SecurityFocus Linux Newsletter #373

[email protected] 24 Jan 2008 17:34:22 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #373
----------------------------------------

This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Mother May I?
       2. Finding a Cure for Data Loss
II.  LINUX VULNERABILITY SUMMARY
       1. Linux Kernel VFS Unauthorized File Access Vulnerability
       2. Cisco VPN Client for Windows Local Denial of Service Vulnerabil=
ity
       3. Boost Library Regular Expression Remote Denial of Service Vulne=
rabilities
       4. apt-listchanges Unsafe Paths Library Import Local Shell Code Ex=
ecution Vulnerability
       5. RETIRED: X.Org X Server Local Privilege Escalation and Informat=
ion Disclosure Vulnerabilities
       6. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerabili=
ty
       7. X.Org X Server 'Xinput' Extension Local Privilege Escalation Vu=
lnerability
       8. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
       9. X.Org X Server 'EVI' Extension Local Privilege Escalation Vulne=
rability
       10. X.Org X Server 'PassMessage' Request Local Privilege Escalatio=
n Vulnerability
       11. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation =
Vulnerability
       12. X.Org X 'Server X:1 -sp' Command Information Disclosure Vulner=
ability
       13. BitDefender Products Update Server HTTP Daemon Directory Trave=
rsal Vulnerability
       14. Apache Tomcat SingleSignOn Remote Information Disclosure Vulne=
rability
       15. MoinMoin MOIN_ID Cookie Remote Authentication Bypass Vulnerabi=
lity
       16. IBM AIX WebSM Remote Client For Linux Local Insecure File Perm=
issions Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Mother May I?
By Mark Rasch
"Sure, you can have a cookie, but you may not."We all have had that discu=
ssion before -- either with our parents or our kids. A recent case from N=
orth Dakota reveals that the difference between those two concepts may le=
ad not only to civil liability, but could land you in jail.
http://www.securityfocus.com/columnists/463

2.Finding a Cure for Data Loss
By Jamie Reid
Despite missteps in protecting customer information, companies have large=
ly escaped the wrath of consumers.=20
http://www.securityfocus.com/columnists/462


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Linux Kernel VFS Unauthorized File Access Vulnerability
BugTraq ID: 27280
Remote: No
Date Published: 2008-01-14
Relevant URL: http://www.securityfocus.com/bid/27280
Summary:
The Linux kernel is prone to an unauthorized file-access vulnerability af=
fecting the VFS (Virtual Filesystem) module.

A local attacker can exploit this issue to access arbitrary files on the =
affected computer. Successfully exploiting this issue may grant the attac=
ker elevated privileges on affected computers. Other attacks are also pos=
sible.

This issue affects kernel versions prior to 2.6.23.14.

2. Cisco VPN Client for Windows Local Denial of Service Vulnerability
BugTraq ID: 27289
Remote: No
Date Published: 2008-01-15
Relevant URL: http://www.securityfocus.com/bid/27289
Summary:
Cisco VPN Client for Windows is prone to a local denial-of-service vulner=
ability because the software's IPsec driver fails to handle certain IOCTL=
s.

Successfully exploiting this issue allows local attackers to crash affect=
ed computers, denying further service to legitimate users.

This issue affects  'cvpndrva.sys' 5.0.02.0090; other versions of the dri=
ver may also be affected.

3. Boost Library Regular Expression Remote Denial of Service Vulnerabilit=
ies
BugTraq ID: 27325
Remote: Yes
Date Published: 2008-01-16
Relevant URL: http://www.securityfocus.com/bid/27325
Summary:
The Boost library is prone to a remote denial-of-service vulnerability be=
cause it fails to adequately verify user-supplied input on regular expres=
sions.

Successful exploits may allow remote attackers to cause denial-of-service=
 conditions on applications that use the affected library.

This issue affects Boost 1.33.1 and 1.34.1; other versions may also be af=
fected.

4. apt-listchanges Unsafe Paths Library Import Local Shell Code Execution=
 Vulnerability
BugTraq ID: 27331
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27331
Summary:
The 'apt-listchanges' tool is prone to a vulnerability that allows arbitr=
ary shell code to run. This issue occurs because the software uses unsafe=
 paths when importing certain libraries.

Attackers can exploit this issue to execute arbitrary shell code with sup=
eruser privileges. Successful attacks will completely compromise the comp=
uter.

Versions prior to apt-listchanges 2.82 are vulnerable.

5. RETIRED: X.Org X Server Local Privilege Escalation and Information Dis=
closure Vulnerabilities
BugTraq ID: 27336
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27336
Summary:
X.Org X Server is prone to multiple local privilege-escalation vulnerabil=
ities and an information-disclosure vulnerability.

Attackers can exploit these issues to execute arbitrary code with superus=
er privileges, crash the affected computer, or obtain potentially sensiti=
ve information.

NOTE: This BID is being retired because each of the vulnerabilities has b=
een given its own record as follows:

27350 X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
27351 X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulner=
ability
27352 X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
27353 X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerabi=
lity
27354 X.Org X Server 'PassMessage' Request Local Privilege Escalation Vul=
nerability
27355 X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulne=
rability
27356 X.Org X Server X:1 -sp Command Information Disclosure Vulnerability

6. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
BugTraq ID: 27350
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27350
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.

Attackers can exploit this issue to execute arbitrary code with superuser=
 privileges or to crash the affected computer.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

7. X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerabi=
lity
BugTraq ID: 27351
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27351
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.

Attackers can exploit this issue to execute arbitrary code with superuser=
 privileges or to crash the affected computer.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

8. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
BugTraq ID: 27352
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27352
Summary:
X.Org X Server is prone to a buffer-overflow vulnerability because it fai=
ls to perform adequate boundary checks on user-supplied input.

Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the server. Failed attacks will cause denial-of-service conditio=
ns.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver  Multiple Local Privilege Escalation and Information Disclosure  Vuln=
erabilities), but has been given its own record to better document the  i=
ssue.

9. X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerabilit=
y
BugTraq ID: 27353
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27353
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.

Attackers can exploit this issue to execute arbitrary code with superuser=
 privileges or to crash the affected computer.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

10. X.Org X Server 'PassMessage' Request Local Privilege Escalation Vulne=
rability
BugTraq ID: 27354
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27354
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.=20

Attackers can exploit this issue to execute arbitrary code with superuser=
 privileges. Successfully exploiting this issue will result in the comple=
te compromise of an affected computer. Failed exploit attempts will likel=
y crash the computer.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

11. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulnera=
bility
BugTraq ID: 27355
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27355
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.

Attackers can exploit this issue to execute arbitrary code with superuser=
 privileges or to crash the affected computer.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

12. X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
BugTraq ID: 27356
Remote: No
Date Published: 2008-01-17
Relevant URL: http://www.securityfocus.com/bid/27356
Summary:
X.Org X Server is prone to a local information-disclosure vulnerability.

Attackers can exploit this issue to gain access to sensitive information =
that may lead to further attacks.

NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.

13. BitDefender Products Update Server HTTP Daemon Directory Traversal Vu=
lnerability
BugTraq ID: 27358
Remote: Yes
Date Published: 2008-01-19
Relevant URL: http://www.securityfocus.com/bid/27358
Summary:
BitDefender Update Server is prone to a directory-traversal vulnerability=
 because it fails to sufficiently sanitize user-supplied input data.

Exploiting this issue allows an attacker to access potentially sensitive =
information that could aid in further attacks.

BitDefender Security for File Servers, BitDefender Enterprise Manger, and=
 other BitDefender products that include the Update Server are vulnerable=
. This issue affects Update Server when running on Windows; Linux and UNI=
X variants may also be affected.

14. Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerabilit=
y
BugTraq ID: 27365
Remote: Yes
Date Published: 2008-01-20
Relevant URL: http://www.securityfocus.com/bid/27365
Summary:
Apache Tomcat is prone to a remote information-disclosure vulnerability b=
ecause the application fails to properly restrict access to sensitive inf=
ormation.

Remote attackers can exploit this issue to obtain confidential user-authe=
ntication credentials.

The issue affects Tomcat 5.5.20; prior versions may also be vulnerable.

15. MoinMoin MOIN_ID Cookie Remote Authentication Bypass Vulnerability
BugTraq ID: 27404
Remote: Yes
Date Published: 2008-01-22
Relevant URL: http://www.securityfocus.com/bid/27404
Summary:
MoinMoin is prone to an authentication-bypass vulnerability because it fa=
ils to properly sanitize user-supplied input.

An attacker can exploit this issue to gain unauthorized access to the aff=
ected application, which may lead to further attacks.

Versions in the MoinMoin 1.5 series are vulnerable.

16. IBM AIX WebSM Remote Client For Linux Local Insecure File Permissions=
 Vulnerability
BugTraq ID: 27433
Remote: No
Date Published: 2008-01-22
Relevant URL: http://www.securityfocus.com/bid/27433
Summary:
IBM AIX WebSM Remote Client for Linux is prone to a local insecure-file-p=
ermissions vulnerability.

A local attacker can exploit this issue to gain unauthorized access to ce=
rtain files and alter the behavior  of the affected application. This may=
 help in further attacks.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com