SecurityFocus Linux Newsletter #388
[email protected] 7 May 2008 20:58:02 -0000
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #388
----------------------------------------
This issue is sponsored by Verisign
Offer strong encryption to your site with VeriSign Server-Gated Cryptogra=
phy (SGC) SSL to enable every site visitor to connect with the strongest =
encryption available to them. Learn about all of the benefits of strong e=
ncryption with the free white paper.
http://clk.atdmt.com/SFI/go/scrtysrv1170000033sfi/direct/01/
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Just Who's Being Exploited?
2.On the Border
II. LINUX VULNERABILITY SUMMARY
1. Linux Terminal Server Project 'ldm' Information Disclosure Vuln=
erability
2. util-linux-ng 'login' Remote Log Injection Weakness
3. Linux Kernel 'dnotify.c' Local Race Condition Vulnerability
4. Linux Kernel RLIMIT_CPU Zero Limit Handling Local Security Bypa=
ss Vulnerability
5. Linux Kernel Tehuti Network Driver 'BDX_OP_WRITE' Memory Corrup=
tion Vulnerability
6. WebMod Multiple Remote Security Vulnerabilities
7. Linux Kernel 'fcntl_setlk()' SMP Ordering Local Denial of Servi=
ce Vulnerability
8. Linux Kernel IPSec Fragmented ESP Packet Remote Denial of Servi=
ce Vulnerability
9. Linux Kernel '/include/xen/blkif.h' 32-on-64 Support Denial Of =
Service Vulnerability
10. Linux Kernel Asynchronous FIFO IO Local Denial of Service Vuln=
erability
11. Linux Kernel Direction Flag Local Memory Corruption Vulnerabil=
ity
12. Linux Kernel 'ssm_i' Emulation Hypervisor Panic Denial of Serv=
ice Vulnerability
13. Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Just Who's Being Exploited?
By Jamie Reid
Last month's revelation that Tipping Point paid out a prize of $10,000 an=
d a new laptop (MSRP: about $2000) at the CanSecWest conference, for the =
privilege of being the exclusive licensor of a heretofore unpublished vul=
nerability in Apple's Safari web browser to researcher, Charles Miller of=
Independent Security Evaluators, may lend some credence to this adage.
http://www.securityfocus.com/columnists/470
2.On the Border
By Mark Rasch
Recently, I was going through an airport with my shoes, coat, jacket, and=
belt off as well as with my carry-on bag, briefcase, and laptop all sepa=
rated for easy inspection. I was heading through security at the Washingt=
on D.C., Ronald Reagan National Airport in Arlington, Virginia, or "Natio=
nal" as we locals call it. As I passed through the new magnetometer which=
gently puffed air all over my body -- which to me seems to be a cross be=
tween a glaucoma test and Marilyn Monroe in Gentlemen Prefer Blondes -- a=
TSA employee absent-mindedly asked if he could "inspect" my laptop compu=
ter. While the inspection was cursory, the situation immediately gave me =
pause: What was in my laptop anyway?
http://www.securityfocus.com/columnists/469
II. LINUX VULNERABILITY SUMMARY
------------------------------------
1. Linux Terminal Server Project 'ldm' Information Disclosure Vulnerabili=
ty
BugTraq ID: 28960
Remote: Yes
Date Published: 2008-04-28
Relevant URL: http://www.securityfocus.com/bid/28960
Summary:
Linux Terminal Server Project is prone to an information-disclosure vulne=
rability.
An attacker can exploit this issue from the local network to obtain poten=
tially sensitive information that may aid in further attacks.
2. util-linux-ng 'login' Remote Log Injection Weakness
BugTraq ID: 28983
Remote: Yes
Date Published: 2008-04-29
Relevant URL: http://www.securityfocus.com/bid/28983
Summary:
The 'login' utility from 'util-linux-ng' is prone to a weakness that allo=
ws remote attackers to inject false information into log files. This issu=
e occurs because the utility fails to properly sanitize user-supplied inp=
ut.
Successful exploits allow malicious users to inject false information int=
o log files. The injected information may aid in indirect attacks against=
log-monitoring systems or may allow attackers to obfuscate malicious act=
ivity.
Versions prior to util-linux-ng 2.13.1.1 are prone to this issue.
3. Linux Kernel 'dnotify.c' Local Race Condition Vulnerability
BugTraq ID: 29003
Remote: No
Date Published: 2008-05-01
Relevant URL: http://www.securityfocus.com/bid/29003
Summary:
The Linux kernel is prone to a local race-condition vulnerability.
A local attacker may exploit this issue to crash the computer or to gain =
elevated privileges on the affected computer.
4. Linux Kernel RLIMIT_CPU Zero Limit Handling Local Security Bypass Vuln=
erability
BugTraq ID: 29004
Remote: No
Date Published: 2008-05-01
Relevant URL: http://www.securityfocus.com/bid/29004
Summary:
The Linux kernel is prone to a local security-bypass vulnerability becaus=
e it fails to properly handle certain RLIMIT_CPU time limitations.
Attackers can exploit this issue to bypass certain security restrictions,=
which may lead to further attacks.
Versions prior to Linux kernel 2.6.22 are affected.
5. Linux Kernel Tehuti Network Driver 'BDX_OP_WRITE' Memory Corruption Vu=
lnerability
BugTraq ID: 29014
Remote: No
Date Published: 2008-05-02
Relevant URL: http://www.securityfocus.com/bid/29014
Summary:
The Linux kernel is prone to a memory-corruption vulnerability because of=
insufficient boundary checks in the Tehuti network driver.
Local attackers could exploit this issue to cause denial-of-service condi=
tions, bypass certain security restrictions, and potentially access sensi=
tive information or gain elevated privileges.
These issues affect versions prior to Linux 2.6.25.1.
6. WebMod Multiple Remote Security Vulnerabilities
BugTraq ID: 29031
Remote: Yes
Date Published: 2008-05-03
Relevant URL: http://www.securityfocus.com/bid/29031
Summary:
WebMod is prone to multiple remote security vulnerabilities, including a =
directory-traversal issue, a stack-based buffer-overflow issue, multiple =
memory-corruption issues, and an information-disclosure issue.
Attackers can exploit these issues to execute arbitrary code with the pri=
vileges of the user running the affected application, obtain sensitive in=
formation to aid in further attacks, or cause denial-of-service condition=
s.=20
WebMod 0.48 is vulnerable; other versions may also be affected.
7. Linux Kernel 'fcntl_setlk()' SMP Ordering Local Denial of Service Vuln=
erability
BugTraq ID: 29076
Remote: No
Date Published: 2008-05-06
Relevant URL: http://www.securityfocus.com/bid/29076
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.
Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users.
Versions prior to Linux kernel 2.6.25.2 and 2.4.36.4 are vulnerable.
8. Linux Kernel IPSec Fragmented ESP Packet Remote Denial of Service Vuln=
erability
BugTraq ID: 29081
Remote: Yes
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29081
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected computer, denyin=
g service to legitimate users.
Note: this issue occurs on computers that have netscreen firewalls or Cis=
co PIX installed.
9. Linux Kernel '/include/xen/blkif.h' 32-on-64 Support Denial Of Service=
Vulnerability
BugTraq ID: 29082
Remote: No
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29082
Summary:
The Linux kernel is prone to a denial-of-service vulnerability due to a a=
lack of sanity checks when handling values when running 32-bit paravirtu=
alized guests on a 64-bit host.
Local, privileged attackers can leverage the issue to crash the kernel an=
d deny service to legitimate users.
10. Linux Kernel Asynchronous FIFO IO Local Denial of Service Vulnerabili=
ty
BugTraq ID: 29083
Remote: No
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29083
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.
Attackers can exploit this issue to trigger kernel panics, denying servic=
e to legitimate users.
Versions prior to Linux kernel 2.4.21 are vulnerable.
11. Linux Kernel Direction Flag Local Memory Corruption Vulnerability
BugTraq ID: 29084
Remote: No
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29084
Summary:
The Linux kernel is prone to a vulnerability that causes kernel memory co=
rruption.
A local attacker can exploit this issue to crash the affected computer, d=
enying service to legitimate users. Due to the nature of this issue arbit=
rary code-execution may be possible, however this has not been confirmed.
12. Linux Kernel 'ssm_i' Emulation Hypervisor Panic Denial of Service Vul=
nerability
BugTraq ID: 29085
Remote: No
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29085
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability in certain=
virtualized environments.=20
An attacker can exploit this issue to crash the affected computer, denyin=
g service to legitimate users.
This issue may only affect the IA-64 architecture.
13. Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
BugTraq ID: 29086
Remote: No
Date Published: 2008-05-07
Relevant URL: http://www.securityfocus.com/bid/29086
Summary:
The Linux kernel is prone to a denial-of-service vulnerability when proce=
ss traces are performed on 64-bit computers.
Local attackers can leverage the issue to crash the kernel and deny servi=
ce to legitimate users.
III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Verisign
Offer strong encryption to your site with VeriSign Server-Gated Cryptogra=
phy (SGC) SSL to enable every site visitor to connect with the strongest =
encryption available to them. Learn about all of the benefits of strong e=
ncryption with the free white paper.
http://clk.atdmt.com/SFI/go/scrtysrv1170000033sfi/direct/01/