SecurityFocus Linux Newsletter #382
[email protected] 25 Mar 2008 22:46:02 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #382
----------------------------------------
This issue is sponsored by bmighty:
Linux: The Impact of Service & Support
Review the practices & priorities of 354 business-technology professional=
s such as: using open source, Windows & Linux. A $99 value for FREE.
http://www.bmighty.com/drivers/linux.jhtml?cid=3DLSM-sfL
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.On the Border
2.Catch Them if You can
II. LINUX VULNERABILITY SUMMARY
1. RaidSonic NAS-4220-B Encryption Key Disclosure Vulnerability
2. F-Secure Multiple Products Multiple Remote Archive Handling Vul=
nerabilities
3. bzip2 Unspecified File Handling Vulnerability
4. Info-ZIP UnZip 'inflate_dynamic()' Remote Code Execution Vulner=
ability
5. S9Y Serendipity Trackbacks HTML Injection Vulnerability
6. MIT Kerberos5 kadmind Excessive File Descriptors Multiple Remot=
e Code Execution Vulnerabilities
7. MIT Kerberos 5 KDC Multiple Memory Corruption Based Information=
Disclosure Vulnerabilities
8. CUPS CGI Interface Remote Buffer Overflow Vulnerability
9. Asterisk RTP Codec Payload Handling Multiple Buffer Overflow Vu=
lnerabilities
10. Asterisk Call Authentication Security Bypass Vulnerability
11. Asterisk Logger and Manager Format String Vulnerabilities
12. xine-lib 'sdpplin_parse()' Remote Buffer Overflow Vulnerabilit=
y
13. Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
14. XWine WINE Configuration File Local Arbitrary Command Executio=
n Vulnerability
15. Novell eDirectory LDAP Extended Request Message Buffer Overflo=
w Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.On the Border
By Mark Rasch
Recently, I was going through an airport with my shoes, coat, jacket, and=
belt off as well as with my carry-on bag, briefcase, and laptop all sepa=
rated for easy inspection. I was heading through security at the Washingt=
on D.C., Ronald Reagan National Airport in Arlington, Virginia, or "Natio=
nal" as we locals call it. As I passed through the new magnetometer which=
gently puffed air all over my body -- which to me seems to be a cross be=
tween a glaucoma test and Marilyn Monroe in Gentlemen Prefer Blondes -- a=
TSA employee absent-mindedly asked if he could "inspect" my laptop compu=
ter. While the inspection was cursory, the situation immediately gave me =
pause: What was in my laptop anyway?
http://www.securityfocus.com/columnists/469
2.Catch Them if You Can
By Don Parker
High-profile network security breaches have proliferated over the past fe=
w years. While many "breaches" consist of lost data or a stolen laptop, t=
rue breaches -- where a online attacker compromises a network and removes=
data -- have become very common
http://www.securityfocus.com/columnists/468
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. RaidSonic NAS-4220-B Encryption Key Disclosure Vulnerability
BugTraq ID: 28264
Remote: No
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28264
Summary:
RaidSonic NAS-4220-B is prone to a vulnerability that can compromise encr=
ypted data. This issue occurs because the key used by the device to encry=
pt hard-drive data is stored insecurely in the configuration partitions o=
f each drive.
Attackers with physical access to the NAS can exploit this issue to decry=
pt potentially sensitive information stored on the hard disks.
This issue affects NAS-4220-B running firmware 2.6.0-n(2007-10-11). Other=
devices and firmware versions may also be affected.
2. F-Secure Multiple Products Multiple Remote Archive Handling Vulnerabil=
ities
BugTraq ID: 28282
Remote: Yes
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28282
Summary:
Multiple F-Secure products are prone to multiple remote archive-handling =
vulnerabilities because the applications fails to properly handle malform=
ed archive files.
Successfully exploiting these issues allows remote attackers to trigger u=
nhandled exceptions. Various unspecified effects (potentially including d=
enial of service or remote code execution) are possible.
3. bzip2 Unspecified File Handling Vulnerability
BugTraq ID: 28286
Remote: Yes
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28286
Summary:
The 'bzip2' application is prone to a remote file-handling vulnerability =
because the application fails to properly handle malformed files.
Successful exploits may allow remote code to run, but this has not been c=
onfirmed. Exploit attempts will likely crash the application.
This issue affects bzip2 1.0.4; prior versions may also be affected.
4. Info-ZIP UnZip 'inflate_dynamic()' Remote Code Execution Vulnerability
BugTraq ID: 28288
Remote: Yes
Date Published: 2008-03-17
Relevant URL: http://www.securityfocus.com/bid/28288
Summary:
UnZip is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted ZIP file ('.zip').
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.
UnZip 5.52 is vulnerable; other versions may be affected as well.
5. S9Y Serendipity Trackbacks HTML Injection Vulnerability
BugTraq ID: 28298
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28298
Summary:
Serendipity is prone to an HTML-injection vulnerability because it fails =
to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script co=
de in the context of the affected site, to steal cookie-based authenticat=
ion credentials, or to control how the site is rendered to the user; othe=
r attacks are also possible.
Versions prior to Serendipity 1.3 are vulnerable.
6. MIT Kerberos5 kadmind Excessive File Descriptors Multiple Remote Code =
Execution Vulnerabilities
BugTraq ID: 28302
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28302
Summary:
The 'kadmind' server is prone to multiple vulnerabilities that can allow =
attackers to execute remote code because of array overruns in the RPC lib=
rary code.
Exploiting these issues may allow attackers to execute arbitrary code wit=
h superuser privileges, facilitating in the complete compromise of affect=
ed computers. Failed attempts will cause crashes and deny service to leg=
itimate users of the application.
Note that a compromise of a Master KDC (Key Distribution Center) principa=
l and policy server will affect multiple hosts that use the server for au=
thentication, potentially contributing to their compromise as well.
These issues affect:
- krb5-1.4 through krb5-1.63, where configurations allow large numbers of=
open file descriptors.
- krb5-1.2.2 through krb5-1.3, where '<unistd.h>' does not define F=
D_SETSIZE. Note that this is likely the case in many GNU/Linux distribu=
tions; Solaris 10 and Mac OS X 10.4 may be unaffected.
7. MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclo=
sure Vulnerabilities
BugTraq ID: 28303
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28303
Summary:
MIT Kerberos 5 KDC is prone to multiple information-disclosure vulnerabil=
ities resulting from memory corruption.
These issues occur when KDC is configured to support Kerberos 4 and proce=
sses malformed krb4 messages.
An attacker can exploit these issues to obtain potentially sensitive info=
rmation that will aid in further attacks. Failed exploit attempts will li=
kely result in denial-of-service conditions. Given the nature of these vu=
lnerabilities, the attacker could leverage these issues to execute arbitr=
ary code, but this has not been confirmed.
MIT Kerberos 5 version 1.6.3 KDC is vulnerable; other versions may also b=
e affected.
8. CUPS CGI Interface Remote Buffer Overflow Vulnerability
BugTraq ID: 28307
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28307
Summary:
CUPS is prone to a remote buffer-overflow vulnerability because it fails =
to properly bounds-check user-supplied data before copying it to an insuf=
ficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.
CUPS 1.3.5 is reported vulnerable; other versions may be affected as well=
.
NOTE: This issue was originally covered in BID 28304 (Apple Mac OS X 2008=
-002 Multiple Security Vulnerabilities), but has been given its own recor=
d because further information has emerged.
9. Asterisk RTP Codec Payload Handling Multiple Buffer Overflow Vulnerabi=
lities
BugTraq ID: 28308
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28308
Summary:
Asterisk is prone to multiple buffer-overflow vulnerabilities because it =
fails to perform adequate boundary checks on user-supplied data before co=
pying it to insufficiently sized buffers.
Exploiting these issues may allow an attacker to corrupt memory and cause=
denial-of-service conditions or potentially execute arbitrary code in th=
e context of the application.
These issues affect the following versions:
Asterisk Open Source prior to 1.4.18.1 and 1.4.19-rc3.
Asterisk Open Source prior to 1.6.0-beta6
Asterisk Business Edition prior to C.1.6.1
AsteriskNOW prior to 1.0.2
Asterisk Appliance Developer Kit prior to Asterisk 1.4 revision 109386
s800i (Asterisk Appliance) prior to 1.1.0.2
10. Asterisk Call Authentication Security Bypass Vulnerability
BugTraq ID: 28310
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28310
Summary:
Asterisk is prone to a security-bypass vulnerability that allows attacker=
s to make unauthenticated calls through the SIP channel driver.=20
Exploiting this issue may also aid in other attacks.
This issue affects the following versions:
Asterisk Open Source prior to 1.2.27
Asterisk Open Source prior to 1.4.18.1 and 1.4.19-rc3.
Asterisk Open Source prior to 1.6.0-beta6=20
Asterisk Business Edition all A versions
Asterisk Business Edition prior to B.2.5.1
Asterisk Business Edition prior to C.1.6.2
AsteriskNOW prior to 1.0.2=20
Asterisk Appliance Developer Kit prior to Asterisk 1.4 revision 109393
s800i (Asterisk Appliance) prior to 1.1.0.2
11. Asterisk Logger and Manager Format String Vulnerabilities
BugTraq ID: 28311
Remote: Yes
Date Published: 2008-03-18
Relevant URL: http://www.securityfocus.com/bid/28311
Summary:
Asterisk is prone to multiple format-string vulnerabilities because the =
application fails to adequately sanitize user-supplied input before pass=
ing it as the format-specifier to a formatted-printing function. =20
A remote attacker may potentially execute arbitrary code in the context o=
f the affected application. Failed exploit attempts will likely result in=
a denial of service.
These issues affect versions prior to Asterisk Open Source 1.6.0-beta6.
12. xine-lib 'sdpplin_parse()' Remote Buffer Overflow Vulnerability
BugTraq ID: 28312
Remote: Yes
Date Published: 2008-03-19
Relevant URL: http://www.securityfocus.com/bid/28312
Summary:
The 'xine-lib' library is prone to a remote buffer-overflow vulnerability=
because the software fails to perform adequate boundary checks on user-s=
upplied data.=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running an application that relies on the affected li=
brary. Failed exploit attempts will result in a denial-of-service conditi=
on.
=20
This issue affects xine-lib 1.1.10.1; other versions may also be vulnera=
ble.
13. Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
BugTraq ID: 28350
Remote: No
Date Published: 2008-03-20
Relevant URL: http://www.securityfocus.com/bid/28350
Summary:
Gentoo is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information and ga=
in access to SSL private encryption keys. Information obtained may aid i=
n further attacks.
The issue affects multiple ebuilds included in Gentoo Linux.
14. XWine WINE Configuration File Local Arbitrary Command Execution Vulne=
rability
BugTraq ID: 28369
Remote: No
Date Published: 2008-03-20
Relevant URL: http://www.securityfocus.com/bid/28369
Summary:
XWine is prone to a vulnerability that can allow local attackers to execu=
te arbitrary commands.
Local attackers can exploit this issue to execute arbitrary commands when=
ever a local user executes a program under WINE.
This issue affects XWine 1.0.1; other versions may also be vulnerable.
15. Novell eDirectory LDAP Extended Request Message Buffer Overflow Vulne=
rability
BugTraq ID: 28434
Remote: Yes
Date Published: 2008-03-24
Relevant URL: http://www.securityfocus.com/bid/28434
Summary:
Novell eDirectory is prone to a buffer-overflow vulnerability because it =
fails to adequately bounds-check user-supplied data before copying it to =
an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected application. Failed exploit attempts will result in =
a denial-of-service condition.
This issue affects eDirectory 8.8.1 and prior as well as 8.7.3.9 and prio=
r versions for Linux, Solaris, and Windows platforms.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by bmighty:
Linux: The Impact of Service & Support
Review the practices & priorities of 354 business-technology professional=
s such as: using open source, Windows & Linux. A $99 value for FREE.
http://www.bmighty.com/drivers/linux.jhtml?cid=3DLSM-sfL