SecurityFocus Linux Newsletter #394

[email protected] 20 Jun 2008 17:16:26 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #394
----------------------------------------

This issue is sponsored by Black Hat USA:

Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
 Network with 4,000 delegates from 50 nations.  Visit product displays by=
 30 top sponsors in a relaxed setting.=20
www.blackhat.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Racing Against Reversers
       2.Anti-Social Networking
II.  LINUX VULNERABILITY SUMMARY
       1. OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vu=
lnerability
       2. Net-SNMP Remote Authentication Bypass Vulnerability
       3. TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulner=
ability
       4. X.Org X Server RENDER Extension 'ProcRenderCreateCursor()' Deni=
al of Service Vulnerability
       5. X.Org X Server MIT-SHM Extension Information Disclosure Vulnera=
bility
       6. X.Org X server RENDER Extension Multiple Integer Overflow Vulne=
rabilities
       7. Sun Java System Access Manager Authentication Bypass Vulnerabil=
ity
       8. Red Hat Enterprise Linux OpenOffice Insecure Library Path Local=
 Privilege Escalation Vulnerability
       9. Fetchmail Verbose Mode Large Log Messages Remote Denial of Serv=
ice Vulnerability
       10. Linux Kernel 'pppol2tp_recvmsg()' Remote Denial of Service Vul=
nerability
       11. No-IP DUC Client for Windows Local Information Disclosure Vuln=
erability
       12. Skulltag Malformed Packet Denial of Service Vulnerability
       13. Novell eDirectory iMonitor Unspecified Cross-Site Scripting Vu=
lnerability
       14. PHP 'rfc822_write_address()' Function Buffer Overflow Vulnerab=
ility
III. LINUX FOCUS LIST SUMMARY
       1. Vulnerability and Patch-Management in Linux (and other Unix)
       2. sshd log analyzer
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Racing Against Reversers
By Federico Biancuzzi
Each time a new digital rights management (DRM) system is released, hacke=
rs are not far behind in cracking it. Reverse engineers have taken down t=
he security protecting content encoded for Windows Media, iTunes, DVDs, a=
nd HD-DVDs.=20
http://www.securityfocus.com/columnists/474

2.Anti-Social Networking
By Mark Rasch
On May 15, 2008, a federal grand jury Los Angeles indicted 49-year-old Lo=
ri Drew of O.Fallon, Missouri, on charges of unauthorized access to a com=
puter, typically used in hacking cases. Yet, Drew's alleged actions had l=
ittle to do with computer intrusions.=20
http://www.securityfocus.com/columnists/473


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerabi=
lity
BugTraq ID: 29622
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29622
Summary:
OpenOffice is prone to a remote heap-based buffer-overflow vulnerability =
because of errors in processing certain files.

Remote attackers can exploit this issue by enticing victims into opening =
maliciously crafted OpenOffice.org document files.

Successful exploits may allow attackers to execute arbitrary code within =
the context of the affected application. Failed exploit attempts will lik=
ely result in a denial of service.

The issue affects OpenOffice 2 up to and including 2.4.

2. Net-SNMP Remote Authentication Bypass Vulnerability
BugTraq ID: 29623
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29623
Summary:
Net-SNMP is prone to a remote authentication-bypass vulnerability caused =
by a design error.

Successfully exploiting this issue will allow attackers to gain unauthori=
zed access to the affected application.

Net-SNMP 5.4.1, 5.3.2, 5.2.4, and prior versions are vulnerable.

3. TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
BugTraq ID: 29657
Remote: Yes
Date Published: 2008-06-11
Relevant URL: http://www.securityfocus.com/bid/29657
Summary:
TYPO3 is prone to a cross-site scripting vulnerability and a file-upload =
vulnerability because it fails to properly sanitize user-supplied input.=20

An attacker may leverage the cross-site scripting issue to execute arbitr=
ary script code in the browser of an unsuspecting user in the context of =
the affected site. This may allow the attacker to steal cookie-based auth=
entication credentials and to launch other attacks. The attacker can expl=
oit the file-upload issue to execute arbitrary code in the context of the=
 webserver.

TYPO3 3.x, 4.0 to 4.0.8, 4.1 to 4.1.6, and 4.2.0 are vulnerable.

4. X.Org X Server RENDER Extension 'ProcRenderCreateCursor()' Denial of S=
ervice Vulnerability
BugTraq ID: 29665
Remote: Yes
Date Published: 2008-06-11
Relevant URL: http://www.securityfocus.com/bid/29665
Summary:
X.Org X Server is prone to a denial-of-service vulnerability because the =
software fails to properly handle exceptional conditions.

Attackers who can connect to a vulnerable X Server may exploit this issue=
 to crash the targeted server, denying further service to legitimate user=
s.

5. X.Org X Server MIT-SHM Extension Information Disclosure Vulnerability
BugTraq ID: 29669
Remote: Yes
Date Published: 2008-06-11
Relevant URL: http://www.securityfocus.com/bid/29669
Summary:
X.Org X Server is prone to an information-disclosure vulnerability that l=
ets X clients read arbitrary X server memory.

Attackers can exploit this issue to obtain sensitive information that may=
 lead to further attacks.

6. X.Org X server RENDER Extension Multiple Integer Overflow Vulnerabilit=
ies
BugTraq ID: 29670
Remote: Yes
Date Published: 2008-06-11
Relevant URL: http://www.securityfocus.com/bid/29670
Summary:
The RENDER component for X Server is prone to multiple integer-overflow v=
ulnerabilities because it fails to perform adequate boundary checks on us=
er-supplied data.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of a user running the software. Failed exploit attempts like=
ly cause denial-of-service conditions.

7. Sun Java System Access Manager Authentication Bypass Vulnerability
BugTraq ID: 29676
Remote: Yes
Date Published: 2008-06-11
Relevant URL: http://www.securityfocus.com/bid/29676
Summary:
Sun Java System Access Manager is prone to an authentication-bypass vulne=
rability.

Exploiting this issue can allow remote attackers to access resources in a=
n unauthorized manner or to gain administrative privileges to the applica=
tion. This may aid in further attacks.

Sun Java System Access Manager 7.1 is affected by this issue.

8. Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privil=
ege Escalation Vulnerability
BugTraq ID: 29695
Remote: No
Date Published: 2008-06-13
Relevant URL: http://www.securityfocus.com/bid/29695
Summary:
Red Hat Enterprise Linux OpenOffice packages are prone to a local privile=
ge-escalation vulnerability because they were built with insecure library=
 search paths.

Exploiting this issue allows local attackers to execute arbitrary code wi=
th the privileges of the user running the affected application.

OpenOffice 1.1.x built and shipped with Red Hat Enterprise Linux 3 and 4 =
are affected.

9. Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vul=
nerability
BugTraq ID: 29705
Remote: Yes
Date Published: 2008-06-13
Relevant URL: http://www.securityfocus.com/bid/29705
Summary:
Fetchmail is prone to a denial-of-service vulnerability because the appli=
cation fails to handle exceptional conditions.=20

An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.  Given the nature of the issue, remote =
code execution may also be possible, but this has not been confirmed.

Versions prior to Fetchmail 6.3.9 are vulnerable.

10. Linux Kernel 'pppol2tp_recvmsg()' Remote Denial of Service Vulnerabil=
ity
BugTraq ID: 29747
Remote: Yes
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29747
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to crash the affected computer on the =
local network, denying service to legitimate users. Given the nature of t=
his issue, code execution may be possible, but this has not been confirme=
d.

Versions prior to Linux Kernel 2.6.26-rc6 are vulnerable.

11. No-IP DUC Client for Windows Local Information Disclosure Vulnerabili=
ty
BugTraq ID: 29758
Remote: No
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29758
Summary:
The DUC application for No-IP is prone to a local information-disclosure =
vulnerability when it is running on Microsoft Windows.

Successfully exploiting this issue allows attackers to obtain potentially=
 sensitive information that may aid in further attacks.

12. Skulltag Malformed Packet Denial of Service Vulnerability
BugTraq ID: 29760
Remote: Yes
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29760
Summary:
Skulltag is prone to a vulnerability that can cause denial-of-service con=
ditions.

A successful attack will deny service to legitimate users.

Skulltag 0.97d2-RC3 is vulnerable; other versions may also be affected.

13. Novell eDirectory iMonitor Unspecified Cross-Site Scripting Vulnerabi=
lity
BugTraq ID: 29782
Remote: Yes
Date Published: 2008-06-17
Relevant URL: http://www.securityfocus.com/bid/29782
Summary:
The Novell eDirectory server iMonitor is prone to a cross-site scripting =
vulnerability because the application fails to properly sanitize user-sup=
plied input.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

The issue affects Novell eDirectory versions prior to and including 8.8.2=
 and 8.7.3.9 for Solaris, Linux and Windows 2000/2003.

14. PHP 'rfc822_write_address()' Function Buffer Overflow Vulnerability
BugTraq ID: 29829
Remote: Yes
Date Published: 2008-06-19
Relevant URL: http://www.securityfocus.com/bid/29829
Summary:
PHP is prone to a buffer-overflow vulnerability because the application f=
ails to perform boundary checks before copying user-supplied data to insu=
fficiently sized memory buffers.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected webserver. Failed exploit attempts will likely=
 crash the webserver, denying service to legitimate users.=20

PHP versions 5.2.6 and prior are vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Vulnerability and Patch-Management in Linux (and other Unix)
http://www.securityfocus.com/archive/91/493478

2. sshd log analyzer
http://www.securityfocus.com/archive/91/493280

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Black Hat USA:

Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
 Network with 4,000 delegates from 50 nations.  Visit product displays by=
 30 top sponsors in a relaxed setting.=20
www.blackhat.com