SecurityFocus Linux Newsletter #362

[email protected] 8 Nov 2007 04:46:43 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #362
----------------------------------------

This issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored.=20
This paper examines a few vulnerability detection methods - specifically =
comparing and contrasting manual penetration testing with automated scann=
ing tools.
Download Watchfire's "Web Application Security: Automated Scanning or Man=
ual Penetration Testing?" whitepaper today!=20
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D7017000000093z=
v


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.E-mail privacy to disappear?
       2.Rebinding attacks unbound
II.  LINUX VULNERABILITY SUMMARY
       1. vobcopy vobcopy.bla Insecure Temporary File Creation Vulnerabil=
ity
       2. Liferea Feedlist.OPML Local Information Disclosure Vulnerabilit=
y
       3. CUPS IPP Tag Handling Remote Buffer Overflow Vulnerability
       4. McAfee E-Business Server Authentication Packet Handling Integer=
 Overflow Vulnerability
       5. Perdition IMAPD __STR_VWRITE Remote Format String Vulnerability
       6. Mono System.Math BigInteger Buffer Overflow Vulnerability
       7. iSCSI Enterprise Target IETD.CONF Local Information Disclosure =
Vulnerability
       8. BitchX E_HOSTNAME Function Insecure Temporary File Creation Vul=
nerability
       9. Linux Kernel IEEE80211 HDRLen Remote Denial Of Service Vulnerab=
ility
       10. PCRE Regular Expression Library Multiple Security Vulnerabilit=
ies
       11. Perl Unicode Regular Expression Buffer Overflow Vulnerability
       12. Xpdf Multiple Remote Stream.CC Vulnerabilities
       13. CoolKey PK11IPC1 Insecure Temporary File Creation Vulnerabilit=
y
       14. Mcstrans Mcstrans.C Local Denial of Service Vulnerability
       15. GForge Insecure Temporary File Creation Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. How secure  is the openSUSE Build Service?
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.E-mail privacy to disappear?
On October 8, 2007, the United States Court of Appeals for the Sixth Circ=
uit in Cincinnati granted the government's request for a full-panel heari=
ng in United States v. Warshak case centering on the right of privacy for=
 stored electronic communications. At issue is whether the procedure wher=
eby the government can subpoena stored copies of your e-mail -- similar t=
o the way they could simply subpoena any physical mail sitting on your de=
sk -- is unconstitutionally broad.=20
http://www.securityfocus.com/columnists/456

2.Rebinding attacks unbound
By Federico Biancuzzi
DNS rebinding was discovered in 1996 and affected the Java Virtual Machin=
e (VM). Recently a group of researchers at Stanford found out that this v=
ulnerability is still present in browsers and that the common solution, k=
nown as DNS pinning, is not effective anymore.
http://www.securityfocus.com/columnists/455


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. vobcopy vobcopy.bla Insecure Temporary File Creation Vulnerability
BugTraq ID: 26233
Remote: No
Date Published: 2007-10-29
Relevant URL: http://www.securityfocus.com/bid/26233
Summary:
The 'vobcopy' tool creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20

Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.

2. Liferea Feedlist.OPML Local Information Disclosure Vulnerability
BugTraq ID: 26254
Remote: No
Date Published: 2007-10-30
Relevant URL: http://www.securityfocus.com/bid/26254
Summary:
Liferea is prone to a local information-disclosure vulnerability because =
the application fails to set file permissions correctly on a backup file.

 Attackers can leverage this issue to obtain sensitive information used t=
o construct valid login credentials.
=20
This issue affects  versions prior to Liferea 1.4.6.

3. CUPS IPP Tag Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 26268
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26268
Summary:
CUPS is prone to a remote buffer-overflow vulnerability because it fails =
to properly bounds-check user-supplied data before copying it to an insuf=
ficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.

CUPS 1.3.3 is reported vulnerable; other versions may be affected as well=
.

4. McAfee E-Business Server Authentication Packet Handling Integer Overfl=
ow Vulnerability
BugTraq ID: 26269
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26269
Summary:
The application is prone to an integer-overflow vulnerability because it =
fails to ensure that integer values aren't overrun.

Successfully exploiting this issue may allow attackers to execute arbitra=
ry code within the context of the affected application. This is turn may =
result in a complete compromise of the affected system. Failed exploit at=
tempts will result in a denial of service.

The issue affects McAfee E-Business Server 8.1.1 for Linux and  8.5.2 for=
 Solaris. Versions for Windows are not affected.

5. Perdition IMAPD __STR_VWRITE Remote Format String Vulnerability
BugTraq ID: 26270
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26270
Summary:
Perdition IMAP proxy server is prone to a remote format-string vulnerabil=
ity because it fails to properly sanitize user-supplied input before pass=
ing it as the format specifier to a formatted-printing function.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected application. A successful attack will compromi=
se the application. Failed attempts may cause denial-of-service condition=
s.
=20
 This issue affects Perdition 1.17 and prior versions.

6. Mono System.Math BigInteger Buffer Overflow Vulnerability
BugTraq ID: 26279
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26279
Summary:
Mono is prone to a buffer-overflow vulnerability because the application =
fails to perform adequate boundary checks on user-supplied data.

Successfully exploiting this issue could allow attackers to execute arbit=
rary code in the context of the user running an affected application. Fai=
led exploit attempts will likely result in a denial-of-service condition.

7. iSCSI Enterprise Target IETD.CONF Local Information Disclosure Vulnera=
bility
BugTraq ID: 26299
Remote: No
Date Published: 2007-11-02
Relevant URL: http://www.securityfocus.com/bid/26299
Summary:
iSCSI Enterprise Target is prone to a local information-disclosure vulner=
ability because the software sets incorrect permissions on the '/etc/ietd=
.conf' file.

Attackers can exploit this issue to obtain usernames and passwords as wel=
l as information about the configuration of the affected application.
=20
This issue affects iSCSI Enterprise Target 0.4.15; other versions may als=
o be affected.

8. BitchX E_HOSTNAME Function Insecure Temporary File Creation Vulnerabil=
ity
BugTraq ID: 26326
Remote: No
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26326
Summary:
BitchX is prone to a security vulnerability because it creates temporary =
files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20

Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.

This issue affects BitchX 1.1; other versions may also be vulnerable.

9. Linux Kernel IEEE80211 HDRLen Remote Denial Of Service Vulnerability
BugTraq ID: 26337
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26337
Summary:
The Linux kernel ieee80211 driver is prone to a remote denial-of-service =
vulnerability because it fails to perform adequate boundary checks on use=
r-supplied data.

An attacker can exploit this issue to crash a victim computer, effectivel=
y denying service.

Versions prior to Linux kernel 2.6.22.11 are vulnerable.

10. PCRE Regular Expression Library Multiple Security Vulnerabilities
BugTraq ID: 26346
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26346
Summary:
PCRE regular-expression library is prone to multiple security vulnerabili=
ties.

Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.

11. Perl Unicode Regular Expression Buffer Overflow Vulnerability
BugTraq ID: 26350
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26350
Summary:
Perl is prone to a buffer-overflow vulnerability because it fails to suff=
iciently bounds-check user-supplied input.

Successfully exploiting this issue allows attackers to execute arbitrary =
machine code in the context of Perl applications using regular expression=
s in a vulnerable manner. This facilitates the remote compromise of affec=
ted computers.

Perl 5.8 is vulnerable to this issue; other versions may also be affected=
.

12. Xpdf Multiple Remote Stream.CC Vulnerabilities
BugTraq ID: 26367
Remote: Yes
Date Published: 2007-11-07
Relevant URL: http://www.securityfocus.com/bid/26367
Summary:
Xpdf is prone to multiple remote vulnerabilities because of flaws in vari=
ous functions in the 'Stream.cc' source file.

Attackers exploit these issues by coercing users to view specially crafte=
d PDF files with the affected application.

Successfully exploiting these issues allows attackers to execute arbitrar=
y machine code in the context of the vulnerable application. This facilit=
ates the remote compromise of affected computers.

Xpdf 3.02pl1 is vulnerable to these issues; other versions may also be af=
fected.

13. CoolKey PK11IPC1 Insecure Temporary File Creation Vulnerability
BugTraq ID: 26369
Remote: No
Date Published: 2007-11-07
Relevant URL: http://www.securityfocus.com/bid/26369
Summary:
CoolKey creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks to alter the permissions of an arbitrary attac=
ker-specified file, such as '/etc/shadow'. This could facilitate a comple=
te compromise of the affected computer.

14. Mcstrans Mcstrans.C Local Denial of Service Vulnerability
BugTraq ID: 26371
Remote: No
Date Published: 2007-11-07
Relevant URL: http://www.securityfocus.com/bid/26371
Summary:
Mcstrans is prone to a local denial-of-service vulnerability because it f=
ails to adequately check  user-supplied data.

Successfully exploiting this issue allows local attackers to deny service=
 to legitimate users.

15. GForge Insecure Temporary File Creation Vulnerability
BugTraq ID: 26373
Remote: No
Date Published: 2007-11-07
Relevant URL: http://www.securityfocus.com/bid/26373
Summary:
GForge creates temporary files in an insecure way.

An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks, overwriting arbitrary files in the context of=
 the affected application. This may result in denial-of-service condition=
s; other attacks are also possible.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. How secure  is the openSUSE Build Service?
http://www.securityfocus.com/archive/91/483116

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored.=20
This paper examines a few vulnerability detection methods - specifically =
comparing and contrasting manual penetration testing with automated scann=
ing tools.
Download Watchfire's "Web Application Security: Automated Scanning or Man=
ual Penetration Testing?" whitepaper today!=20
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D7017000000093z=
v