SecurityFocus Linux Newsletter #352

[email protected] 29 Aug 2007 22:36:48 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #352
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data.=20
XPath Injection can be just as dangerous as SQL Injection, and can be eve=
n easier to exploit. Learn how to identify XPath Injection vulnerabilitie=
s and which methods of recourse to take to prevent them. Download this *F=
REE* white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D1r=
X


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Virtualized rootkits - Part 2
       2. Virtualized rootkits - Part 1
II.  LINUX VULNERABILITY SUMMARY
       1. Gentoo Linux NVIDIA Drivers Local Denial of Service Vulnerabili=
ty
       2. Gentoo Linux NVIDIA Drivers Local Denial of Service Vulnerabili=
ty
       3. Sysstat Insecure Temporary File Creation Vulnerability
       4. Linux Kernel Parent Process Death Signal Local Security Bypass =
Weakness
       5. Asterisk SIP Dialog History Resource Exhaustion Remote Denial o=
f Service Vulnerability
       6. IBM Lotus Notes NTMulti.EXE Local Privilege Escalation Vulnerab=
ility
       7. GNU Tar Dot_Dot Function Remote Directory Traversal Vulnerabili=
ty
       8. Skulltag Huffman Packet Decompression Remote Heap Based Buffer =
Overflow Vulnerability
       9. Bugzilla Multiple Remote Vulnerabilities
       10. Sophos Antivirus UPX and BZIP Multiple Remote Vulnerabilities
       11. Asterisk Malformed MIME Body Remote Denial of Service Vulnerab=
ility
       12. BitchX IRC MODE Remote Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. mail antivirus
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Virtualized rootkits - Part 2
By Federico Biancuzzi
There has been a lot of buzz around the topic of virtualized rootkits. Jo=
anna Rutkowska has been working on a new version of Blue-Pill, her proof =
of concept invisible rootkit, while a team made by three prominent securi=
ty experts (Thomas Ptacek, Nate Lawson, Peter Ferrie) challenged her that=
 there is not an "invisible" rootkit, and that they were going to present=
 at BlackHat conference various techniques to detect Blue-Pill. Federico =
Biancuzzi interviewed both sides to learn more. Part 2 of 2
http://www.securityfocus.com/columnists/452


2. Virtualized rootkits - Part 1
By Federico Biancuzzi
There has been a lot of buzz around the topic of virtualized rootkits. Jo=
anna Rutkowska has been working on a new version of Blue-Pill, her proof =
of concept invisible rootkit, while a team made by three prominent securi=
ty experts (Thomas Ptacek, Nate Lawson, Peter Ferrie) challenged her that=
 there is not an "invisible" rootkit, and that they were going to present=
 at BlackHat conference various techniques to detect Blue-Pill. Federico =
Biancuzzi interviewed both sides to learn more. Part 1 of 2
http://www.securityfocus.com/columnists/451


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Gentoo Linux NVIDIA Drivers Local Denial of Service Vulnerability
BugTraq ID: 25360
Remote: No
Date Published: 2007-08-19
Relevant URL: http://www.securityfocus.com/bid/25360
Summary:
Gentoo Linux NVIDIA drivers are prone to a denial-of-service vulnerabilit=
y.

Exploiting this issue allows local attackers to cause the application to =
crash or possibly cause hardware damage to a graphics card.

2. Gentoo Linux NVIDIA Drivers Local Denial of Service Vulnerability
BugTraq ID: 25363
Remote: No
Date Published: 2007-08-19
Relevant URL: http://www.securityfocus.com/bid/25363
Summary:
Gentoo Linux NVIDIA drivers are prone to a denial-of-service vulnerabilit=
y.

Exploiting this issue allows local attackers to cause the application to =
crash or possibly cause hardware damage to a graphics card.

3. Sysstat Insecure Temporary File Creation Vulnerability
BugTraq ID: 25380
Remote: No
Date Published: 2007-08-21
Relevant URL: http://www.securityfocus.com/bid/25380
Summary:
Sysstat creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of appli=
cations utilizing the affected library.

Successfully mounting a symbolic link attack may allow the attacker to ov=
erwrite or corrupt sensitive files, which may result in a denial of servi=
ce. Other attacks may also be possible.

Sysstat 7.1.6 is reported to be vulnerable.  Other versions may be affect=
ed as well.

4. Linux Kernel Parent Process Death Signal Local Security Bypass Weaknes=
s
BugTraq ID: 25387
Remote: No
Date Published: 2007-08-21
Relevant URL: http://www.securityfocus.com/bid/25387
Summary:
The Linux kernel is prone to a security-bypass weakness when dealing with=
 signal handling.

This issue is due to a lack of proper access-validation when the parent p=
rocess attempts to deliver its death signal to the child that registered =
it via 'prctl'.

A local attacker may exploit this issue to bypass certain security restri=
ctions, which may lead to other attacks.

Linux kernel versions prior to 2.6.22.4 are vulnerable.

5. Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Servi=
ce Vulnerability
BugTraq ID: 25392
Remote: Yes
Date Published: 2007-08-21
Relevant URL: http://www.securityfocus.com/bid/25392
Summary:
Asterisk is prone to a remote denial-of-service vulnerability.

Successfully exploiting this issue allows remote attackers to consume all=
 system resources, denying service to legitimate users.

6. IBM Lotus Notes NTMulti.EXE Local Privilege Escalation Vulnerability
BugTraq ID: 25401
Remote: No
Date Published: 2007-08-22
Relevant URL: http://www.securityfocus.com/bid/25401
Summary:
IBM Lotus Notes is prone to a local privilege-escalation vulnerability be=
cause it fails to assigned proper file permissions during installation.

Attackers can exploit this issue to run arbitrary applications with SYSTE=
M-level privileges. Successful attacks will completely compromise affecte=
d computers.

NOTE: This issue may be related to the one covered under BID 20612. This =
has not been confirmed. This BID will be updated as further information b=
ecomes available.

7. GNU Tar Dot_Dot Function Remote Directory Traversal Vulnerability
BugTraq ID: 25417
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25417
Summary:
GNU Tar is prone to a directory-traversal vulnerability. This issue occur=
s because the application fails to validate user-supplied data.

A successful attack can allow the attacker to overwrite files on a comput=
er in the context of the user running the affected application. Successfu=
l exploits may aid in further attacks.

8. Skulltag Huffman Packet Decompression Remote Heap Based Buffer Overflo=
w Vulnerability
BugTraq ID: 25423
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25423
Summary:
Skulltag is prone to a remote heap-based buffer-overflow vulnerability be=
cause it fails to perform adequate boundary-checks on user-supplied input=
.

Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the user running the application. Successful exploits may compro=
mise affected computers. Failed attacks will likely cause denial-of-servi=
ce conditions.

Skulltag version 0.97d-beta4.1 is vulnerable; other versions may also be =
affected.

9. Bugzilla Multiple Remote Vulnerabilities
BugTraq ID: 25425
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25425
Summary:
Bugzilla is prone to multiple remote vulnerabilities. These issues includ=
e an HTML-injection vulnerability, a remote-command injection vulnerabili=
ty and an information-disclosure vulnerability.

An attacker can exploit this issue to execute arbitrary code and commands=
 with the privileges of the webserver process, steal cookie-based authent=
ication credentials and disclose sensitive information.=20

 This issue affects Bugzilla 2.20.4, 2.22.2, 3.0, 3.1; prior versions of =
the 2.20 and 2.22 branches are also affected.

10. Sophos Antivirus UPX and BZIP Multiple Remote Vulnerabilities
BugTraq ID: 25428
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25428
Summary:
Sophos Antivirus is prone to multiple remote vulnerabilities. These issue=
s include a remote code-execution vulnerability and a denial-of-service v=
ulnerability.

A remote attacker can exploit this issue to execute arbitrary code within=
 the context of the affected application or crash the affected applicatio=
n, denying service to legitimate users. Successful exploits may result in=
 a crash of the antivirus engine or the exhaustion of disk space on affec=
ted computers.

This issue affects Sophos applications using antivirus engine versions pr=
ior to 2.48.0.

11. Asterisk Malformed MIME Body Remote Denial of Service Vulnerability
BugTraq ID: 25438
Remote: Yes
Date Published: 2007-08-24
Relevant URL: http://www.securityfocus.com/bid/25438
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because the=
 application fails to properly handle specially crafted emails.

Exploiting this issue allows remote attackers to cause the application to=
 crash, effectively denying service to legitimate users.
=20
This issue affects Asterisk versions 1.4.5 to 1.4.11.

12. BitchX IRC MODE Remote Buffer Overflow Vulnerability
BugTraq ID: 25462
Remote: Yes
Date Published: 2007-08-27
Relevant URL: http://www.securityfocus.com/bid/25462
Summary:
BitchX is prone to a remote buffer-overflow vulnerability because the app=
lication fails to bounds-check user-supplied data before copying it into =
an insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20
=20
This issue affects BitchX 1.1; other versions may also be affected.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. mail antivirus
http://www.securityfocus.com/archive/91/477433

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data.=20
XPath Injection can be just as dangerous as SQL Injection, and can be eve=
n easier to exploit. Learn how to identify XPath Injection vulnerabilitie=
s and which methods of recourse to take to prevent them. Download this *F=
REE* white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D1r=
X