SecurityFocus Linux Newsletter #368
[email protected] 20 Dec 2007 21:20:00 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #368
----------------------------------------
This issue is Sponsored by: The Computer Forensics Show
Imangine the ability to view anything that ever appeared on almost any co=
mputer. The Computer Forensics Show is the "DON"T MISS" event of the year=
for IT professionals
The Computer Forensics Show
February 4-6, 2008
Washington Convention Center
Washington D.C.
www.computerforensicshow.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Copyrights and Wrongs
2.The Man in the Machine
II. LINUX VULNERABILITY SUMMARY
1. Samba Send_MailSlot Stack-Based Buffer Overflow Vulnerability
2. Linux Kernel Mmap_min_addr Local Security Bypass Vulnerability
3. XOOPS register.php Cross-Site Scripting Vulnerability
4. autofs nosuid Mount Option Local Privilege Escalation Vulnerabi=
lity
5. Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulne=
rability
6. Portage 'etc-update' Local Information Disclosure Vulnerability
7. Linux Kernel 'hrtimers' Local Denial of Service Vulnerability
8. ClamAV 'libclamav/pe.c' MEW Packed PE File Integer Overflow Vul=
nerability
9. Adobe Flash Player Multiple Security Vulnerabilities
10. Adobe Flash Player DNS Rebinding Vulnerability
11. libexif Image Tag Remote Integer Overflow Vulnerability
12. Linux Kernel IPv6 Hop-By-Hop Header Remote Denial of Service V=
ulnerability
13. ClamAV 'mspack.c' Off-By-One Buffer Overflow Vulnerability
14. Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerabi=
lity
15. Adobe Flash Player JPG Header Remote Heap Based Buffer Overflo=
w Vulnerability
16. Adobe Flash Player ActiveX Control 'navigateToURL' API Cross D=
omain Scripting Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Copyrights and Wrongs
By Mark Rasch
On October 1, 2007, Jammie Thomas -- a single mother living in Brainerd, =
Minnesota -- was sued in civil court for copyright infringement by the Re=
cording Industry Association of America. Three days later, the jury retur=
ned the verdict; Ms. Thomas was liable for willfully infringing the copyr=
ights on 24 songs. The fine: $222,000.=20
http://www.securityfocus.com/columnists/460
2.The Man in the Machine
By Federico Biancuzzi
In April 2007, when two security researchers demonstrated a flaw in the n=
ext-generation IPv6 routing scheme that would allow attackers to signific=
antly amplify any denial-of-service attack by a factor of at least 80, ne=
tworking expert Jun-ichiro "Itojun" Hagino worked to get Internet enginee=
rs to take the threat seriously.=20
http://www.securityfocus.com/columnists/459
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Samba Send_MailSlot Stack-Based Buffer Overflow Vulnerability
BugTraq ID: 26791
Remote: Yes
Date Published: 2007-12-10
Relevant URL: http://www.securityfocus.com/bid/26791
Summary:
Samba is prone to a remote stack-based buffer-overflow vulnerability beca=
use it fails to properly bounds-check user-supplied data before copying i=
t to an insufficiently sized memory buffer.
NOTE: This issue occurs only when the 'domain logons' option is enabled.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges. Successful attacks will completely compromise affected com=
puters. Failed exploit attempts will result in a denial of service.
2. Linux Kernel Mmap_min_addr Local Security Bypass Vulnerability
BugTraq ID: 26831
Remote: No
Date Published: 2007-12-11
Relevant URL: http://www.securityfocus.com/bid/26831
Summary:
The Linux kernel is prone to a security-bypass vulnerability.
A local attacker may exploit this issue to bypass certain security restri=
ctions, which may lead to other attacks.
Versions prior to Linux kernel 2.6.24-rc5 are vulnerable.
3. XOOPS register.php Cross-Site Scripting Vulnerability
BugTraq ID: 26835
Remote: Yes
Date Published: 2007-12-12
Relevant URL: http://www.securityfocus.com/bid/26835
Summary:
XOOPS is prone to a cross-site scripting vulnerability because it fails t=
o properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
XOOPS 2.2.5 is vulnerable; prior versions may also be affected.
4. autofs nosuid Mount Option Local Privilege Escalation Vulnerability
BugTraq ID: 26841
Remote: No
Date Published: 2007-12-12
Relevant URL: http://www.securityfocus.com/bid/26841
Summary:
The 'autofs' utility is prone to a local privilege-escalation vulnerabili=
ty because of a flaw in its default configuration. Filesystems mounted u=
nder '/net' using the 'hosts' automount map do not have the 'nosuid' moun=
t option enabled by default.
Attackers can leverage this issue to gain superuser privileges. Successfu=
l exploits will completely compromise affected computers.
5. Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerabilit=
y
BugTraq ID: 26842
Remote: Yes
Date Published: 2007-12-12
Relevant URL: http://www.securityfocus.com/bid/26842
Summary:
The 'iwlwifi' drive is prone to a NULL-pointer dereference vulnerability =
because of a flaw in the 'compatible/iwl3945-base.c' file.
Attackers can exploit this issue to trigger a kernel panic and cause deni=
al-of-service conditions.
Versions prior to iwlwifi 1.1.22 are vulnerable.
6. Portage 'etc-update' Local Information Disclosure Vulnerability
BugTraq ID: 26864
Remote: No
Date Published: 2007-12-13
Relevant URL: http://www.securityfocus.com/bid/26864
Summary:
Portage is prone to a local information-disclosure vulnerability because =
it creates temporary files with an unsuitable 'umask'. As a result, the =
files are world-readable.
An attacker can exploit this issue to access sensitive information that m=
ay lead to further attacks.
Versions prior to Portage 2.1.3.11 are vulnerable to this issue.
7. Linux Kernel 'hrtimers' Local Denial of Service Vulnerability
BugTraq ID: 26880
Remote: No
Date Published: 2007-12-14
Relevant URL: http://www.securityfocus.com/bid/26880
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly handle certain 'hrtimers' relative timeout value=
s.
Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users. Given the nature of this issue, attackers may als=
o be able to execute arbitrary code, but this has not been confirmed.
Versions prior to Linux kernel 2.6.23.10 are vulnerable.
8. ClamAV 'libclamav/pe.c' MEW Packed PE File Integer Overflow Vulnerabil=
ity
BugTraq ID: 26927
Remote: Yes
Date Published: 2007-12-18
Relevant URL: http://www.securityfocus.com/bid/26927
Summary:
ClamAV is prone to an integer-overflow vulnerability because it fails to =
properly verify user-supplied data.=20
Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the 'l=
ibclamav' library. Failed exploits may crash the application.
ClamAV 0.91.2 is vulnerable to this issue; other versions may also be aff=
ected.
9. Adobe Flash Player Multiple Security Vulnerabilities
BugTraq ID: 26929
Remote: Yes
Date Published: 2007-12-18
Relevant URL: http://www.securityfocus.com/bid/26929
Summary:
Adobe Flash Player is prone to multiple security vulnerabilities, includi=
ng:
- A privilege-escalation issue
- A cross-domain security-bypass issue
- An HTTP request-splitting issue
Attackers can exploit these vulnerabilities to compromise affected comput=
ers, execute arbitrary code and misrepresent how web content is served, c=
ached, or interpreted. Other attacks are also possible.=20
These issues affect Adobe Flash Player 9.0.48.0, 8.0.35.0, and 7.0.70.0 a=
nd prior.
Notes:
- The issues described in CVE-2007-6244 have been reassigned to BID 26949=
and BID 26960.
- The issue described in CVE-2007-6242 has been reassigned to BID 26951.
10. Adobe Flash Player DNS Rebinding Vulnerability
BugTraq ID: 26930
Remote: Yes
Date Published: 2007-12-18
Relevant URL: http://www.securityfocus.com/bid/26930
Summary:
Adobe Flash Player is prone to a DNS rebinding vulnerability that allows =
remote attackers to establish arbitrary TCP sessions.=20
=20
An attacker can exploit this issue by enticing an unsuspecting victim to =
view a malicious SWF file.=20
=20
Successfully exploiting this issue allows the attacker to bypass the appl=
ication's same-origin policy and set up connections to services on arbitr=
ary computers. This may lead to other attacks.
11. libexif Image Tag Remote Integer Overflow Vulnerability
BugTraq ID: 26942
Remote: Yes
Date Published: 2007-12-19
Relevant URL: http://www.securityfocus.com/bid/26942
Summary:
The libexif library is prone to an integer-overflow vulnerability because=
the software fails to ensure that integer values are not overrun.
Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of an application using the vuln=
erable library. Failed attempts will likely result in denial-of-service c=
onditions.
12. Linux Kernel IPv6 Hop-By-Hop Header Remote Denial of Service Vulnerab=
ility
BugTraq ID: 26943
Remote: Yes
Date Published: 2007-12-19
Relevant URL: http://www.securityfocus.com/bid/26943
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to adequately validate specially crafted IPv6 'Hop-By-Hop' =
headers.
Attackers can exploit this issue to cause a kernel panic, denying service=
to legitimate users.
13. ClamAV 'mspack.c' Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 26946
Remote: Yes
Date Published: 2007-12-19
Relevant URL: http://www.securityfocus.com/bid/26946
Summary:
ClamAV is prone to a buffer-overflow vulnerability because it fails to pr=
operly bounds-check user-supplied input before copying it to insufficient=
ly sized memory buffers.
Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the 'l=
ibclamav' library. Failed exploits may crash the application.
ClamAV 0.91.2 is vulnerable to this issue; other versions may also be aff=
ected.
14. Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerability
BugTraq ID: 26949
Remote: Yes
Date Published: 2007-12-18
Relevant URL: http://www.securityfocus.com/bid/26949
Summary:
Adobe Flash Player is prone to a cross-site scripting vulnerability becau=
se the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
15. Adobe Flash Player JPG Header Remote Heap Based Buffer Overflow Vulne=
rability
BugTraq ID: 26951
Remote: Yes
Date Published: 2007-12-19
Relevant URL: http://www.securityfocus.com/bid/26951
Summary:
Adobe Flash Player is prone to a remote heap-based buffer-overflow vulner=
ability because the application fails to use consistent signedness when h=
andling user-supplied input.
=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of a user running the application. Failed exploit attempts will l=
ikely cause denial-of-service conditions.
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0, and p=
rior versions.
NOTE: This issue was originally covered by BID 26929 (Adobe Flash Player =
Multiple Security Vulnerabilities).
16. Adobe Flash Player ActiveX Control 'navigateToURL' API Cross Domain S=
cripting Vulnerability
BugTraq ID: 26960
Remote: Yes
Date Published: 2007-12-18
Relevant URL: http://www.securityfocus.com/bid/26960
Summary:
The Adobe Flash Player ActiveX control is prone to a cross-domain scripti=
ng vulnerability.
An attacker may leverage this issue to execute arbitrary JavaScript in th=
e context of another domain.=20
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0. 7.0.70.0 and pr=
ior.
Note: This issue was previously disclosed in BID 26929 (Adobe Flash Playe=
r Multiple Security Vulnerabilities). However new technical details are a=
vailable, therefore the issue has been assigned to this BID.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: The Computer Forensics Show
Imangine the ability to view anything that ever appeared on almost any co=
mputer. The Computer Forensics Show is the "DON"T MISS" event of the year=
for IT professionals
The Computer Forensics Show
February 4-6, 2008
Washington Convention Center
Washington D.C.
www.computerforensicshow.com