SecurityFocus Linux Newsletter #349

[email protected] 12 Aug 2007 15:33:43 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #349
----------------------------------------

This Issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
 Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701700000008yk=
a


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Delete This!
       2. Security conferences versus practical knowledge
II.  LINUX VULNERABILITY SUMMARY
       1. Dovecot ACL Plugin Security Bypass Vulnerability
       2. Sun Java System Web Server Multiple HTTP Redirect Vulnerabiliti=
es
       3. GNOME Display Manager G_Strsplit Function Local Denial Of Servi=
ce Vulnerability
       4. Linux Kernel TIF_SINGLESTEP Check Local Denial of Service Vulne=
rability
       5. Linux Kernel AACRAID Driver Local Security Bypass Vulnerability
       6. Asterisk Skinny Channel Driver Remote Denial of Service Vulnera=
bility
       7. Linux Kernel i965 Chipsets Insecure Batchbuffer Local Privilege=
 Escalation Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Delete This!
By Mark Rasch
A series of legal events means that companies that have no business reaso=
n to retain documents or records may be compelled to create and retain su=
ch records just so they can become available for discovery.
http://www.securityfocus.com/columnists/450

2. Security conferences versus practical knowledge
By Don Parker
While the training industry as a whole has evolved rather well to suit th=
e needs of their clients, the computer conference - specifically the comp=
uter security conference - has declined in relevance to the everyday sys-=
admin and network security practitioners.
http://www.securityfocus.com/columnists/449


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Dovecot ACL Plugin Security Bypass Vulnerability
BugTraq ID: 25182
Remote: Yes
Date Published: 2007-08-02
Relevant URL: http://www.securityfocus.com/bid/25182
Summary:
Dovecot ACL plugin is prone to a security-bypass vulnerability.=20

An attacker can exploit this issue to bypass mailbox restrictions and ele=
vate privileges by altering ACL permission flags.

Versions prior to Dovecot 1.0.3 are vulnerable to this issue.

2. Sun Java System Web Server Multiple HTTP Redirect Vulnerabilities
BugTraq ID: 25190
Remote: Yes
Date Published: 2007-08-02
Relevant URL: http://www.securityfocus.com/bid/25190
Summary:
Sun Java System Web Server is prone to multiple vulnerabilities regarding=
 'redirect' functionality. The vulnerabilities include HTTP-response spli=
tting, HTTP-header injection, and unauthorized access to system resources=
.=20

An attacker may exploit the HTTP-response-splitting vulnerability to infl=
uence or misrepresent how web content is served, cached, or interpreted. =
This could aid in various attacks that attempt to entice client users int=
o a false sense of trust.=20

Attackers typically exploit HTTP-header-injection issues to inject arbitr=
ary cookie attributes into a session cookie. Since session IDs are usuall=
y stored in cookie form, an attacker can inject arbitrary cookie data att=
ributes into a session cookie and then launch various attacks on active w=
eb sessions.

3. GNOME Display Manager G_Strsplit Function Local Denial Of Service Vuln=
erability
BugTraq ID: 25191
Remote: No
Date Published: 2007-08-03
Relevant URL: http://www.securityfocus.com/bid/25191
Summary:
GNOME Display Manager is prone to a local denial-of-service vulnerability=
 because the application fails to handle specially crafted GDM socket com=
mands.

A local attacker can exploit this issue to crash the affected application=
, denying service to legitimate users.=20

Versions prior to GNOME Display Manager 2.14.13, 2.16.7, 2.18.4, and 2.19=
.5 are vulnerable.

4. Linux Kernel TIF_SINGLESTEP Check Local Denial of Service Vulnerabilit=
y
BugTraq ID: 25200
Remote: No
Date Published: 2007-08-04
Relevant URL: http://www.securityfocus.com/bid/25200
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.

A local attacker may exploit this issue to trigger an infinite loop in th=
e kernel, causing a denial of service to legitimate users.

Versions prior to 2.6.21.7 are vulnerable.

5. Linux Kernel AACRAID Driver Local Security Bypass Vulnerability
BugTraq ID: 25216
Remote: No
Date Published: 2007-08-06
Relevant URL: http://www.securityfocus.com/bid/25216
Summary:
The Linux kernel is prone to a security-bypass vulnerability.

A local attacker may exploit this vulnerability to issue IOCTL commands t=
o AACRAID devices. This may lead to denial-of-service conditions, includi=
ng data loss and computer crashes.

Versions prior to 2.6.23-rc2 are vulnerable.

6. Asterisk Skinny Channel Driver Remote Denial of Service Vulnerability
BugTraq ID: 25228
Remote: Yes
Date Published: 2007-08-07
Relevant URL: http://www.securityfocus.com/bid/25228
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because the=
 application fails to properly handle certain specially crafted packets.

Exploiting this issue allows remote attackers to cause the application to=
 crash, effectively denying service to legitimate users.=20

These versions are vulnerable:

Asterisk Open Source prior to 1.4.10
AsteriskNOW pre-release prior to beta7
Asterisk Appliance Developer Kit prior to 0.7.0
Asterisk s800i (Asterisk Appliance) prior to 1.0.3

7. Linux Kernel i965 Chipsets Insecure Batchbuffer Local Privilege Escala=
tion Vulnerability
BugTraq ID: 25263
Remote: No
Date Published: 2007-08-09
Relevant URL: http://www.securityfocus.com/bid/25263
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability.

Exploiting this issue may allow local attackers to gain elevated privileg=
es, facilitating the complete compromise of affected computers.

Versions of Linux kernel prior to 2.6.22.2 are vulnerable to this issue.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
 Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701700000008yk=
a