SecurityFocus Linux Newsletter #345
[email protected] 11 Jul 2007 19:49:32 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #345
----------------------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Achtung! New German Laws on Cybercrime
2. Don't Be Evil
II. LINUX VULNERABILITY SUMMARY
1. GSAMBAD Insecure Temporary File Creation Vulnerability
2. Fireflier-Server Insecure Temporary File Creation Vulnerability
3. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnerab=
ility
4. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulner=
ability
5. Retired: SlackRoll Malicious Package Denial of Service Vulnerab=
ility
6. GIMP PSD File Integer Overflow Vulnerability
7. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerabili=
ty
8. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerabil=
ity
9. GFax Temporary Files Local Arbitrary Command Execution Vulnerab=
ility
10. JP1/HiCommand Series Products OpenSSL Insecure Protocol Negoti=
ation Weakness
11. Linux Kernel Decode_Choices Function Remote Denial Of Service =
Vulnerability
12. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Servic=
e Vulnerability
13. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulner=
ability
14. Sun Java System Server XSLT Processing Remote Java Method Exec=
ution Vulnerability
15. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Achtung! New German Laws on Cybercrime
By Federico Biancuzzi
Germany is passing some new laws regarding cybercrime that might affect s=
ecurity professionals. Federico Biancuzzi interviewed Marco Gercke, one o=
f the experts that was invited to the parliamentary hearing, to learn mor=
e about this delicate subject. They discussed what is covered by the new =
laws, which areas remain in the dark, and how they might affect vulnerabi=
lity disclosure and the use of common tools, such as nmap.
http://www.securityfocus.com/columnists/448
2. Don't Be Evil
By Mark Rasch
A series of developments raise the specter that remotely stored or create=
d documents may be subject to subpoena or discovery all without the knowl=
edge or consent of the document's creators.
http://www.securityfocus.com/columnists/447
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. GSAMBAD Insecure Temporary File Creation Vulnerability
BugTraq ID: 24717
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24717
Summary:
GSAMBAD creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
An attacker may leverage this issue to corrupt or overwrite arbitrary fil=
es with the privileges of an unsuspecting user that activated the affecte=
d application. Reportedly, attackers can exploit this issue to escalate p=
rivileges.
All versions of GSAMBAD are considered to be vulnerable to this issue.
2. Fireflier-Server Insecure Temporary File Creation Vulnerability
BugTraq ID: 24718
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24718
Summary:
Fireflier-Server application creates temporary files in an insecure manne=
r.
An attacker with local access could potentially exploit this issue to rem=
ove arbitrary files from the local system. =20
Successfully mounting a symlink attack may allow the attacker to remove s=
ensitive files, which may result in a denial of service. Other attacks ma=
y also be possible.
3. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnerability
BugTraq ID: 24721
Remote: Yes
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24721
Summary:
phpEventCalendar is prone to an SQL-injection vulnerability because it fa=
ils to sufficiently sanitize user-supplied data before using it in an SQL=
query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
phpEventCalendar 0.2.3 and prior versions are reported prone to this issu=
e.
4. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulnerability
BugTraq ID: 24734
Remote: No
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24734
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability because it=
fails to limit memory consumption by 'fast writers'.
Attackers can exploit this issue to consume memory, resulting in denial-o=
f-service conditions.
Versions prior to 2.6.22-rc7 are vulnerable.
5. Retired: SlackRoll Malicious Package Denial of Service Vulnerability
BugTraq ID: 24739
Remote: Yes
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24739
Summary:
SlackRoll is prone to a denial-of-service vulnerability.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
This issue affects versions prior to SlackRoll 10.
Further analysis reveals that this issue is not exploitable; therefore, t=
his BID is being retired.
6. GIMP PSD File Integer Overflow Vulnerability
BugTraq ID: 24745
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24745
Summary:
GIMP is prone to an integer-overflow vulnerability because it fails to pr=
operly bounds-check user-supplied input data before copying it to an insu=
fficiently sized memory buffer.
Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of the affected application.
GIMP 2.2.15 is vulnerable to this issue; other versions may also be affec=
ted.
7. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerability
BugTraq ID: 24750
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24750
Summary:
Imlib is prone to a denial-of-service vulnerability because the software =
fails to properly process certain BMP image files.
Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted BMP files.
An attacker could exploit this issue to cause denial-of-service condition=
s on applications using the affected library.
8. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerability
BugTraq ID: 24758
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24758
Summary:
GNU glibc is prone to an integer-overflow vulnerability because it fails =
to properly ensure that integer math operations do not wrap around.=20
An attacker can exploit this issue to execute arbitrary code with super=
user privileges. Successfully exploiting this issue will result in the =
complete compromise of affected application. Failed exploit attempts will=
result in a denial of service.=20
GNU glibc 2.5 and prior versions are prone to this issue.
9. GFax Temporary Files Local Arbitrary Command Execution Vulnerability
BugTraq ID: 24780
Remote: No
Date Published: 2007-07-05
Relevant URL: http://www.securityfocus.com/bid/24780
Summary:
GFAX is prone to a vulnerability that lets local attackers execute arbitr=
ary commands with superuser privileges. Successful attacks will result in=
the complete compromise of affected computers.
GFAX 0.7.6 is vulnerable; other versions may also be affected.
10. JP1/HiCommand Series Products OpenSSL Insecure Protocol Negotiation W=
eakness
BugTraq ID: 24799
Remote: Yes
Date Published: 2007-07-06
Relevant URL: http://www.securityfocus.com/bid/24799
Summary:
JP1/HiCommand Series Products are prone to a remote protocol-negotiation =
weakness due to a design error.
Successful exploits may allow an attacker connecting to the affected serv=
er to replace the SSL 3 or TLS 1 protocol with the SSL 2 protocol. This m=
ay allow the attacker to exploit insecurities in SSL version 2 to gain ac=
cess to or tamper with the clear-text communications between the targeted=
client and server.
This issue may be related to BID: 15071 OpenSSL Insecure Protocol Negotia=
tion Weakness.
11. Linux Kernel Decode_Choices Function Remote Denial Of Service Vulnera=
bility
BugTraq ID: 24818
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24818
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to handle certain H.323 data.
Attackers can exploit this issue to crash the affected operating system, =
denying access to legitimate users.
Versions prior to 2.6.21.6, 2.6.20.15, and 2.6.22 are vulnerable.
12. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Service Vulne=
rability
BugTraq ID: 24845
Remote: No
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24845
Summary:
The PowerPC Linux kernel is prone to a denial-of-service vulnerability.
Exploiting this issue allows local attackers to corrupt memory resources =
and eventually cause the kernel to crash, effectively denying service to =
legitimate users.
Note that this issue affects only the Linux kernel on PowerPC architectur=
es.
13. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability
BugTraq ID: 24846
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24846
Summary:
The Sun JSSE (Java Secure Socket Extension) is prone to a denial-of-servi=
ce vulnerability.
An attacker can exploit this issue to crash the computer, denying access =
to legitimate users.
14. Sun Java System Server XSLT Processing Remote Java Method Execution V=
ulnerability
BugTraq ID: 24850
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24850
Summary:
Sun Java System Web Servers and Application Servers are prone to a vulner=
ability that lets attackers execute arbitrary Java methods. This issue oc=
curs because the application fails to securely process XSLT stylesheets.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary Java methods, aiding them in further attacks.
Sun Java System Web Server 7.0 for the following operating systems is aff=
ected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
- HP-UX
Sun Java System Application Server Platform and Enterprise Editions 8.2 a=
nd Platform Edition 9.0 for the following operating systems are also affe=
cted:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
15. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 24854
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24854
Summary:
Centericq is prone to multiple remote buffer-overflow vulnerabilities bec=
ause the application fails to properly bounds-check user-supplied input b=
efore copying it to an insufficiently sized memory buffer
An attacker can exploit these issues to execute arbitrary code within the=
context of the affected application. Failed exploit attempts will result=
in a denial of service.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j