SecurityFocus Linux Newsletter #344
[email protected] 4 Jul 2007 21:35:07 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #344
----------------------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701700000008yk=
a
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Don't Be Evil
2. Persistence of data on storage media
II. LINUX VULNERABILITY SUMMARY
1. Hiki Session ID File Deletion Vulnerability
2. Avahi Empty TXT Data Denial Of Service Vulnerability
3. Red Hat Kernel SysFS_ReadDir NULL Pointer Dereference Vulnerabi=
lity
4. Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerabilit=
y
5. SlackRoll GnuPG And HTTP Codes Signature Validation Bypass Vuln=
erability And Weakness
6. Apache HTTP Server Mod_Cache Denial of Service Vulnerability
7. MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function=
Stack Buffer Overflow Vulnerability
8. MIT Kerberos Administration Daemon RPC Library Free Pointer Rem=
ote Code Execution Vulnerability
9. MIT Kerberos 5 KAdminD Server RPC Type Conversion Stack Buffer =
Overflow Vulnerability
10. RealPlayer/HelixPlayer ParseWallClockValue Function Buffer Ove=
rflow Vulnerability
11. Wireshark Multiple Protocol Denial of Service Vulnerabilities
12. CA BrightStor ARCserve Backup Server Unspecified Remote Code E=
xecution Vulnerability
13. Sun JavaDoc Tool Cross-Site Scripting Vulnerability
14. GSAMBAD Insecure Temporary File Creation Vulnerability
15. Fireflier-Server Insecure Temporary File Creation Vulnerabilit=
y
16. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnera=
bility
17. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulne=
rability
18. SlackRoll Malicious Package Denial of Service Vulnerability
19. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerabil=
ity
20. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerabi=
lity
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Don't Be Evil
By Mark Rasch
A series of developments raise the specter that remotely stored or create=
d documents may be subject to subpoena or discovery all without the knowl=
edge or consent of the document's creators.
http://www.securityfocus.com/columnists/447
2. Persistence of data on storage media
By Jamie Ridden
Jamie Ridden discusses the re-use of storage media and how slack space ca=
n prevent sensitive data from being completely removed.
http://www.securityfocus.com/infocus/1891
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Hiki Session ID File Deletion Vulnerability
BugTraq ID: 24603
Remote: Yes
Date Published: 2007-06-24
Relevant URL: http://www.securityfocus.com/bid/24603
Summary:
Hiki is prone to a vulnerability that allows an attacker to delete arbitr=
ary files because of an error in the way it deletes files when a user log=
s out.
An attacker can exploit this vulnerability to delete arbitrary files in t=
he context of the affected software, which can allow the attacker to caus=
e significant damage to an installation, potentially denying service to l=
egitimate users.
2. Avahi Empty TXT Data Denial Of Service Vulnerability
BugTraq ID: 24614
Remote: No
Date Published: 2007-06-25
Relevant URL: http://www.securityfocus.com/bid/24614
Summary:
Avahi is prone to a denial-of-service vulnerability.
A local attacker may exploit this issue to cause the application to crash=
, denying further service to legitimate users.
Versions prior to 0.6.20 are vulnerable to this issue.
3. Red Hat Kernel SysFS_ReadDir NULL Pointer Dereference Vulnerability
BugTraq ID: 24631
Remote: No
Date Published: 2007-06-25
Relevant URL: http://www.securityfocus.com/bid/24631
Summary:
The Red Hat kernel is prone to a NULL-pointer dereference vulnerability.
A local attacker can exploit this issue to crash the affected kernel, den=
ying service to legitimate users.=20
UPDATE (June 26, 2007): Given the nature of this issue, remote code execu=
tion may also be possible but has not been confirmed.
4. Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
BugTraq ID: 24645
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24645
Summary:
The Apache HTTP Server mod_status module is prone to a cross-site scripti=
ng vulnerability because the application fails to properly sanitize user-=
supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
5. SlackRoll GnuPG And HTTP Codes Signature Validation Bypass Vulnerabili=
ty And Weakness
BugTraq ID: 24648
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24648
Summary:
SlackRoll is prone to a signature-validation bypass vulnerability and an =
HTTP-error detection weakness
These issues occur because the application fails to adequately interpret =
certain GnuPG exit codes and HTTP error codes.
An attacker can exploit these issues to bypass GnuPG signature detection.=
Successful attacks could result in the execution of arbitrary code; othe=
r attacks are possible.
Versions prior to SlackRoll 8 are vulnerable.
6. Apache HTTP Server Mod_Cache Denial of Service Vulnerability
BugTraq ID: 24649
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24649
Summary:
The Apache mod_cache module is prone to a denial-of-service vulnerability=
.
A remote attacker may be able to exploit this issue to crash the child pr=
ocess. This could lead to denial-of-service conditions if the server is u=
sing a multithreaded Multi-Processing Module (MPM).
7. MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack =
Buffer Overflow Vulnerability
BugTraq ID: 24653
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24653
Summary:
Kerberos 5 'kadmind' (Kerberos Administration Daemon) server is prone to =
a stack-based buffer-overflow vulnerability because the software fails to=
adequately bounds-check user-supplied data before copying it to an insuf=
ficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with adminis=
trative privileges. A successful attack can result in the complete compro=
mise of the application. Failed attempts will likely result in denial-of-=
service conditions.
All 'kadmind' servers run on the master Kerberos server. Since the maste=
r server holds the KDC principal and policy database, an attack may not =
only compromise the affected computer, but could also compromise multipl=
e hosts that use the server for authentication.
Kerberos 5 'kadmind' 1.6.1, 1.5.3, and prior versions are vulnerable.
8. MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Cod=
e Execution Vulnerability
BugTraq ID: 24655
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24655
Summary:
MIT Kerberos 5 Administration Daemon (kadmind) is prone to a remote code-=
execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, completely compromising affected computers. Failed exploit=
attempts will likely result in a denial-of-service conditions.
All kadmind servers run on the master Kerberos server. Since the master s=
erver holds the KDC principal and policy database, an attack may not only=
compromise the affected computer, but could also compromise multiple hos=
ts that use the server for authentication.
This issue also affects third-party applications using the affected RPC l=
ibrary.
kadmind versions prior to krb5-1.6.1 are vulnerable.
9. MIT Kerberos 5 KAdminD Server RPC Type Conversion Stack Buffer Overflo=
w Vulnerability
BugTraq ID: 24657
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24657
Summary:
Kerberos 5 'kadmind' (Kerberos Administration Daemon) server is prone to =
a stack-based buffer-overflow vulnerability because the software fails to=
adequately bounds-check user-supplied data before copying it to an insuf=
ficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with adminis=
trative privileges. A successful attack can result in the complete compro=
mise of the application. Failed attempts will likely result in denial-of-=
service conditions.
This issue also affects third-party applications using the affected RPC l=
ibrary.
All 'kadmind' servers run on the master Kerberos server. Since the maste=
r server holds the KDC principal and policy database, an attack may not =
only compromise the affected computer, but could also compromise multipl=
e hosts that use the server for authentication.
Kerberos 5 'kadmind' 1.6.1 and prior versions are vulnerable.
10. RealPlayer/HelixPlayer ParseWallClockValue Function Buffer Overflow V=
ulnerability
BugTraq ID: 24658
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24658
Summary:
RealPlayer and HelixPlayer are prone to a buffer-overflow vulnerability =
because the applications fail to bounds-check user-supplied data before c=
opying it into an insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
This issue affects RealPlayer 10.5-GOLD and HelixPlayer 10.5-GOLD; other =
versions may also be affected.
11. Wireshark Multiple Protocol Denial of Service Vulnerabilities
BugTraq ID: 24662
Remote: Yes
Date Published: 2007-06-26
Relevant URL: http://www.securityfocus.com/bid/24662
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may permit attackers to cause crashes and deny se=
rvice to legitimate users of the application.
Wireshark versions prior to 0.99.6 are affected.
12. CA BrightStor ARCserve Backup Server Unspecified Remote Code Executio=
n Vulnerability
BugTraq ID: 24680
Remote: Yes
Date Published: 2007-06-27
Relevant URL: http://www.securityfocus.com/bid/24680
Summary:
Computer Associates BrightStor ARCserve Backup is prone to a remote code-=
execution vulnerability.
Currently, very few details are available regarding this issue. We will u=
pdate this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-le=
vel privileges.
BrightStor ARCserve Backup 11.5 SP3 for Microsoft Windows is reported vul=
nerable; other versions may also be affected.
13. Sun JavaDoc Tool Cross-Site Scripting Vulnerability
BugTraq ID: 24690
Remote: Yes
Date Published: 2007-06-28
Relevant URL: http://www.securityfocus.com/bid/24690
Summary:
Sun JavaDoc Tool is prone to a cross-site scripting vulnerability.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
14. GSAMBAD Insecure Temporary File Creation Vulnerability
BugTraq ID: 24717
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24717
Summary:
GSAMBAD creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
An attacker may leverage this issue to corrupt or overwrite arbitrary fil=
es with the privileges of an unsuspecting user that activated the affecte=
d application. Reportedly, attackers can exploit this issue to escalate p=
rivileges.
All versions of GSAMBAD are considered to be vulnerable to this issue.
15. Fireflier-Server Insecure Temporary File Creation Vulnerability
BugTraq ID: 24718
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24718
Summary:
Fireflier-Server application creates temporary files in an insecure manne=
r.
An attacker with local access could potentially exploit this issue to rem=
ove arbitrary files from the local system. =20
Successfully mounting a symlink attack may allow the attacker to remove s=
ensitive files, which may result in a denial of service. Other attacks ma=
y also be possible.
16. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnerability
BugTraq ID: 24721
Remote: Yes
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24721
Summary:
phpEventCalendar is prone to an SQL-injection vulnerability because it fa=
ils to sufficiently sanitize user-supplied data before using it in an SQL=
query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
phpEventCalendar 0.2.3 and prior versions are reported prone to this issu=
e.
17. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulnerabilit=
y
BugTraq ID: 24734
Remote: No
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24734
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability because it=
fails to limit memory consumption by 'fast writers'.
Attackers can exploit this issue to consume memory, resulting in denial-o=
f-service conditions.
Versions prior to 2.6.22-rc7 are vulnerable.
18. SlackRoll Malicious Package Denial of Service Vulnerability
BugTraq ID: 24739
Remote: Yes
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24739
Summary:
SlackRoll is prone to a denial-of-service vulnerability.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
This issue affects versions prior to SlackRoll 10.
19. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerability
BugTraq ID: 24750
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24750
Summary:
ImLib is prone to a denial-of-service vulnerability because the applicati=
on fails to properly process certain BMP image files.
Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted BMP files.
An attacker could exploit this issue to cause denial-of-service condition=
s on applications using the affected library.
20. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerability
BugTraq ID: 24758
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24758
Summary:
GNU glibc is prone to an integer-overflow vulnerability because it fails =
to properly ensure that integer math operations do not result in overflow=
.
An attacker can exploit this issue to execute arbitrary code with super=
user privileges. Successfully exploiting this issue will result in the =
complete compromise of affected application. Failed exploit attempts will=
result in a denial-of-service.=20
Versions 2.5 and prior vulnerable to this issue.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701700000008yk=
a