SecurityFocus Linux Newsletter #345

[email protected] 11 Jul 2007 19:49:32 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #345
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Achtung! New German Laws on Cybercrime
       2. Don't Be Evil
II.  LINUX VULNERABILITY SUMMARY
       1. GSAMBAD Insecure Temporary File Creation Vulnerability
       2. Fireflier-Server Insecure Temporary File Creation Vulnerability
       3. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnerab=
ility
       4. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulner=
ability
       5. Retired: SlackRoll Malicious Package Denial of Service Vulnerab=
ility
       6. GIMP PSD File Integer Overflow Vulnerability
       7. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerabili=
ty
       8. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerabil=
ity
       9. GFax Temporary Files Local Arbitrary Command Execution Vulnerab=
ility
       10. JP1/HiCommand Series Products OpenSSL Insecure Protocol Negoti=
ation Weakness
       11. Linux Kernel Decode_Choices Function Remote Denial Of Service =
Vulnerability
       12. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Servic=
e Vulnerability
       13. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulner=
ability
       14. Sun Java System Server XSLT Processing Remote Java Method Exec=
ution Vulnerability
       15. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Achtung! New German Laws on Cybercrime
By Federico Biancuzzi
Germany is passing some new laws regarding cybercrime that might affect s=
ecurity professionals. Federico Biancuzzi interviewed Marco Gercke, one o=
f the experts that was invited to the parliamentary hearing, to learn mor=
e about this delicate subject. They discussed what is covered by the new =
laws, which areas remain in the dark, and how they might affect vulnerabi=
lity disclosure and the use of common tools, such as nmap.
http://www.securityfocus.com/columnists/448

2. Don't Be Evil
By Mark Rasch
A series of developments raise the specter that remotely stored or create=
d documents may be subject to subpoena or discovery all without the knowl=
edge or consent of the document's creators.
http://www.securityfocus.com/columnists/447


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. GSAMBAD Insecure Temporary File Creation Vulnerability
BugTraq ID: 24717
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24717
Summary:
GSAMBAD creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20

An attacker may leverage this issue to corrupt or overwrite arbitrary fil=
es with the privileges of an unsuspecting user that activated the affecte=
d application. Reportedly, attackers can exploit this issue to escalate p=
rivileges.

All versions of GSAMBAD are considered to be vulnerable to this issue.

2. Fireflier-Server Insecure Temporary File Creation Vulnerability
BugTraq ID: 24718
Remote: No
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24718
Summary:
Fireflier-Server application creates temporary files in an insecure manne=
r.

An attacker with local access could potentially exploit this issue to rem=
ove arbitrary files from the local system. =20

Successfully mounting a symlink attack may allow the attacker to remove s=
ensitive files, which may result in a denial of service. Other attacks ma=
y also be possible.

3. PHPEventCalendar Eventdisplay.PHP Script SQL Injection Vulnerability
BugTraq ID: 24721
Remote: Yes
Date Published: 2007-07-01
Relevant URL: http://www.securityfocus.com/bid/24721
Summary:
phpEventCalendar is prone to an SQL-injection vulnerability because it fa=
ils to sufficiently sanitize user-supplied data before using it in an SQL=
 query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

phpEventCalendar 0.2.3 and prior versions are reported prone to this issu=
e.

4. Linux Kernel USBLCD Memory Consumption Denial Of Service Vulnerability
BugTraq ID: 24734
Remote: No
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24734
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability because it=
 fails to limit memory consumption by 'fast writers'.

Attackers can exploit this issue to consume memory, resulting in denial-o=
f-service conditions.

Versions prior to 2.6.22-rc7 are vulnerable.

5. Retired: SlackRoll Malicious Package Denial of Service Vulnerability
BugTraq ID: 24739
Remote: Yes
Date Published: 2007-07-02
Relevant URL: http://www.securityfocus.com/bid/24739
Summary:
SlackRoll is prone to a denial-of-service vulnerability.=20

An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20

This issue affects versions prior to SlackRoll 10.

Further analysis reveals that this issue is not exploitable; therefore, t=
his BID is being retired.

6. GIMP PSD File Integer Overflow Vulnerability
BugTraq ID: 24745
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24745
Summary:
GIMP is prone to an integer-overflow vulnerability because it fails to pr=
operly bounds-check user-supplied input data before copying it to an insu=
fficiently sized memory buffer.

Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of the affected application.

GIMP 2.2.15 is vulnerable to this issue; other versions may also be affec=
ted.

7. ImLib BMP Image _LoadBMP Function Denial of Service Vulnerability
BugTraq ID: 24750
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24750
Summary:
Imlib is prone to a denial-of-service vulnerability because the software =
fails to properly process certain BMP image files.

Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted BMP files.

An attacker could exploit this issue to cause denial-of-service condition=
s on applications using the affected library.

8. GNU GLibC LD.SO Mask Dynamic Loader Integer Overflow Vulnerability
BugTraq ID: 24758
Remote: Yes
Date Published: 2007-07-03
Relevant URL: http://www.securityfocus.com/bid/24758
Summary:
GNU glibc is prone to an integer-overflow vulnerability because it fails =
to properly ensure that integer math operations do not wrap around.=20

An attacker can exploit this issue to execute  arbitrary code with  super=
user privileges. Successfully exploiting this  issue will result in  the =
complete compromise of affected application. Failed exploit attempts will=
 result in a denial of service.=20

GNU glibc 2.5 and prior versions are prone to this issue.

9. GFax Temporary Files Local Arbitrary Command Execution Vulnerability
BugTraq ID: 24780
Remote: No
Date Published: 2007-07-05
Relevant URL: http://www.securityfocus.com/bid/24780
Summary:
GFAX is prone to a vulnerability that lets local attackers execute arbitr=
ary commands with superuser privileges. Successful attacks will result in=
 the complete compromise of affected computers.

GFAX 0.7.6 is vulnerable; other versions may also be affected.

10. JP1/HiCommand Series Products OpenSSL Insecure Protocol Negotiation W=
eakness
BugTraq ID: 24799
Remote: Yes
Date Published: 2007-07-06
Relevant URL: http://www.securityfocus.com/bid/24799
Summary:
JP1/HiCommand Series Products are prone to a remote protocol-negotiation =
weakness due to a design error.

Successful exploits may allow an attacker connecting to the affected serv=
er to replace the SSL 3 or TLS 1 protocol with the SSL 2 protocol. This m=
ay allow the attacker to exploit insecurities in SSL version 2 to gain ac=
cess to or tamper with the clear-text communications between the targeted=
 client and server.

This issue may be related to BID: 15071 OpenSSL Insecure Protocol Negotia=
tion Weakness.

11. Linux Kernel Decode_Choices Function Remote Denial Of Service Vulnera=
bility
BugTraq ID: 24818
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24818
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to handle certain H.323 data.

Attackers can exploit this issue to crash the affected operating system, =
denying access to legitimate users.

Versions prior to 2.6.21.6, 2.6.20.15, and 2.6.22 are vulnerable.

12. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Service Vulne=
rability
BugTraq ID: 24845
Remote: No
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24845
Summary:
The PowerPC Linux kernel is prone to a denial-of-service vulnerability.

Exploiting this issue allows local attackers to corrupt memory resources =
and eventually cause the kernel to crash, effectively denying service to =
legitimate users.

Note that this issue affects only the Linux kernel on PowerPC architectur=
es.

13. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability
BugTraq ID: 24846
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24846
Summary:
The Sun JSSE (Java Secure Socket Extension) is prone to a denial-of-servi=
ce vulnerability.

An attacker can exploit this issue to crash the computer, denying access =
to legitimate users.

14. Sun Java System Server XSLT Processing Remote Java Method Execution V=
ulnerability
BugTraq ID: 24850
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24850
Summary:
Sun Java System Web Servers and Application Servers are prone to a vulner=
ability that lets attackers execute arbitrary Java methods. This issue oc=
curs because the application fails to securely process XSLT stylesheets.

Successfully exploiting this issue may allow remote attackers to execute =
arbitrary Java methods, aiding them in further attacks.

Sun Java System Web Server 7.0 for the following operating systems is aff=
ected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
- HP-UX

Sun Java System Application Server Platform and Enterprise Editions 8.2 a=
nd Platform Edition 9.0 for the following operating systems are also affe=
cted:
- Sun Solaris SPARC and x86 platforms
 - Linux
 - Microsoft Windows

15. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 24854
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24854
Summary:
Centericq is prone to multiple remote buffer-overflow vulnerabilities bec=
ause the application fails to properly bounds-check user-supplied input b=
efore copying it to an insufficiently sized memory buffer

An attacker can exploit these issues to execute arbitrary code within the=
 context of the affected application. Failed exploit attempts will result=
 in a denial of service.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j