SecurityFocus Linux Newsletter #383

[email protected] 3 Apr 2008 23:23:59 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #383
----------------------------------------

This issue is sponsored by IBM=AE Rational=AE AppScan

Failure to properly secure Web applications significantly impacts your ab=
ility to protect sensitive client and corporate data. IBM Rational AppSca=
n is an automated scanner that monitors, identifies and helps remediate v=
ulnerabilities.
Download a free trial of AppScan and see how it can help prevent against =
the threat of attack.
https://www.watchfire.com/securearea/appscan.aspx?id=3D701700000009T0r


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.On the Border
       2.Catch Them if You can
II.  LINUX VULNERABILITY SUMMARY
       1. Novell eDirectory LDAP Extended Request Message Buffer Overflow=
 Vulnerability
       2. OpenSSH X connections Session Hijacking Vulnerability
       3. Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote =
Vulnerabilities
       4. policyd-weight Insecure Temporary File Creation Vulnerability
       5. lighttpd SSL Error Denial of Service Vulnerability
       6. Mondo Rescue Prior to 2.2.5 Unspecified Vulnerability
       7. Linux Audit Daemon 'audit_log_user_command()' Local Buffer Over=
flow Vulnerability
       8. Sympa 'Content-Type' Header Remote Denial Of Service Vulnerabil=
ity
       9. CUPS 'gif_read_lzw()' GIF File Buffer Overflow Vulnerability
       10. IBM DB2 Content Manager Unspecified Security Vulnerability
       11. Gnome Desktop Screensaver NIS Authentication Local Unauthorize=
d Access Vulnerability=20
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.On the Border
By Mark Rasch
Recently, I was going through an airport with my shoes, coat, jacket, and=
 belt off as well as with my carry-on bag, briefcase, and laptop all sepa=
rated for easy inspection. I was heading through security at the Washingt=
on D.C., Ronald Reagan National Airport in Arlington, Virginia, or "Natio=
nal" as we locals call it. As I passed through the new magnetometer which=
 gently puffed air all over my body -- which to me seems to be a cross be=
tween a glaucoma test and Marilyn Monroe in Gentlemen Prefer Blondes -- a=
 TSA employee absent-mindedly asked if he could "inspect" my laptop compu=
ter. While the inspection was cursory, the situation immediately gave me =
pause: What was in my laptop anyway?
http://www.securityfocus.com/columnists/469

2.Catch Them if You Can
By Don Parker
High-profile network security breaches have proliferated over the past fe=
w years. While many "breaches" consist of lost data or a stolen laptop, t=
rue breaches -- where a online attacker compromises a network and removes=
 data -- have become very common
http://www.securityfocus.com/columnists/468


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Novell eDirectory LDAP Extended Request Message Buffer Overflow Vulner=
ability
BugTraq ID: 28434
Remote: Yes
Date Published: 2008-03-24
Relevant URL: http://www.securityfocus.com/bid/28434
Summary:
Novell eDirectory is prone to a buffer-overflow vulnerability because it =
fails to adequately bounds-check user-supplied data before copying it to =
an insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected application. Failed exploit attempts will result in =
a denial-of-service condition.

This issue affects eDirectory 8.8.1 and prior as well as 8.7.3.9 and prio=
r versions for Linux, Solaris, and Windows platforms.

2. OpenSSH X connections Session Hijacking Vulnerability
BugTraq ID: 28444
Remote: No
Date Published: 2008-03-25
Relevant URL: http://www.securityfocus.com/bid/28444
Summary:
OpenSSH is prone to a vulnerability that allows attackers to hijack forwa=
rded X connections.

Successfully exploiting this issue may allow an attacker run arbitrary sh=
ell commands with the privileges of the user running the affected applica=
tion.

This issue affects OpenSSH 4.3p2; other versions may also be affected.=20

NOTE: This issue affects the portable version of OpenSSH and may not affe=
ct OpenSSH running on OpenBSD.

3. Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnera=
bilities
BugTraq ID: 28448
Remote: Yes
Date Published: 2008-03-26
Relevant URL: http://www.securityfocus.com/bid/28448
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox 2.0.0.12 and prior versions.

Exploiting these issues can allow attackers to:

- steal authentication credentials
- obtain potentially sensitive information
- violate the same-origin policy
- execute scripts with elevated privileges
- cause denial-of-service conditions
- potentially execute arbitrary code=20
- perform cross-site request-forgery attacks

Other attacks are possible.

These issues are present in Firefox 2.0.0.12 and prior versions. Many of =
these issues are present in Mozilla Thunderbird 2.0.0.12 and prior versio=
ns as well as SeaMonkey 1.1.8 and prior versions.

4. policyd-weight Insecure Temporary File Creation Vulnerability
BugTraq ID: 28480
Remote: No
Date Published: 2008-03-27
Relevant URL: http://www.securityfocus.com/bid/28480
Summary:
The 'policyd-weight' daemon creates temporary files in an insecure manner=
.

An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks, overwriting arbitrary files in the context of=
 the affected application.=20

Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
 attacks may also be possible.

5. lighttpd SSL Error Denial of Service Vulnerability
BugTraq ID: 28489
Remote: Yes
Date Published: 2008-03-27
Relevant URL: http://www.securityfocus.com/bid/28489
Summary:
The 'lighttpd' program is prone to a remote denial-of-service vulnerabili=
ty because it fails to handle exceptional conditions.
=20
Successfully exploiting this issue allows remote attackers to close forei=
gn SSL connections, denying service to legitimate users.

The issue affects lighttpd 1.4.19 and prior versions.

6. Mondo Rescue Prior to 2.2.5 Unspecified Vulnerability
BugTraq ID: 28522
Remote: No
Date Published: 2008-03-31
Relevant URL: http://www.securityfocus.com/bid/28522
Summary:
Mondo Rescue is prone to an unspecified vulnerability.

Very few technical details are currently available. We will update this B=
ID as more information emerges.

Versions prior to Mondo Rescue 2.2.5 are vulnerable.

7. Linux Audit Daemon 'audit_log_user_command()' Local Buffer Overflow Vu=
lnerability
BugTraq ID: 28524
Remote: No
Date Published: 2008-03-31
Relevant URL: http://www.securityfocus.com/bid/28524
Summary:
The Linux Audit daemon is prone to a local buffer-overflow vulnerability =
because the software fails to properly bounds-check user-supplied input.

Successfully exploiting this issue allows local attackers to execute arbi=
trary machine code with elevated privileges. This may facilitate the comp=
romise of affected computers.

Versions prior to Linux Audit 1.7 are vulnerable.

8. Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
BugTraq ID: 28539
Remote: Yes
Date Published: 2008-03-27
Relevant URL: http://www.securityfocus.com/bid/28539
Summary:
Sympa is prone to a remote denial-of-service vulnerability because it fai=
ls to handle specially crafted 'Content-Type' headers.

An attacker can exploit this issue to cause the application to crash. Suc=
cessful attacks will deny service to legitimate users.

Versions prior to Sympa 5.4 are affected.

9. CUPS 'gif_read_lzw()' GIF File Buffer Overflow Vulnerability
BugTraq ID: 28544
Remote: Yes
Date Published: 2008-04-01
Relevant URL: http://www.securityfocus.com/bid/28544
Summary:
CUPS is prone to a buffer-overflow vulnerability because it fails to perf=
orm adequate boundary checks on user-supplied GIF image data before copyi=
ng it to an insufficiently sized buffer.

Successful exploits allow attackers to execute arbitrary code with the pr=
ivileges of a user running the utilities. Failed exploit attempts likely =
cause denial-of-service conditions.

CUPS 1.3.6 is vulnerable; other versions may also be affected.

10. IBM DB2 Content Manager Unspecified Security Vulnerability
BugTraq ID: 28567
Remote: No
Date Published: 2008-04-02
Relevant URL: http://www.securityfocus.com/bid/28567
Summary:
IBM DB2 Content Manager is prone to an unspecified security vulnerability=
.

Very few technical details are currently available. We will update this B=
ID as more information emerges.

Versions prior to 8.3 Fix Pack 8 are vulnerable.

11. Gnome Desktop Screensaver NIS Authentication Local Unauthorized Acces=
s Vulnerability=20
BugTraq ID: 28575
Remote: No
Date Published: 2008-04-02
Relevant URL: http://www.securityfocus.com/bid/28575
Summary:
Gnome Desktop is prone to a local unauthorized-access vulnerability.

A local attacker can exploit this issue to gain access to the affected co=
mputer. Successfully exploiting this issue may lead to other attacks.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by IBM=AE Rational=AE AppScan

Failure to properly secure Web applications significantly impacts your ab=
ility to protect sensitive client and corporate data. IBM Rational AppSca=
n is an automated scanner that monitors, identifies and helps remediate v=
ulnerabilities.
Download a free trial of AppScan and see how it can help prevent against =
the threat of attack.
https://www.watchfire.com/securearea/appscan.aspx?id=3D701700000009T0r