SecurityFocus Linux Newsletter #364
[email protected] 20 Nov 2007 23:37:29 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #364
----------------------------------------
This issue is Sponsored by: Insight24
Are There Holes in Your Network? View this on-demand webcast hosted by Dr=
. Chenxi Wang,=20
Principal Analyst, Security & Risk Management, Forrester Research, as she=
discusses the steps you can follow=20
to ensure your network isn't vulnerable. She will also outline key metric=
s organizations can use to measure the=20
maturity of their vulnerability management programs. Click on the link be=
low to view this on-demand webcast today!
http://showcase.insight24.com/?ForresterSecurityLinux
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Aye, Robot, or Can Computers Contract?
2.Don't blame the IDS
II. LINUX VULNERABILITY SUMMARY
1. Ruby Multiple Libraries SSL Multiple Insecure Certificate Valid=
ation Weaknesses
2. Linux Kernel CIFS Transport.C Remote Buffer Overflow Vulnerabil=
ity
3. GNU TAR and CPIO safer_name_suffix Remote Denial of Service Vul=
nerability
4. IBM DB2 Multiple Privilege Escalation Vulnerabilities
5. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
6. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overflo=
w Vulnerability
7. PCRE Regular Expression Library Multiple Integer and Buffer Ove=
rflow Vulnerabilities
8. Linux Kernel TCP_Input.C Remote Denial of Service Vulnerability
9. Linux Kernel wait_task_stopped Local Denial of Service Vulnerab=
ility
10. SMF Private Forum Messages Information Disclosure Vulnerabilit=
y
III. LINUX FOCUS LIST SUMMARY
1. important errors to control with swatch
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Aye, Robot, or Can Computers Contract?
By Mark Rasch
A contract is usually described as a "meeting of the minds." One person m=
akes an offer for goods or services; another person sees the offer and ne=
gotiates terms; the parties enter into an agreement of the offer; and som=
e form of consideration is given in return for the provision of something=
of value. At least that's what I remember from first year law school con=
tracts class.=20
http://www.securityfocus.com/columnists/458
2.Don't blame the IDS
By Don Parker
Some years ago, I remember reading a press release from the Gartner Group=
. It was about intrusion detection systems (IDS) offering little return f=
or the monetary investment in them and furthermore, that this very same s=
ecurity technology would be obsolete by the year 2005. A rather bold stat=
ement and an even bolder prediction on their part.
http://www.securityfocus.com/columnists/457
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Ruby Multiple Libraries SSL Multiple Insecure Certificate Validation W=
eaknesses
BugTraq ID: 26421
Remote: Yes
Date Published: 2007-11-13
Relevant URL: http://www.securityfocus.com/bid/26421
Summary:
Ruby is prone to multiple weaknesses related to its validation of certifi=
cates. The problem is that multiple libraries fail to properly perform va=
lidity checks on X.509 certificates.
Successfully exploiting these issues may allow attackers to perform man-i=
n-the-middle attacks against applications that insecurely use an affected=
library. Other attacks may also be possible.
NOTE: These issues are related to a weakness covered by BID 25847 (Ruby N=
et::HTTP SSL Insecure Certificate Validation Weakness).
2. Linux Kernel CIFS Transport.C Remote Buffer Overflow Vulnerability
BugTraq ID: 26438
Remote: Yes
Date Published: 2007-11-14
Relevant URL: http://www.securityfocus.com/bid/26438
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied input before copying i=
t into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges or cause the affected kernel to crash, denying service t=
o legitimate users.=20
This issue affects version 2.6.23.1; previous versions may also be affect=
ed.
3. GNU TAR and CPIO safer_name_suffix Remote Denial of Service Vulnerabil=
ity
BugTraq ID: 26445
Remote: Yes
Date Published: 2007-11-14
Relevant URL: http://www.securityfocus.com/bid/26445
Summary:
GNU's tar and cpio utilities are prone to a denial-of-service vulnerabili=
ty because of insecure use of the 'alloca()' function.
Successfully exploiting this issue allows attackers to crash the affected=
utilities and possibly to execute code, but this has not been confirmed.
GNU tar and cpio utilities share the same vulnerable code and are both af=
fected. Other utilities sharing this code may also be affected.
4. IBM DB2 Multiple Privilege Escalation Vulnerabilities
BugTraq ID: 26450
Remote: Yes
Date Published: 2007-11-14
Relevant URL: http://www.securityfocus.com/bid/26450
Summary:
IBM DB2 is prone to multiple privilege-escalation vulnerabilities.
Attackers can exploit these issues to gain elevated privileges.
Very few details are available regarding these issues. We will update thi=
s BID as more information emerges.
This issue affects IBM DB2 9.1 and IBM DB2 9.1 with fix pack 1, 2, 3, and=
3a.
5. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
BugTraq ID: 26454
Remote: Yes
Date Published: 2007-11-15
Relevant URL: http://www.securityfocus.com/bid/26454
Summary:
Samba is prone to a buffer-overflow vulnerability because it fails to per=
form adequate boundary checks on user-supplied data.
This issue occurs only when Samba is configured as a Primary or Backup Do=
main Controller.
Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of this issue, attackers may also be able to execute remo=
te code, but the vendor doesn't think that this is possible.
Samba 3.0.0 through 3.0.26a are vulnerable.
6. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overflow Vulne=
rability
BugTraq ID: 26455
Remote: Yes
Date Published: 2007-11-15
Relevant URL: http://www.securityfocus.com/bid/26455
Summary:
Samba is prone to a remote stack-based buffer-overflow vulnerability beca=
use it fails to properly bounds-check user-supplied data before copying i=
t to an insufficiently sized memory buffer.
NOTE: This issue occurs only when Samba is configured with the 'wins supp=
ort' option enabled in the host's 'smb.conf' file.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Successful attacks will completely compro=
mise affected computers. Failed exploit attempts will result in a denial =
of service.
Samba 3.0.0 through 3.0.26a are vulnerable.
7. PCRE Regular Expression Library Multiple Integer and Buffer Overflow V=
ulnerabilities
BugTraq ID: 26462
Remote: Yes
Date Published: 2007-11-15
Relevant URL: http://www.securityfocus.com/bid/26462
Summary:
PCRE regular-expression library is prone to multiple integer- and buffer-=
overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.
8. Linux Kernel TCP_Input.C Remote Denial of Service Vulnerability
BugTraq ID: 26474
Remote: Yes
Date Published: 2007-11-16
Relevant URL: http://www.securityfocus.com/bid/26474
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to adequately sanitize specially crafted ACK responses.
Attackers can exploit this issue to cause a NULL-pointer dereference and =
crash the kernel.
Linux kernel versions prior to 2.6.23.8 as well as 2.6.24-rc1 and 2.6.24=
-rc1 are vulnerable.
9. Linux Kernel wait_task_stopped Local Denial of Service Vulnerability
BugTraq ID: 26477
Remote: No
Date Published: 2007-11-16
Relevant URL: http://www.securityfocus.com/bid/26477
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly handle certain process-exit conditions.
Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users.
Linux kernel versions prior to 2.6.23.8 as well as 2.6.24-rc1 and 2.6.24=
-rc1 are vulnerable.
10. SMF Private Forum Messages Information Disclosure Vulnerability
BugTraq ID: 26508
Remote: Yes
Date Published: 2007-11-20
Relevant URL: http://www.securityfocus.com/bid/26508
Summary:
SMF is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to access sensitive information that m=
ay lead to further attacks.
SMF 1.1.4 is vulnerable; other versions may also be affected.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. important errors to control with swatch
http://www.securityfocus.com/archive/91/483940
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Insight24
Are There Holes in Your Network? View this on-demand webcast hosted by Dr=
. Chenxi Wang,=20
Principal Analyst, Security & Risk Management, Forrester Research, as she=
discusses the steps you can follow=20
to ensure your network isn't vulnerable. She will also outline key metric=
s organizations can use to measure the=20
maturity of their vulnerability management programs. Click on the link be=
low to view this on-demand webcast today!
http://showcase.insight24.com/?ForresterSecurityLinux