SecurityFocus Linux Newsletter #357

[email protected] 3 Oct 2007 18:22:57 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #357
----------------------------------------

This Issue is Sponsored by: Techmentor:

TechMentor - Las Vegas - October 15 - 19
Join your fellow systems administrators and IT managers at the Rio Hotel =
& Casino in Vegas for a week of in-depth technical training. TechMentor w=
ill give you the tools and techniques to help you get the most out of you=
r network. Register now!
http://ad.doubleclick.net/clk;135399548;6631910;q?http://techmentorevents=
.com/


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Passive Network Analysis
II.  LINUX VULNERABILITY SUMMARY
       1. Imatix Xitami If-Modified-Since Remote Buffer Overflow Vulnerab=
ility
       2. Balsa Fetch Command Remote Stack Buffer Overflow Vulnerability
       3. Linux Kernel PTrace NULL Pointer Dereference Local Denial Of Se=
rvice Vulnerability
       4. Linux Kernel ALSA snd-page-alloc Local Proc File Information Di=
sclosure Vulnerability
       5. OpenSSL SSL_Get_Shared_Ciphers Off-by-One Buffer Overflow Vulne=
rability
       6. Linux Kernel JFFS2 Filesystem Security Bypass Vulnerability
       7. Sun Java System Access Manager Multiple Vulnerabilities
       8. Pidgin MSN Nudge Messages Remote Denial Of Service Vulnerabilit=
y
       9. rPath rMake Local Privilege Escalation Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Passive Network Analysis
By Stephen Barish
In sports, it's pretty much accepted wisdom that home teams have the adva=
ntage; that's why teams with winning records on the road do so well in th=
e playoffs. But for some reason we rarely think about "the home field adv=
antage" when we look at defending our networks.=20
http://www.securityfocus.com/infocus/1894


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Imatix Xitami If-Modified-Since Remote Buffer Overflow Vulnerability
BugTraq ID: 25772
Remote: Yes
Date Published: 2007-09-24
Relevant URL: http://www.securityfocus.com/bid/25772
Summary:
Xitami is prone to a remote buffer-overflow vulnerability because the sof=
tware fails to properly bounds-check user-supplied input before copying i=
t into an insufficiently sized memory buffer.

Attackers may exploit this issue to execute arbitrary code in the context=
 of the affected application. Failed exploit attempts will likely result =
in denial-of-service conditions.

Xitami 2.5 is vulnerable to this issue; other versions may also be affect=
ed.

2. Balsa Fetch Command Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 25777
Remote: Yes
Date Published: 2007-09-24
Relevant URL: http://www.securityfocus.com/bid/25777
Summary:
Balsa is prone to a remote stack-based buffer-overflow vulnerability beca=
use the application fails to perform adequate boundary-checks on user-sup=
plied data.=20

This issue affects the application's IMAP functionality.

An attacker can exploit this issue to execute arbitrary machine code with=
in the context of the user running the application. Failed exploit attemp=
ts will result in a denial-of-service vulnerability.

Versions prior to Balsa 2.3.20 are vulnerable.

3. Linux Kernel PTrace NULL Pointer Dereference Local Denial Of Service V=
ulnerability
BugTraq ID: 25801
Remote: No
Date Published: 2007-09-25
Relevant URL: http://www.securityfocus.com/bid/25801
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

This issue occurs because of a NULL-pointer dereference in certain 'ptrac=
e' operations.

A local attacker can exploit this issue to crash the affected kernel, den=
ying service to legitimate users.

4. Linux Kernel ALSA snd-page-alloc Local Proc File Information Disclosur=
e Vulnerability
BugTraq ID: 25807
Remote: No
Date Published: 2007-09-25
Relevant URL: http://www.securityfocus.com/bid/25807
Summary:
The Linux kernel is prone to an information-disclosure vulnerability.

Successful exploits will allow attackers to obtain portions of kernel mem=
ory. Information harvested may aid in further attacks.

Versions of the Linux kernel prior to 2.6.22.8 are vulnerable.

5. OpenSSL SSL_Get_Shared_Ciphers Off-by-One Buffer Overflow Vulnerabilit=
y
BugTraq ID: 25831
Remote: Yes
Date Published: 2007-09-27
Relevant URL: http://www.securityfocus.com/bid/25831
Summary:
OpenSSL is prone to an off-by-one buffer-overflow vulnerability because t=
he library fails to properly bounds-check user-supplied input before copy=
ing it to an insufficiently sized memory buffer.

Successfully exploiting this issue may allow attackers to execute arbitra=
ry machine code in the context of applications that use the affected libr=
ary, but this has not been confirmed. Failed exploit attempts may crash a=
pplications, denying service to legitimate users.
 =20
NOTE: This issue was introduced in the fix for the vulnerability describe=
d in BID 20249 (OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerabil=
ity).

6. Linux Kernel JFFS2 Filesystem Security Bypass Vulnerability
BugTraq ID: 25838
Remote: No
Date Published: 2007-09-27
Relevant URL: http://www.securityfocus.com/bid/25838
Summary:
The Linux kernel is prone to a security-bypass vulnerability because the =
software fails to properly store POSIX ACLs in the JFFS2 filesystem.

A local attacker may exploit this issue to bypass ACL security restrictio=
ns, which may lead to other attacks.

7. Sun Java System Access Manager Multiple Vulnerabilities
BugTraq ID: 25842
Remote: Yes
Date Published: 2007-09-27
Relevant URL: http://www.securityfocus.com/bid/25842
Summary:
Sun Java System Access Manager is prone to multiple remote vulnerabilitie=
s that result from configuration errors.

Exploiting these issues can allow remote attackers to gain unauthorized a=
ccess to the application or execute arbitrary code in the context of the =
application.

Sun Java System Access Manager 7.1 is affected by these issues.

8. Pidgin MSN Nudge Messages Remote Denial Of Service Vulnerability
BugTraq ID: 25872
Remote: Yes
Date Published: 2007-10-01
Relevant URL: http://www.securityfocus.com/bid/25872
Summary:
Pidgin is prone to a remote denial-of-service vulnerability because it fa=
ils to handle specially crafted messages.

Attackers can exploit this issue to crash the application, denying servic=
e to legitimate users.

Versions prior to Pidgin 2.2.1 are vulnerable.

9. rPath rMake Local Privilege Escalation Vulnerability
BugTraq ID: 25899
Remote: No
Date Published: 2007-10-02
Relevant URL: http://www.securityfocus.com/bid/25899
Summary:
rPath rMake is prone to a local privilege-escalation vulnerability that s=
tems from a design error.

An attacker may exploit this vulnerability to execute arbitrary code with=
 superuser privileges. This may facilitate a complete compromise of affec=
ted computers.

This vulnerability affects rMake 1.0.11; other versions may also be affec=
ted.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Techmentor:

TechMentor - Las Vegas - October 15 - 19
Join your fellow systems administrators and IT managers at the Rio Hotel =
& Casino in Vegas for a week of in-depth technical training. TechMentor w=
ill give you the tools and techniques to help you get the most out of you=
r network. Register now!
http://ad.doubleclick.net/clk;135399548;6631910;q?http://techmentorevents=
.com/