SecurityFocus Linux Newsletter #381
[email protected] 19 Mar 2008 18:43:31 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #381
----------------------------------------
This issue is sponsored by Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Catch Them if You can
2.Integrating More Intelligence into Your IDS, Part 2
II. LINUX VULNERABILITY SUMMARY
1. MoinMoin GUI Editor Multiple Cross Site Scripting Vulnerabiliti=
es
2. MoinMoin Macro Code Information Disclosure Vulnerability
3. Dovecot 'Tab' Character Password Check Security Bypass Vulnerab=
ility
4. SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vul=
nerability
5. SAP MaxDB sdbstarter Environment Variable Local Privilege Escal=
ation Vulnerability
6. ManageEngine ServiceDesk Plus 'SolutionSearch.do' Cross-Site Sc=
ripting Vulnerability
7. Lighttpd mod_userdir Information Disclosure Vulnerability
8. RaidSonic NAS-4220-B Encryption Key Disclosure Vulnerability
9. F-Secure Multiple Products Multiple Remote Archive Handling Vul=
nerabilities
10. Info-ZIP UnZip 'inflate_dynamic()' Remote Code Execution Vulne=
rability
11. MIT Kerberos5 kadmind Excessive File Descriptors Multiple Remo=
te Code Execution Vulnerabilities
12. MIT Kerberos 5 KDC Multiple Memory Corruption Based Informatio=
n Disclosure Vulnerabilities
13. Asterisk RTP Codec Payload Handling Multiple Buffer Overflow V=
ulnerabilities
14. Asterisk Logger and Manager Format String Vulnerabilities
15. xine-lib 'sdpplin_parse()' Remote Buffer Overflow Vulnerabilit=
y
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Catch Them if You Can
By Don Parker
High-profile network security breaches have proliferated over the past fe=
w years. While many "breaches" consist of lost data or a stolen laptop, t=
rue breaches -- where a online attacker compromises a network and removes=
data -- have become very common
http://www.securityfocus.com/columnists/468
2.Integrating More Intelligence into Your IDS, Part 2
By Don Parker and Ryan Wegner=20
The more an intrusion detection system (IDS) knows about the network it i=
s trying to protect, the better it will be able to protect the network. T=
his is the fundamental principle behind target-based intrusion detection,=
where an IDS knows about the hosts on the network.
http://www.securityfocus.com/infocus/1899
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. MoinMoin GUI Editor Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 28173
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28173
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.
2. MoinMoin Macro Code Information Disclosure Vulnerability
BugTraq ID: 28177
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28177
Summary:
MoinMoin is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain potentially sensitive informat=
ion that may aid in further attacks.
3. Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
BugTraq ID: 28181
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28181
Summary:
Dovecot is prone to a security-bypass vulnerability because the applicati=
on fails to adequately sanitize user-supplied input.=20
An attacker may exploit this issue to gain unauthorized access the affect=
ed application. Successful exploits will compromise the application.
Versions prior to Dovecot 1.0.13 and 1.1.rc3 are vulnerable. The vendor s=
tates that this issue affects only password databases that have blocking =
enabled.
NOTE: Reports indicate that this issue can be exploited only on versions =
after Dovecot 1.0.10, which introduced the 'skip_password_check' field.
4. SAP MaxDB 'vserver' Component Remote Heap Memory Corruption Vulnerabil=
ity
BugTraq ID: 28183
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28183
Summary:
SAP MaxDB is prone to a heap-based memory-corruption vulnerability.=20
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Successfully exploiting this issue wi=
ll compromise the affected application and possibly the underlying comput=
er.=20
This issue affects MaxDB 7.6.0.37 running on the Linux operating system.=
Other versions running on different platforms may also be affected.
5. SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation V=
ulnerability
BugTraq ID: 28185
Remote: No
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28185
Summary:
SAP MaxDB is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code wi=
th superuser privileges. This will lead to the complete compromise of an=
affected computer.
This issue affects MaxDB 7.6.0.37 on both Linux and Solaris platforms. O=
ther UNIX variants are most likely affected. Microsoft Windows versions =
are not vulnerable to this issue.
6. ManageEngine ServiceDesk Plus 'SolutionSearch.do' Cross-Site Scripting=
Vulnerability
BugTraq ID: 28191
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28191
Summary:
ManageEngine ServiceDesk Plus is prone to a cross-site scripting vulnerab=
ility because the application fails to properly sanitize user-supplied in=
put.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Microsoft Windows is v=
ulnerable; other versions may be affected as well.
7. Lighttpd mod_userdir Information Disclosure Vulnerability
BugTraq ID: 28226
Remote: Yes
Date Published: 2008-03-12
Relevant URL: http://www.securityfocus.com/bid/28226
Summary:
The 'lighttpd' program is prone to a vulnerability that may allow attacke=
rs to access sensitive information because the application fails to prope=
rly handle exceptional conditions.
Information obtained may aid in further attacks.
This issue affects lighttpd 1.4.18; other versions may also be vulnerable=
.
8. RaidSonic NAS-4220-B Encryption Key Disclosure Vulnerability
BugTraq ID: 28264
Remote: No
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28264
Summary:
RaidSonic NAS-4220-B is prone to a vulnerability that can compromise encr=
ypted data. This issue occurs because the key used by the device to encry=
pt hard-drive data is stored insecurely in the configuration partitions o=
f each drive.
Attackers with physical access to the NAS can exploit this issue to decry=
pt potentially sensitive information stored on the hard disks.
This issue affects NAS-4220-B running firmware 2.6.0-n(2007-10-11). Other=
devices and firmware versions may also be affected.
9. F-Secure Multiple Products Multiple Remote Archive Handling Vulnerabil=
ities
BugTraq ID: 28282
Remote: Yes
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28282
Summary:
Multiple F-Secure products are prone to multiple remote archive-handling =
vulnerabilities because the applications fails to properly handle malform=
ed archive files.
Successfully exploiting these issues allows remote attackers to trigger u=
nhandled exceptions. Various unspecified effects (potentially including d=
enial of service or remote code execution) are possible.
10. Info-ZIP UnZip 'inflate_dynamic()' Remote Code Execution Vulnerabilit=
y
BugTraq ID: 28288
Remote: Yes
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28288
Summary:
UnZip is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted ZIP file ('.zip').
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.
UnZip 5.52 is vulnerable; other versions may be affected as well.
11. MIT Kerberos5 kadmind Excessive File Descriptors Multiple Remote Code=
Execution Vulnerabilities
BugTraq ID: 28302
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28302
Summary:
kadmind is prone to multiple vulnerabilities that can allow remote code-e=
xecution due to array over-runs in the RPC library code.
Exploiting these issues may allow attackers to execute arbitrary code wit=
h superuser privileges, facilitating in the complete compromise of affect=
ed computers. Failed attempts will cause crashes and deny service to leg=
itimate users of the application. Note that a compromise of a Master KDC =
(Key Distribution Center) principal and policy server will affect multipl=
e hosts that use the server for authentication, potentially contributing =
to their compromise as well.
These issues affect:
- krb5-1.4 through krb5-1.63, where configurations allow large numbers of=
open file descriptors.
- krb5-1.2.2 through krb5-1.3, where '<unistd.h>' does not define F=
D_SETSIZE. Note that this is likely the case in many GNU/Linux distribu=
tions; Solaris 10 and Mac OS X 10.4 may be unaffected.
12. MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Discl=
osure Vulnerabilities
BugTraq ID: 28303
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28303
Summary:
MIT Kerberos 5 KDC is prone to multiple information-disclosure vulnerabil=
ities resulting from memory-corruption.
These issues occur when KDC is configured to support Kerberos 4 and proce=
sses malformed krb4 messages.
An attacker can exploit these issues to gain access to potentially sensit=
ive information that will aid in further attacks. Failed exploit attempts=
will likely result in a denial-of-service conditions. Due to the nature =
of these vulnerabilities, the issues could be leveraged to execute arbitr=
ary code however this has not been confirmed.
MIT Kerberos 5 version 1.6.3 KDC is vulnerable; other versions may also b=
e affected.
13. Asterisk RTP Codec Payload Handling Multiple Buffer Overflow Vulnerab=
ilities
BugTraq ID: 28308
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28308
Summary:
Asterisk is prone to multiple buffer-overflow vulnerabilities because it =
fails to perform adequate boundary checks on user-supplied data before co=
pying it to insufficiently sized buffers.
Exploiting these issues may allow an attacker to corrupt memory and cause=
denial-of-service conditions or potentially execute arbitrary code in th=
e context of the application.
These issues affect the following versions:
Asterisk Open Source versions prior to prior to 1.4.18.1 and 1.4.19-rc3.
Asterisk Open Source versions prior to 1.6.0-beta6
Asterisk Business Edition versions prior to C.1.6.1
AsteriskNOW versions prior to 1.0.2
Asterisk Appliance Developer Kit versions prior to Asterisk 1.4 revision =
109386
s800i (Asterisk Appliance) versions prior to 1.1.0.2
14. Asterisk Logger and Manager Format String Vulnerabilities
BugTraq ID: 28311
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28311
Summary:
Asterisk is prone to multiple format-string vulnerabilities because the =
application fails to adequately sanitize user-supplied input before pass=
ing it as the format-specifier to a formatted-printing function. =20
A remote attacker may potentially execute arbitrary code in the context o=
f the affected application. Failed exploit attempts will likely result in=
a denial of service.
These issues affect Asterisk Open Source versions prior to 1.6.0-beta6.
15. xine-lib 'sdpplin_parse()' Remote Buffer Overflow Vulnerability
BugTraq ID: 28312
Remote: Yes
Date Published: 2008-03-19
Relevant URL: http://www.securityfocus.com/bid/28312
Summary:
The xine-lib library is prone to a remote buffer-overflow vulnerability. =
This issue occurs because the software fails to perform adequate boundary=
checks on user-supplied data.=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.
=20
This issue affects xine-lib 1.1.10.1; other versions may also be vulnera=
ble.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com