SecurityFocus Linux Newsletter #373
[email protected] 24 Jan 2008 17:34:22 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #373
----------------------------------------
This issue is Sponsored by: Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Mother May I?
2. Finding a Cure for Data Loss
II. LINUX VULNERABILITY SUMMARY
1. Linux Kernel VFS Unauthorized File Access Vulnerability
2. Cisco VPN Client for Windows Local Denial of Service Vulnerabil=
ity
3. Boost Library Regular Expression Remote Denial of Service Vulne=
rabilities
4. apt-listchanges Unsafe Paths Library Import Local Shell Code Ex=
ecution Vulnerability
5. RETIRED: X.Org X Server Local Privilege Escalation and Informat=
ion Disclosure Vulnerabilities
6. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerabili=
ty
7. X.Org X Server 'Xinput' Extension Local Privilege Escalation Vu=
lnerability
8. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
9. X.Org X Server 'EVI' Extension Local Privilege Escalation Vulne=
rability
10. X.Org X Server 'PassMessage' Request Local Privilege Escalatio=
n Vulnerability
11. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation =
Vulnerability
12. X.Org X 'Server X:1 -sp' Command Information Disclosure Vulner=
ability
13. BitDefender Products Update Server HTTP Daemon Directory Trave=
rsal Vulnerability
14. Apache Tomcat SingleSignOn Remote Information Disclosure Vulne=
rability
15. MoinMoin MOIN_ID Cookie Remote Authentication Bypass Vulnerabi=
lity
16. IBM AIX WebSM Remote Client For Linux Local Insecure File Perm=
issions Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Mother May I?
By Mark Rasch
"Sure, you can have a cookie, but you may not."We all have had that discu=
ssion before -- either with our parents or our kids. A recent case from N=
orth Dakota reveals that the difference between those two concepts may le=
ad not only to civil liability, but could land you in jail.
http://www.securityfocus.com/columnists/463
2.Finding a Cure for Data Loss
By Jamie Reid
Despite missteps in protecting customer information, companies have large=
ly escaped the wrath of consumers.=20
http://www.securityfocus.com/columnists/462
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Linux Kernel VFS Unauthorized File Access Vulnerability
BugTraq ID: 27280
Remote: No
Date Published: 2008-01-14
Relevant URL: http://www.securityfocus.com/bid/27280
Summary:
The Linux kernel is prone to an unauthorized file-access vulnerability af=
fecting the VFS (Virtual Filesystem) module.
A local attacker can exploit this issue to access arbitrary files on the =
affected computer. Successfully exploiting this issue may grant the attac=
ker elevated privileges on affected computers. Other attacks are also pos=
sible.
This issue affects kernel versions prior to 2.6.23.14.
2. Cisco VPN Client for Windows Local Denial of Service Vulnerability
BugTraq ID: 27289
Remote: No
Date Published: 2008-01-15
Relevant URL: http://www.securityfocus.com/bid/27289
Summary:
Cisco VPN Client for Windows is prone to a local denial-of-service vulner=
ability because the software's IPsec driver fails to handle certain IOCTL=
s.
Successfully exploiting this issue allows local attackers to crash affect=
ed computers, denying further service to legitimate users.
This issue affects 'cvpndrva.sys' 5.0.02.0090; other versions of the dri=
ver may also be affected.
3. Boost Library Regular Expression Remote Denial of Service Vulnerabilit=
ies
BugTraq ID: 27325
Remote: Yes
Date Published: 2008-01-16
Relevant URL: http://www.securityfocus.com/bid/27325
Summary:
The Boost library is prone to a remote denial-of-service vulnerability be=
cause it fails to adequately verify user-supplied input on regular expres=
sions.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions on applications that use the affected library.
This issue affects Boost 1.33.1 and 1.34.1; other versions may also be af=
fected.
4. apt-listchanges Unsafe Paths Library Import Local Shell Code Execution=
Vulnerability
BugTraq ID: 27331
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27331
Summary:
The 'apt-listchanges' tool is prone to a vulnerability that allows arbitr=
ary shell code to run. This issue occurs because the software uses unsafe=
paths when importing certain libraries.
Attackers can exploit this issue to execute arbitrary shell code with sup=
eruser privileges. Successful attacks will completely compromise the comp=
uter.
Versions prior to apt-listchanges 2.82 are vulnerable.
5. RETIRED: X.Org X Server Local Privilege Escalation and Information Dis=
closure Vulnerabilities
BugTraq ID: 27336
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27336
Summary:
X.Org X Server is prone to multiple local privilege-escalation vulnerabil=
ities and an information-disclosure vulnerability.
Attackers can exploit these issues to execute arbitrary code with superus=
er privileges, crash the affected computer, or obtain potentially sensiti=
ve information.
NOTE: This BID is being retired because each of the vulnerabilities has b=
een given its own record as follows:
27350 X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
27351 X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulner=
ability
27352 X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
27353 X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerabi=
lity
27354 X.Org X Server 'PassMessage' Request Local Privilege Escalation Vul=
nerability
27355 X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulne=
rability
27356 X.Org X Server X:1 -sp Command Information Disclosure Vulnerability
6. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
BugTraq ID: 27350
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27350
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
7. X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerabi=
lity
BugTraq ID: 27351
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27351
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
8. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
BugTraq ID: 27352
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27352
Summary:
X.Org X Server is prone to a buffer-overflow vulnerability because it fai=
ls to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the server. Failed attacks will cause denial-of-service conditio=
ns.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vuln=
erabilities), but has been given its own record to better document the i=
ssue.
9. X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerabilit=
y
BugTraq ID: 27353
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27353
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
10. X.Org X Server 'PassMessage' Request Local Privilege Escalation Vulne=
rability
BugTraq ID: 27354
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27354
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.=20
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges. Successfully exploiting this issue will result in the comple=
te compromise of an affected computer. Failed exploit attempts will likel=
y crash the computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
11. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulnera=
bility
BugTraq ID: 27355
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27355
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
12. X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
BugTraq ID: 27356
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27356
Summary:
X.Org X Server is prone to a local information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information =
that may lead to further attacks.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
13. BitDefender Products Update Server HTTP Daemon Directory Traversal Vu=
lnerability
BugTraq ID: 27358
Remote: Yes
Date Published: 2008-01-19
Relevant URL: http://www.securityfocus.com/bid/27358
Summary:
BitDefender Update Server is prone to a directory-traversal vulnerability=
because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access potentially sensitive =
information that could aid in further attacks.
BitDefender Security for File Servers, BitDefender Enterprise Manger, and=
other BitDefender products that include the Update Server are vulnerable=
. This issue affects Update Server when running on Windows; Linux and UNI=
X variants may also be affected.
14. Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerabilit=
y
BugTraq ID: 27365
Remote: Yes
Date Published: 2008-01-20
Relevant URL: http://www.securityfocus.com/bid/27365
Summary:
Apache Tomcat is prone to a remote information-disclosure vulnerability b=
ecause the application fails to properly restrict access to sensitive inf=
ormation.
Remote attackers can exploit this issue to obtain confidential user-authe=
ntication credentials.
The issue affects Tomcat 5.5.20; prior versions may also be vulnerable.
15. MoinMoin MOIN_ID Cookie Remote Authentication Bypass Vulnerability
BugTraq ID: 27404
Remote: Yes
Date Published: 2008-01-22
Relevant URL: http://www.securityfocus.com/bid/27404
Summary:
MoinMoin is prone to an authentication-bypass vulnerability because it fa=
ils to properly sanitize user-supplied input.
An attacker can exploit this issue to gain unauthorized access to the aff=
ected application, which may lead to further attacks.
Versions in the MoinMoin 1.5 series are vulnerable.
16. IBM AIX WebSM Remote Client For Linux Local Insecure File Permissions=
Vulnerability
BugTraq ID: 27433
Remote: No
Date Published: 2008-01-22
Relevant URL: http://www.securityfocus.com/bid/27433
Summary:
IBM AIX WebSM Remote Client for Linux is prone to a local insecure-file-p=
ermissions vulnerability.
A local attacker can exploit this issue to gain unauthorized access to ce=
rtain files and alter the behavior of the affected application. This may=
help in further attacks.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com