SecurityFocus Linux Newsletter #401

[email protected] 7 Aug 2008 00:45:28 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #401
----------------------------------------

This issue is sponsored by Sponsored by IBM=AE Rational=AE AppScan
Copy: Failure to properly secure Web applications significantly impacts y=
our ability to protect sensitive client and corporate data. IBM Rational =
AppScan is an automated scanner that monitors, identifies and helps remed=
iate vulnerabilities.=20
Download a free trial of AppScan and see how it can help prevent against =
the threat of attack.
https://www.watchfire.com/securearea/appscan.aspx?id=3D701700000009T0r


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.An Astonishing Collaboration
       2.Bad-Code Blues
II.  LINUX VULNERABILITY SUMMARY
       1. Links 'only proxies' Unspecified Security Vulnerability
       2. HTTrack URI Parsing Remote Buffer Overflow Vulnerability
       3. @Mail Multiple Local Information Disclosure Vulnerabilities
       4. 'nfs-utils' Package for Red Hat Enterprise Linux 5 TCP Wrappers=
 Security Bypass Vulnerability
       5. libxslt RC4 Encryption and Decryption Functions Buffer Overflow=
 Vulnerability
       6. OpenSC CardOS M4 Smart Cards Insecure Permissions Vulnerability
       7. SAP MaxDB 'dbmsrv' Process 'PATH' Environment Variable Local Pr=
ivilege Escalation Vulnerability
       8. Python Multiple Buffer Overflow Vulnerabilities
       9. Ingres Database Multiple Local Vulnerabilities
       10. Linux Kernel 'uvc_driver.c ' Format Descriptor Parsing Buffer =
Overflow Vulnerability
       11. XAMPP for Linux 'text' Parameter Multiple Cross-Site Scripting=
 Vulnerabilities
       12. JBoss Enterprise Application Platform Information Disclosure V=
ulnerability
       13. Linux Kernel 'snd_seq_oss_synth_make_info()' Information Discl=
osure Vulnerability
       14. DD-WRT Site Survey SSID Script Injection Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. root shell auditing
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.An Astonishing Collaboration
By Dan Kaminsky
Wow. It's out. It's finally, finally out. Sweet!
http://www.securityfocus.com/columnists/477

2.Bad-Code Blues
By Don Parker
The current state of secure software development by corporations both lar=
ge and small is a mess. We are still cursed with half-baked software, and=
 as a result, a never ending stream of vulnerabilities. Secure coding pra=
ctices and active quality assurance (QA) efforts are now more mainstream,=
 but that still hasn.t made much of a dent.
http://www.securityfocus.com/columnists/476


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Links 'only proxies' Unspecified Security Vulnerability
BugTraq ID: 30422
Remote: Yes
Date Published: 2008-07-29
Relevant URL: http://www.securityfocus.com/bid/30422
Summary:
Links is prone to an unspecified security vulnerability related to provid=
ing URIs to external programs.

Very few details are available regarding this issue.  We will update this=
 BID as more information emerges.

2. HTTrack URI Parsing Remote Buffer Overflow Vulnerability
BugTraq ID: 30425
Remote: Yes
Date Published: 2008-07-28
Relevant URL: http://www.securityfocus.com/bid/30425
Summary:
HTTrack is prone to a remote buffer-overflow vulnerability because it fai=
ls to perform sufficient boundary checks when parsing long URIs.

Remote attackers can exploit this  issue by enticing victims into crawlin=
g a malicious URI designed to  exploit this issue.=20

Successful exploits may allow attackers to execute arbitrary code within =
the context of an affected application. Failed exploit attempts will like=
ly result in a denial of service.

Versions prior to HTTrack 3.42-3 are vulnerable.

3. @Mail Multiple Local Information Disclosure Vulnerabilities
BugTraq ID: 30434
Remote: No
Date Published: 2008-07-30
Relevant URL: http://www.securityfocus.com/bid/30434
Summary:
@Mail is prone to multiple information-disclosure vulnerabilities because=
 the application fails to properly restrict access to sensitive files.

An unprivileged attacker may exploit these issues to obtain sensitive inf=
ormation.

@Mail 5.41 is vulnerable; other versions may also be affected.

4. 'nfs-utils' Package for Red Hat Enterprise Linux 5 TCP Wrappers Securi=
ty Bypass Vulnerability
BugTraq ID: 30466
Remote: Yes
Date Published: 2008-07-31
Relevant URL: http://www.securityfocus.com/bid/30466
Summary:
The 'nfs-utils' package is prone to a security-bypass vulnerability becau=
se it was not properly built with TCP Wrappers support.

Remote attackers can exploit this issue to bypass certain security restri=
ctions and gain access to NFS services on vulnerable computers.

This issue occurs in the 'nfs-utils' package built with Red Hat Enterpris=
e Linux 5.

5. libxslt RC4 Encryption and Decryption Functions Buffer Overflow Vulner=
ability
BugTraq ID: 30467
Remote: Yes
Date Published: 2008-07-31
Relevant URL: http://www.securityfocus.com/bid/30467
Summary:
The 'libxslt' library is prone to a heap-based buffer-overflow vulnerabil=
ity because the software fails to perform adequate boundary checks on use=
r-supplied data.=20

An attacker may exploit this issue to execute arbitrary code with the pri=
vileges of the user running an application that relies on the affected li=
brary. Failed exploit attempts will likely result in denial-of-service co=
nditions.
=20
 This issue affects libxslt 1.1.8 to 1.1.24.

6. OpenSC CardOS M4 Smart Cards Insecure Permissions Vulnerability
BugTraq ID: 30473
Remote: No
Date Published: 2008-07-31
Relevant URL: http://www.securityfocus.com/bid/30473
Summary:
OpenSC insecurely initializes smart cards  and USB crypto tokens based on=
 Seimens CardOS M4.

Attackers can leverage this issue to change the PIN number on a card with=
out having knowledge of the existing PIN or PUK number. Successfully expl=
oiting this issue allows attackers to use the card in further attacks.

 NOTE: This issue cannot be leveraged to access an existing PIN number.

This issue occurs in versions prior to OpenSC 0.11.5.

7. SAP MaxDB 'dbmsrv' Process 'PATH' Environment Variable Local Privilege=
 Escalation Vulnerability
BugTraq ID: 30474
Remote: No
Date Published: 2008-07-31
Relevant URL: http://www.securityfocus.com/bid/30474
Summary:
SAP MaxDB is prone to a local privilege-escalation vulnerability that occ=
urs in the 'dbmsrv' process because the application fails to sufficiently=
 sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary code with 'sdb:sd=
ba' privileges. Successfully exploiting this issue will compromise the af=
fected application and possibly the underlying computer.=20

SAP MaxDB 7.6.03.15 on Linux is vulnerable; other versions running on dif=
ferent platforms may also be affected.

8. Python Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 30491
Remote: Yes
Date Published: 2008-07-31
Relevant URL: http://www.securityfocus.com/bid/30491
Summary:
Python is prone to multiple buffer-overflow vulnerabilities.

Successful exploits may allow attackers to execute arbitrary code in the =
context of applications using the vulnerable Python modules. This may res=
ult in a compromise of the underlying system. Failed attempts may lead to=
 a denial-of-service condition.=20

These issues affect versions prior to Python 2.5.2-r6.

9. Ingres Database Multiple Local Vulnerabilities
BugTraq ID: 30512
Remote: No
Date Published: 2008-08-01
Relevant URL: http://www.securityfocus.com/bid/30512
Summary:
Ingres Database is prone to multiple local vulnerabilities:=20

- Multiple local privilege-escalation vulnerabilities
- A vulnerability that may allow attackers to overwrite arbitrary files.=20

Local attackers can exploit these issues to gain elevated privileges on t=
he affected computer, execute arbitrary code with superuser privileges, a=
nd overwrite arbitrary files owned by 'Ingres' user.

10. Linux Kernel 'uvc_driver.c ' Format Descriptor Parsing Buffer Overflo=
w Vulnerability
BugTraq ID: 30514
Remote: No
Date Published: 2008-08-02
Relevant URL: http://www.securityfocus.com/bid/30514
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it f=
ails to perform adequate boundary checks on user-supplied data.=20

Local attackers can exploit this issue to execute arbitrary code with sup=
eruser privileges. Successfully exploiting this issue will result in the =
complete compromise of affected computers. Failed exploit attempts will r=
esult in a denial-of-service condition.=20

Versions prior to Linux kernel 2.6.26.1 are vulnerable.

11. XAMPP for Linux 'text' Parameter Multiple Cross-Site Scripting Vulner=
abilities
BugTraq ID: 30535
Remote: Yes
Date Published: 2008-08-04
Relevant URL: http://www.securityfocus.com/bid/30535
Summary:
XAMPP for Linux is prone to multiple cross-site scripting vulnerabilities=
 because it fails to properly sanitize user-supplied input.=20

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks.

XAMPP 1.6.7 for Linux is vulnerable; other versions may also be affected.

12. JBoss Enterprise Application Platform Information Disclosure Vulnerab=
ility
BugTraq ID: 30540
Remote: Yes
Date Published: 2008-08-05
Relevant URL: http://www.securityfocus.com/bid/30540
Summary:
JBoss Enterprise Application Platform is prone to a remote information-di=
sclosure vulnerability.

Remote attackers can exploit this issue to obtain potentially sensitive d=
etails about deployed web contexts. Information obtained may lead to furt=
her attacks.=20

The issue affects versions prior to JBoss Enterprise Application Platform=
 4.3.0.CP01 and 4.2.0.CP03.

13. Linux Kernel 'snd_seq_oss_synth_make_info()' Information Disclosure V=
ulnerability
BugTraq ID: 30559
Remote: No
Date Published: 2008-08-06
Relevant URL: http://www.securityfocus.com/bid/30559
Summary:
The Linux kernel is prone to an information-disclosure vulnerability.

Successful exploits will allow attackers to obtain sensitive information =
that may aid in further attacks.

Versions prior to Linux kernel 2.6.27-rc2 are vulnerable.

14. DD-WRT Site Survey SSID Script Injection Vulnerability
BugTraq ID: 30573
Remote: Yes
Date Published: 2008-08-06
Relevant URL: http://www.securityfocus.com/bid/30573
Summary:
DD-WRT is prone to a script-injection vulnerability because it fails to a=
dequately sanitize user-supplied data to the 'Site Survey' section of the=
 administrative web interface.

Attackers can exploit this issue to execute arbitrary script code in the =
DD-WRT web interface.

Versions prior to DD-WRT 24-sp1 are vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. root shell auditing
http://www.securityfocus.com/archive/91/494849

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Sponsored by IBM=AE Rational=AE AppScan
Copy: Failure to properly secure Web applications significantly impacts y=
our ability to protect sensitive client and corporate data. IBM Rational =
AppScan is an automated scanner that monitors, identifies and helps remed=
iate vulnerabilities.=20
Download a free trial of AppScan and see how it can help prevent against =
the threat of attack.
https://www.watchfire.com/securearea/appscan.aspx?id=3D701700000009T0r