SecurityFocus Linux Newsletter #414

[email protected] 13 Nov 2008 20:56:15 -0000
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #414
----------------------------------------

This issue is sponsored by IronKey:

IronKey flash drives lock down your most sensitive data using today's mos=
t advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/secure-flash-drive1a


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Clicking to the Past
       2. The Vice of Vice Presidential E-Mail
II.  LINUX VULNERABILITY SUMMARY
       1. Adobe Reader 'util.printf()' JavaScript Function Stack Buffer O=
verflow Vulnerability
       2. htop Hidden Process Name Input Filtering Vulnerability
       3. Linux Kernel 'hfsplus_find_cat()' Local Denial of Service Vulne=
rability
       4. Linux Kernel 'hfsplus_block_allocate()' Local Denial of Service=
 Vulnerability
       5. Linux Kernel VDSO Unspecified Privilege Escalation Vulnerabilit=
y
       6. Adobe Acrobat and Reader 8.1.2 Multiple Security Vulnerabilitie=
s
       7. NOS Microsystems getPlus Download Manager ActiveX Control Buffe=
r Overflow Vulnerability
       8. libcdaudio 'cddb.c' Remote Heap Buffer Overflow Vulnerability
       9. Adobe Flash Player Multiple Security Vulnerabilities
       10. Linux Kernel '__scm_destroy()' Local Denial of Service Vulnera=
bility
       11. cluster Multiple Insecure Temporary File Creation Vulnerabilit=
ies
       12. MoinMoin Cross-Site Scripting and Information Disclosure Vulne=
rabilities
       13. GnuTLS X.509 Certificate Chain Security Bypass Vulnerability
       14. Yosemite Backup 'DtbClsLogin()' Remote Buffer Overflow Vulnera=
bility
       15. Trend Micro ServerProtect Multiple Remote Vulnerabilities
       16. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerab=
ilities
       17. Linux Kernel 'hfs_cat_find_brec()' Local Denial of Service Vul=
nerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Clicking to the Past
By Chris Wysopal
When the first details trickled out about a new attack, dubbed .clickjack=
ing. by the researchers who found it, the descriptions made me think of t=
he tricks I used to pull during penetration tests ten years ago to get ad=
ministrator privileges: Tricking the user into issuing a command on an at=
tacker.s behalf is one of the oldest attack vectors in the book.=20
http://www.securityfocus.com/columnists/483

2a .The Vice of Vice Presidential E-Mail
By Mark Rasch
Is it a crime to read someone else's e-mail without their consent? Seems =
like a simple question, but the law is not so clear. In mid-September 200=
8, a hacker using the handle "Rubico" claim credit for breaking into the =
Yahoo! e-mail account of Governor Sarah Palin, the Republican Vice Presid=
ential candidate. In a post online, Rubico wrote that he had been followi=
ng news reports that claimed Palin had been using her personal Yahoo e-ma=
il account for official government business.
In the early 90's, I attended an academic conference in Hawaii. At one pr=
esentation, a colleague from the University of California at Berkeley who=
m I'll refer to as "the supervisor," told a story of young hackers, who h=
e referred to as the Urchins
http://www.securityfocus.com/columnists/482


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Adobe Reader 'util.printf()' JavaScript Function Stack Buffer Overflow=
 Vulnerability
BugTraq ID: 30035
Remote: Yes
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/30035
Summary:
Adobe Reader is prone to a stack-based buffer-overflow vulnerability beca=
use the application fails to perform adequate boundary checks on user-sup=
plied data.=20

 An attacker can exploit this issue to execute arbitrary code with the pr=
ivileges of the user running the application or crash the application, de=
nying service to legitimate users.

2. htop Hidden Process Name Input Filtering Vulnerability
BugTraq ID: 32081
Remote: No
Date Published: 2008-11-03
Relevant URL: http://www.securityfocus.com/bid/32081
Summary:
The 'htop' program is prone to an input-filtering vulnerability that can =
result in hidden process names.

An attacker can exploit this issue to hide potentially malicious processe=
s, resulting in a false sense of security. This may also aid in launching=
 further attacks against the underlying shell.
=20
 This issue affects htop 0.7; other versions may also be affected.

3. Linux Kernel 'hfsplus_find_cat()' Local Denial of Service Vulnerabilit=
y
BugTraq ID: 32093
Remote: No
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/32093
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly bounds-check data before copying it to an insuff=
iciently sized memory buffer.

Attackers can exploit this issue to cause the kernel to crash, denying se=
rvice to legitimate users. Given the nature of this issue, attackers may =
also be able to run arbitrary code, but this has not been confirmed.

This issue affects versions prior to Linux kernel 2.6.28-rc1.

4. Linux Kernel 'hfsplus_block_allocate()' Local Denial of Service Vulner=
ability
BugTraq ID: 32096
Remote: No
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/32096
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly check return values before proceeding with furth=
er operations.

Attackers can exploit this issue to cause the kernel to crash, denying se=
rvice to legitimate users. Given the nature of this issue, attackers may =
also be able to execute arbitrary code, but this has not been confirmed.=20

This issue affects versions prior to Linux kernel 2.6.28-rc1.

5. Linux Kernel VDSO Unspecified Privilege Escalation Vulnerability
BugTraq ID: 32099
Remote: No
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/32099
Summary:
The Linux Kernel is prone to a local privilege-escalation vulnerability.

A local attacker may exploit this issue to gain elevated privileges or to=
 create a denial-of-service condition.

Versions prior to the Linux kernel 2.6.20-git5 are vulnerable.

6. Adobe Acrobat and Reader 8.1.2 Multiple Security Vulnerabilities
BugTraq ID: 32100
Remote: Yes
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/32100
Summary:
Adobe Acrobat and Reader are prone to multiple security vulnerabilities:

1. Multiple remote code-execution vulnerabilities.
2. A privilege-escalation vulnerability affecting computers running Unix-=
like operating systems.
3. An input-validation issue in a JavaScript method may lead to remote co=
de execution.

Attackers can exploit these issues to execute arbitrary code, elevate pri=
vileges, or cause a denial-of-service condition.

7. NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overf=
low Vulnerability
BugTraq ID: 32105
Remote: Yes
Date Published: 2008-11-04
Relevant URL: http://www.securityfocus.com/bid/32105
Summary:
NOS Microsystems getPlus Download Manager ActiveX control is prone to a b=
uffer-overflow vulnerability because the application fails to adequately =
check boundaries on user-supplied input.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application using the ActiveX control (typically Internet Explo=
rer).  Failed attacks will likely cause denial-of-service conditions.

The following applications use the getPlus Download Manager:
 =20
  Adobe Acrobat Professional
  Adobe Acrobat Reader
=20
 getPlus Download Manager 1.2.2.50 is vulnerable; other versions may also=
 be affected.

8. libcdaudio 'cddb.c' Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 32122
Remote: Yes
Date Published: 2008-11-05
Relevant URL: http://www.securityfocus.com/bid/32122
Summary:
The 'libcdaudio' library is prone to a remote heap buffer-overflow vulner=
ability because it fails to perform adequate boundary checks on user-supp=
lied input before copying it to an insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code in the context=
 of an application that uses the library. Failed attacks will cause denia=
l-of-service conditions.

 This issue affects libcdaudio 0.99.12p2; other versions may also be affe=
cted. Additional applications that use this library may also be vulnerabl=
e.

9. Adobe Flash Player Multiple Security Vulnerabilities
BugTraq ID: 32129
Remote: Yes
Date Published: 2008-11-06
Relevant URL: http://www.securityfocus.com/bid/32129
Summary:
Adobe Flash Player is prone to multiple security vulnerabilities.

Attackers can exploit these issues to obtain sensitive information, steal=
 cookie-based authentication credentials, control how webpages are render=
ed, or execute arbitrary script code in the context of the application.  =
Other attacks may also be possible.

These issues affect Flash Player 9.0.124.0 and prior versions.

10. Linux Kernel '__scm_destroy()' Local Denial of Service Vulnerability
BugTraq ID: 32154
Remote: No
Date Published: 2008-11-06
Relevant URL: http://www.securityfocus.com/bid/32154
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to cause the kernel to crash, denying se=
rvice to legitimate users.=20

The Linux kernel 2.6.26 and prior versions are affected.

11. cluster Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 32179
Remote: No
Date Published: 2008-11-07
Relevant URL: http://www.securityfocus.com/bid/32179
Summary:
Multiple components of the 'cluster' program may allow attackers to creat=
e temporary files in an insecure manner.

An attacker with local access could potentially exploit these issues to p=
erform symbolic-link attacks, overwriting arbitrary files in the context =
of the affected application.=20

Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
 attacks may also be possible.

These issues affect versions  prior to cluster 2.03.09.

12. MoinMoin Cross-Site Scripting and Information Disclosure Vulnerabilit=
ies
BugTraq ID: 32208
Remote: Yes
Date Published: 2008-11-09
Relevant URL: http://www.securityfocus.com/bid/32208
Summary:
MoinMoin is prone to cross-site scripting and information-disclosure vuln=
erabilities because it fails to properly sanitize user-supplied input.=20

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may allow the attacker to steal cookie-based authentication credent=
ials or other sensitive information and to launch other attacks.

MoinMoin 1.5.9 and 1.8.0 are vulnerable; other versions may also be affec=
ted.

13. GnuTLS X.509 Certificate Chain Security Bypass Vulnerability
BugTraq ID: 32232
Remote: Yes
Date Published: 2008-11-10
Relevant URL: http://www.securityfocus.com/bid/32232
Summary:
GnuTLS is prone to a security-bypass vulnerability because the applicatio=
n fails to properly validate chained X.509 certificates.

Successfully exploiting this issue allows attackers to perform  man-in-th=
e-middle attacks by impersonating trusted servers.  Unsuspecting users ma=
y feel a false sense of security which can aid attackers in launching fur=
ther attacks.

Versions prior to GnuTLS 2.6.1 are vulnerable.

14. Yosemite Backup 'DtbClsLogin()' Remote Buffer Overflow Vulnerability
BugTraq ID: 32246
Remote: Yes
Date Published: 2008-11-11
Relevant URL: http://www.securityfocus.com/bid/32246
Summary:
Yosemite Backup is prone to a buffer-overflow vulnerability because it fa=
ils to adequately bounds-check user-supplied data before copying it to an=
 insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected application or cause a denial-of-service condition.

NOTE: Reportedly successful exploits allow remote code execution on Linux=
 systems and denial of service on Windows systems.

Yosemite Backup 8.70 is vulnerable; other versions may also be affected.

15. Trend Micro ServerProtect Multiple Remote Vulnerabilities
BugTraq ID: 32261
Remote: Yes
Date Published: 2008-11-11
Relevant URL: http://www.securityfocus.com/bid/32261
Summary:
Trend Micro ServerProtect is prone to multiple remote vulnerabilities, in=
cluding an authentication bypass vulnerability and multiple heap-based bu=
ffer-overflow vulnerabilities.

Few technical details are currently available. We will update this BID as=
 more information emerges.

Successfully exploiting the buffer-overflow issues may allow the attacker=
 to execute arbitrary code with SYSTEM-level privileges or crash the affe=
cted application, denying service to legitimate users. Successfully explo=
iting the authentication-bypass vulnerability will allow the attacker adm=
inistrative access to the vulnerable application.
=20
  Trend Micro ServerProtect versions 5.58 and 5.7 are vulnerable; additio=
nal versions may also be affected.

16. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities
BugTraq ID: 32281
Remote: Yes
Date Published: 2008-11-13
Relevant URL: http://www.securityfocus.com/bid/32281
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Mozilla Firefox, Thunderbird and SeaMonkey.

Exploiting these issues can allow attackers to:

- steal authentication credentials
- obtain potentially sensitive information
- violate the same-origin policy
- execute scripts with elevated privileges
- cause denial-of-service conditions
- execute arbitrary code=20

Other attacks are also possible.

These issues are present in the following applications=20

- Mozilla Firefox 3.0.3 and prior=20
- Mozilla Firefox 2.0.0.17 and prior=20
- Mozilla Thunderbird:  2.0.0.17 and prior=20
- Mozilla SeaMonkey 1.1.13 and prior

17. Linux Kernel 'hfs_cat_find_brec()' Local Denial of Service Vulnerabil=
ity
BugTraq ID: 32289
Remote: No
Date Published: 2008-11-13
Relevant URL: http://www.securityfocus.com/bid/32289
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly bounds-check data before copying it to an insuff=
iciently sized memory buffer.

Attackers can exploit this issue to cause the kernel to crash, denying se=
rvice to legitimate users. Given the nature of this issue, attackers may =
also be able to run arbitrary code, but this has not been confirmed.

This issue affects versions prior to Linux kernel 2.6.27.6.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by IronKey:

IronKey flash drives lock down your most sensitive data using today's mos=
t advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/secure-flash-drive1a