SecurityFocus Linux Newsletter #417

[email protected] Thu, 4 Dec 2008 23:17:10 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #417
----------------------------------------

This issue is Sponsored by Verisign

Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Standing on Other's Shoulders
       2. Just Encase It's Not a Search
II.  LINUX VULNERABILITY SUMMARY
       1. 'tog-pegasus' Package for Red Hat Enterprise Linux Security Byp=
ass Vulnerability
       2. SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injec=
tion Vulnerability
       3. Samba Arbitrary Memory Contents Information Disclosure Vulnerab=
ility
       4. Linux Kernel 'sendmsg()' Local Denial of Service Vulnerability
       5. CUPS PNG Filter '_cupsImageReadPNG()' Integer Overflow Vulnerab=
ility
       6. ClamAV 'cli_check_jpeg_exploit' Function Malformed JPEG File Re=
mote Denial Of Service Vulnerability
       7. MailScanner Multiple Insecure Temporary File Creation Vulnerabi=
lities
       8. Sun Java Runtime Environment and Java Development Kit Multiple =
Security Vulnerabilities
       9. Sun Java Web Start and Java Plug-in Multiple Privilege Escalati=
on Vulnerabilities
       10. Ubuntu Privacy Remix S/ATA-Disks Security Bypass Vulnerability=
=20
       11. RSyslog '$AllowedSender' Configuration Directive Security Bypa=
ss Vulnerability
       12. Linux Kernel 'parisc_show_stack()' Local Denial of Service Vul=
nerability
III. LINUX FOCUS LIST SUMMARY
       1. CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008=
)
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486

2.Just Encase It's Not a Search
By Mark Rasch
When is a search not really a search? If it's done by computer, according=
 to U.S. government lawyers.=20
http://www.securityfocus.com/columnists/485


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. 'tog-pegasus' Package for Red Hat Enterprise Linux Security Bypass Vul=
nerability
BugTraq ID: 32460
Remote: No
Date Published: 2008-11-25
Relevant URL: http://www.securityfocus.com/bid/32460
Summary:
The 'tog-pegasus' package is prone to a security-bypass vulnerability.

Local attackers can exploit this issue to bypass certain security restric=
tions and send requests to WBEM services.

This issue occurs in the 'tog-pegasus' package built with Red Hat Enterpr=
ise Linux 5.

2. SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vu=
lnerability
BugTraq ID: 32464
Remote: No
Date Published: 2008-11-25
Relevant URL: http://www.securityfocus.com/bid/32464
Summary:
SuSE YaST2 Backup is prone to a local command-injection vulnerability bec=
ause it fails to adequately sanitize user-supplied input data.

Attackers can exploit this issue to execute arbitrary shell commands in t=
he context of the vulnerable application. This may facilitate the complet=
e compromise of affected computers.

3. Samba Arbitrary Memory Contents Information Disclosure Vulnerability
BugTraq ID: 32494
Remote: Yes
Date Published: 2008-11-27
Relevant URL: http://www.securityfocus.com/bid/32494
Summary:
Samba is prone to an information-disclosure vulnerability.

Successful exploits will allow attackers to obtain arbitrary memory conte=
nts.

This issue affects Samba 3.0.29 up to and including 3.2.4.

4. Linux Kernel 'sendmsg()' Local Denial of Service Vulnerability
BugTraq ID: 32516
Remote: No
Date Published: 2008-11-28
Relevant URL: http://www.securityfocus.com/bid/32516
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to create a soft lockup of the vulnerabl=
e kernel or to invoke the 'oom-killer' kernel functionality, which may ha=
lt unrelated processes. This may result in a denial-of-service condition.

NOTE: This issue was either caused or revealed by the fix for BID 32154 (=
Linux Kernel '__scm_destroy()' Local Denial of Service Vulnerability).

The Linux kernel 2.6.27 and prior versions are affected.

5. CUPS PNG Filter '_cupsImageReadPNG()' Integer Overflow Vulnerability
BugTraq ID: 32518
Remote: Yes
Date Published: 2008-11-28
Relevant URL: http://www.securityfocus.com/bid/32518
Summary:
CUPS is prone to an integer-overflow vulnerability because it fails to pe=
rform adequate boundary checks on user-supplied PNG image sizes before us=
ing them to allocate memory buffers.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of a user running the utilities. Failed exploit attempts lik=
ely cause denial-of-service conditions.

Versions prior to CUPS 1.3.10 are vulnerable.

6. ClamAV 'cli_check_jpeg_exploit' Function Malformed JPEG File Remote De=
nial Of Service Vulnerability
BugTraq ID: 32555
Remote: Yes
Date Published: 2008-12-01
Relevant URL: http://www.securityfocus.com/bid/32555
Summary:
ClamAV is prone to a denial-of-service vulnerability.

Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of this issue, attackers may also be able to run arbitrar=
y code, but this has not been confirmed.

Versions prior to ClamAV 0.94.2 are vulnerable.

7. MailScanner Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 32557
Remote: No
Date Published: 2008-12-01
Relevant URL: http://www.securityfocus.com/bid/32557
Summary:
Multiple MailScanner scripts create temporary files in an insecure manner=
.

An attacker with local access could perform symbolic-link attacks, overwr=
iting arbitrary files in the context of an affected application.=20

Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
 attacks may also be possible.

MailScanner 4.55.10 and 4.68.8 are vulnerable; other versions may also be=
 affected.

8. Sun Java Runtime Environment and Java Development Kit Multiple Securit=
y Vulnerabilities
BugTraq ID: 32608
Remote: Yes
Date Published: 2008-12-03
Relevant URL: http://www.securityfocus.com/bid/32608
Summary:
Sun Java Runtime Environment and Java Development Kit are prone to multip=
le security vulnerabilities.

Successful exploits may allow attackers to violate the same-origin policy=
, obtain sensitive information, bypass security restrictions, run untrust=
ed applets with elevated privileges, and cause denial-of-service conditio=
ns. This may result in a compromise of affected computers.

These issues affect versions prior to the following:

JDK and JRE 6 Update 11 or later
JDK and JRE 5.0 Update 17 or later
SDK and JRE 1.4.2_19 or later
SDK and JRE 1.3.1_24 or later

9. Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vuln=
erabilities
BugTraq ID: 32620
Remote: Yes
Date Published: 2008-12-03
Relevant URL: http://www.securityfocus.com/bid/32620
Summary:
Sun Java Web Start and Java Plug-in are prone to multiple privilege-escal=
ation vulnerabilities.

Successful exploits may allow attackers to violate the same-origin policy=
, obtain sensitive information, bypass security, or read, write, and exec=
ute arbitrary files in the context of the user running a vulnerable appli=
cation. This may result in a compromise of the underlying system.

This issue affects the following versions:

JDK and JRE 6 Update 10 and earlier
JDK and JRE 5.0 Update 16 and earlier
SDK and JRE 1.4.2_18 and earlier
SDK and JRE 1.3.1_23 and earlier

10. Ubuntu Privacy Remix S/ATA-Disks Security Bypass Vulnerability=20
BugTraq ID: 32629
Remote: No
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32629
Summary:
Ubuntu Privacy Remix (UPR) is prone to a security-bypass vulnerability th=
at may allow attackers to modify the operating system.

Attackers can exploit this issue to mount S-/ATA-Disks onto the affected =
computer. This will allow attackers to bypass the privacy mechanism used =
by the live-CD. Successfully exploiting this issue may compromise the pri=
vacy of users.

Versions prior to Ubutnu Privacy Remix 8.04 r1 are vulnerable.

11. RSyslog '$AllowedSender' Configuration Directive Security Bypass Vuln=
erability
BugTraq ID: 32630
Remote: Yes
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32630
Summary:
RSyslog is prone to a security-bypass vulnerability because of an error i=
n the daemon's ACL (Access Control List) handling.

Attackers can exploit this issue to bypass ACL restrictions that limit wh=
ich hosts may send messages to the daemon.  Successful exploits can resul=
t in misleading log entries or denial-of-service conditions.  Other attac=
ks may also be possible.

12. Linux Kernel 'parisc_show_stack()' Local Denial of Service Vulnerabil=
ity
BugTraq ID: 32636
Remote: No
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32636
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this issue to crash the affected computer, de=
nying service to legitimate users.=20

Versions prior to Linux kernel 2.6.28-rc7 are vulnerable.  Note that this=
 issue applies to PA-RISC 32-bit and 64-bit architectures.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008)
http://www.securityfocus.com/archive/91/498639

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by Verisign

Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v