary File Creation Vulnerability
BugTraq ID: 24336
Remote: No
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24336
Summary:
The 'lha' program creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20

Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.

8. RETIRED: Yahoo! Messenger Multiple Unspecified Remote Code Execution V=
ulnerabilities
BugTraq ID: 24341
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24341
Summary:
Yahoo! Messenger is prone to multiple unspecified remote code-execution v=
ulnerabilities.

No further details are currently available.  We will update this BID as m=
ore information emerges.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers.

Specific vulnerable versions of Yahoo! Messenger are not known, but versi=
ons in the 8 series for Microsoft Windows are reported affected.

UPDATE (June 7, 2007): The vendor announced that a fix is being developed=
 to address this issue.

This BID has been replaced by the following writeups:

BID 24355 Yahoo! Messenger Webcam Viewer ActiveX Control Buffer Overflow =
Vulnerability     =20
BID 24354 Yahoo! Messenger Webcam Upload ActiveX Control Buffer Overflow =
Vulnerability

9. Linux Kernel Bluetooth Null Pointer Deference Denial Of Service Vulner=
ability
BugTraq ID: 24350
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24350
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.=20

An attacker can exploit this issue to crash the affected operating system=
, denying service to legitimate users.=20

Versions prior to 2.4.33.5 are vulnerable to this issue.

10. ClamAV Multiple Unspecified Vulnerabilities
BugTraq ID: 24358
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24358
Summary:
ClamAV is prone to multiple unspecified vulnerabilities.

These issues arise because the software incorrectly calculates the end of=
 a buffer and gives improper permissions to temporary files.

Versions prior to ClamAV 0.90.3 are vulnerable to these issues.

11. Asterisk SIP Channel Driver UDP Packets Remote Denial of Service Vuln=
erability
BugTraq ID: 24359
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24359
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because the=
 application fails to properly handle certain SIP UDP packets.

Exploiting this issue allows remote attackers to cause the application to=
 crash, effectively denying service to legitimate users.

NOTE: This record may be a duplicate of the issue discussed in BID 23093 =
(Asterisk SIP Channel Driver Response Code Zero Remote Denial of Service =
Vulnerability). We are still investigating this issue and will retire thi=
s BID if we find it to be a duplicate.

12. Todd Miller Sudo Kerberos Authentication Local Authentication Bypass =
Weakness
BugTraq ID: 24368
Remote: No
Date Published: 2007-06-07
Relevant URL: http://www.securityfocus.com/bid/24368
Summary:
The 'sudo' utility is prone to a local authentication-bypass weakness whe=
n used in conjunction with Kerberos. Attackers must first gain local, int=
eractive access to a computer running 'sudo' configured to authenticate v=
ia Kerberos. They may do this by exploiting other latent vulnerabilities.

Successfully exploiting this issue allows local attackers to bypass sudo'=
s authentication prompt, allowing them to perform actions that are grante=
d to users via the 'sudoers' file.

This issue affects 'sudo' 1.6.8p12; other versions may also be affected.

13. Linux Kernel SCTP Connection Denial Of Service Vulnerability
BugTraq ID: 24376
Remote: Yes
Date Published: 2007-06-08
Relevant URL: http://www.securityfocus.com/bid/24376
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.

Linux kernel versions prior to 2.6.21.4 are vulnerable to this issue.

This BID initially discussed three weaknesses/vulnerabilities in the Linu=
x kernel. These issues have been separated into the following individual =
records:

24389 Linux Kernel CPUSet Tasks Memory Leak Information Disclosure Vulner=
ability
24390 Linux Kernel PRNG Entropy Weakness
24376 Linux Kernel SCTP Connection Denial Of Service Vulnerability

14. Linux Kernel CPUSet Tasks Memory Leak Information Disclosure Vulnerab=
ility
BugTraq ID: 24389
Remote: No
Date Published: 2007-06-08
Relevant URL: http://www.securityfocus.com/bid/24389
Summary:
The Linux kernel is prone to an information-disclosure vulnerability beca=
use it fails to handle unexpected user-supplied input.

Successful exploits will allow attackers to obtain portions of kernel mem=
ory. Information harvested may aid in further attacks.

Versions of the Linux kernel prior to 2.6.21.4 and 2.6.20.13 are vulnerab=
le.

 This issue was initially reported in BID 24376 Linux Kernel Multiple Wea=
knesses and Vulnerabilities, but has been assigned its own record.

15. Linux Kernel PRNG Entropy Weakness
BugTraq ID: 24390
Remote: No
Date Published: 2007-06-08
Relevant URL: http://www.securityfocus.com/bid/24390
Summary:
The Linux kernel is prone to a weakness that may result in weaker cryptog=
raphic security.

Linux kernel versions prior to 2.6.21.4 are vulnerable to this issue.

This weakness was initially discussed in BID 24376 (Linux Kernel Multiple=
 Weaknesses and Vulnerabilities), but has been assigned its own record.

16. Novell NetWare Modular Authentication Service Local Information Discl=
osure Vulnerability
BugTraq ID: 24405
Remote: No
Date Published: 2007-06-07
Relevant URL: http://www.securityfocus.com/bid/24405
Summary:
Novell NetWare Modular Authentication Service (NMAS) is prone to a local =
information-disclosure vulnerability because 'NMASINST' dumps the admin a=
ccount and password into a log file in clear text.

The flaw presents itself in NMAS 3.1.2; prior versions are also affected.

17. Firebird SQL Fbserver Remote Buffer Overflow Vulnerability
BugTraq ID: 24436
Remote: Yes
Date Published: 2007-06-12
Relevant URL: http://www.securityfocus.com/bid/24436
Summary:
Firebird SQL is prone to a remote buffer-overflow vulnerability.=20
=20
An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected database server. Failed exploit attempts will =
likely crash the server, denying service to legitimate users. =20

Firebird SQL 2.0 is vulnerable; previous versions may also be affected.

18. OpenOffice RTF File Parser Buffer Overflow Vulnerability
BugTraq ID: 24450
Remote: Yes
Date Published: 2007-06-12
Relevant URL: http://www.securityfocus.com/bid/24450
Summary:
OpenOffice is prone to a remote heap-based buffer-overflow vulnerability =
because the application fails to bounds-check user-supplied data before c=
opying it into an insufficiently sized buffer.

Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted RTF files.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.

19. EXIF Library EXIF File Processing Integer Overflow Vulnerability
BugTraq ID: 24461
Remote: Yes
Date Published: 2007-06-13
Relevant URL: http://www.securityfocus.com/bid/24461
Summary:
The 'libexif' library is reported prone to an integer-overflow vulnerabil=
ity. Reportedly, the issue presents itself when the affected library is p=
rocessing malformed EXIF files. =20
=20
Attackers may leverage this issue to execute arbitrary code in the contex=
t of an application that is linked to the vulnerable library. Failed expl=
oit attempts will likely result in denial-of-service conditions.

This issue affects 'libexif' 0.6.13 to 0.6.15; other versions may also be=
 affected.

20. Open ISCSI Multiple Local Denial Of Service Vulnerabilities
BugTraq ID: 24471
Remote: No
Date Published: 2007-06-14
Relevant URL: http://www.securityfocus.com/bid/24471
Summary:
Open-iSCSI is prone to multiple local denial-of-service vulnerabilities.

A local attacker can exploit these issues to deny legitimate user access =
to the server daemon.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cs=
FU