SecurityFocus Linux Newsletter #355

[email protected] 18 Sep 2007 22:53:38 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #355
----------------------------------------

This Issue is Sponsored by:Techmentor
_______________________

TechMentor - Las Vegas - October 15 - 19
Join your fellow systems administrators and IT managers at the Rio Hotel =
& Casino in Vegas for a week of in-depth technical training. TechMentor w=
ill give you the tools and techniques to help you get the most out of you=
r network. Register now!
http://techmentorevents.com/


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.VoIP Hopping: A Method of Testing VoIP security or Voice VLANs
II.  LINUX VULNERABILITY SUMMARY
       1. QGit DataLoader::doStart Function Local Privilege Escalation Vu=
lnerability
       2. Lighttpd Mod_FastCGI Request Headers Remote Buffer Overflow Vul=
nerability
       3. RealPlayer/HelixPlayer AU Divide-By-Zero Denial of Service Vuln=
erability
       4. Quagga Routing Suite Multiple Denial Of Service Vulnerabilities
       5. Samba NSS_Info Plugin Local Privilege Escalation Vulnerability
       6. MPlayer AVIHeader.C Heap Based Buffer Overflow Vulnerability
       7. Trolltech QT ToUnicode Function Off By One Buffer Overflow Vuln=
erability
       8. AOL Instant Messenger Notification Window Remote Script Code Ex=
ecution Vulnerability
       9. Linux Kernel CIFS Local Privilege Escalation Vulnerability
       10. OpenOffice TIFF File Parser Multiple Integer Overflow Vulnerab=
ilities
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.VoIP Hopping: A Method of Testing VoIP security or Voice VLANs
By Jason Ostrom and John Kindervag
Testing Protection Controls on a VoIP Network - A Case Study and Method
http://www.securityfocus.com/infocus/1892


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. QGit DataLoader::doStart Function Local Privilege Escalation Vulnerabi=
lity
BugTraq ID: 25618
Remote: No
Date Published: 2007-09-10
Relevant URL: http://www.securityfocus.com/bid/25618
Summary:
QGit is prone to a local privilege-escalation vulnerability because the a=
pplication handles temporary files in an insecure manner.

An attacker can exploit this issue overwrite files and to execute arbitra=
ry code with superuser privileges. Successfully exploiting this issue wil=
l result in the complete compromise of affected computers.

Versions prior to QGit 1.5.7 are vulnerable.

2. Lighttpd Mod_FastCGI Request Headers Remote Buffer Overflow Vulnerabil=
ity
BugTraq ID: 25622
Remote: Yes
Date Published: 2007-09-10
Relevant URL: http://www.securityfocus.com/bid/25622
Summary:
Lighttpd is prone to a remote buffer-overflow vulnerability because the a=
pplication fails to bounds-check user-supplied data before copying it int=
o an insufficiently sized buffer.=20

An attacker may exploit this issue to execute arbitrary code within the c=
ontext of the affected application or crash the application, denying serv=
ice to legitimate users.

Lighttpd 1.4.17 is vulnerable; prior versions may also be affected.

3. RealPlayer/HelixPlayer AU Divide-By-Zero Denial of Service Vulnerabili=
ty
BugTraq ID: 25627
Remote: Yes
Date Published: 2007-09-11
Relevant URL: http://www.securityfocus.com/bid/25627
Summary:
RealPlayer and Helix Player are  prone to a denial-of-service vulnerabili=
ty when handling malformed AU media files.

Successfully exploiting this issue allows remote attackers to deny servic=
e to legitimate users.

4. Quagga Routing Suite Multiple Denial Of Service Vulnerabilities
BugTraq ID: 25634
Remote: Yes
Date Published: 2007-09-11
Relevant URL: http://www.securityfocus.com/bid/25634
Summary:
Quagga Routing Suite is prone to a multiple denial-of-service vulnerabili=
ties.

An attacker can exploit these issues to crash the affected application, d=
enying service to legitimate users.

These issues affect versions prior to Quagga Routing Suite 0.99.9.

5. Samba NSS_Info Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 25636
Remote: No
Date Published: 2007-09-11
Relevant URL: http://www.securityfocus.com/bid/25636
Summary:
Samba is prone to a local privilege-escalation vulnerability due to a log=
ic error in the Winbind daemon.

An attacker can exploit this issue to gain 'groupid 0' privileges on UNIX=
 computers running the vulnerable Samba software. This may aid them in fu=
rther attacks.

Samba 3.0.25 through 3.0.25c are vulnerable to this issue.

6. MPlayer AVIHeader.C Heap Based Buffer Overflow Vulnerability
BugTraq ID: 25648
Remote: Yes
Date Published: 2007-09-12
Relevant URL: http://www.securityfocus.com/bid/25648
Summary:
MPlayer is prone to a heap-based buffer-overflow vulnerability because it=
 fails to perform adequate boundary checks on user-supplied input data.

Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the user running the application. Failed attacks will result in =
denial-of-service conditions.

MPlayer 1.0rc1 is vulnerable; other versions may also be affected.

7. Trolltech QT ToUnicode Function Off By One Buffer Overflow Vulnerabili=
ty
BugTraq ID: 25657
Remote: Yes
Date Published: 2007-09-13
Relevant URL: http://www.securityfocus.com/bid/25657
Summary:
Qt is prone to a buffer-overflow vulnerability because the framework fail=
s to perform adequate boundary checks on user-supplied data.=20

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of applications that use the affected framework. Failed exploit at=
tempts will result in a denial-of-service condition.

8. AOL Instant Messenger Notification Window Remote Script Code Execution=
 Vulnerability
BugTraq ID: 25659
Remote: Yes
Date Published: 2007-09-13
Relevant URL: http://www.securityfocus.com/bid/25659
Summary:
AOL Instant Messenger is prone to a remote script-code-execution vulnerab=
ility.

An attacker may leverage this issue to execute arbitrary script code in t=
he notification window of an unsuspecting user. This may help the attacke=
r launch other attacks.

AOL Instant Messenger 6.1.41.2 is vulnerable; other versions may also be =
affected.

9. Linux Kernel CIFS Local Privilege Escalation Vulnerability
BugTraq ID: 25672
Remote: No
Date Published: 2007-09-14
Relevant URL: http://www.securityfocus.com/bid/25672
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability.

An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the victim.

10. OpenOffice TIFF File Parser Multiple Integer Overflow Vulnerabilities
BugTraq ID: 25690
Remote: Yes
Date Published: 2007-09-17
Relevant URL: http://www.securityfocus.com/bid/25690
Summary:
OpenOffice is prone to multiple remote integer-overflow vulnerabilities b=
ecause the application fails to bounds-check user-supplied data before co=
pying it into an insufficiently sized buffer.

Remote attackers may exploit these issues by enticing victims into openin=
g maliciously crafted TIFF files.

An attacker can exploit these issues to execute arbitrary code within the=
 context of the affected application. Failed exploit attempts will result=
 in a denial of service.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by:Techmentor
_______________________

TechMentor - Las Vegas - October 15 - 19
Join your fellow systems administrators and IT managers at the Rio Hotel =
& Casino in Vegas for a week of in-depth technical training. TechMentor w=
ill give you the tools and techniques to help you get the most out of you=
r network. Register now!
http://techmentorevents.com/