SecurityFocus Linux Newsletter #419

[email protected] Sat, 27 Dec 2008 13:03:17 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #419
----------------------------------------

This issue is sponsored by Purewire

NEW! White Paper:
"Hackers Announce Open Season on Web 2.0 Users and Browsers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's.
Download this white paper now to mitigate your online security risks.
http://www.purewire.com/lp/sec


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Time to Exclude Bad ISPs
       2.Standing on Other's Shoulders
II.  LINUX VULNERABILITY SUMMARY
       1. GpsDrive Multiple Insecure Temporary File Creation Vulnerabilit=
ies
       2. Adobe Flash Player Unspecified Remote Security Vulnerability
       3. libvirt Local Security Bypass Vulnerability
       4. Courier-Authlib Non-Latin Character Handling Postgres SQL Injec=
tion Vulnerability
       5. PHP 'mbstring' Extension Buffer Overflow Vulnerability
       6. Git gitweb 'diff.external' Local Privilege Escalation Vulnerabi=
lity
       7. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerabilit=
y
       8. Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Time to Exclude Bad ISPs
By Oliver Day
In recent months, three questionable Internet service providers - EstDoma=
ins, Atrivo, and McColo - were effectively taken offline resulting in not=
iceable drops of malware and spam.=20
http://www.securityfocus.com/columnists/487

2. Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. GpsDrive Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 32887
Remote: No
Date Published: 2008-12-17
Relevant URL: http://www.securityfocus.com/bid/32887
Summary:
GpsDrive create temporary files in an insecure manner.

An attacker with local access could perform symbolic-link attacks, overwr=
iting arbitrary files in the context of an affected application.=20

Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
 attacks may also be possible.

GpsDrive 2.10~pre4-6.dfsg-1 is vulnerable; other versions may also be aff=
ected.

2. Adobe Flash Player Unspecified Remote Security Vulnerability
BugTraq ID: 32896
Remote: Yes
Date Published: 2008-12-17
Relevant URL: http://www.securityfocus.com/bid/32896
Summary:
Adobe Flash Player is prone to an unspecified security vulnerability.
=20
 Remote attackers may exploit this vulnerability to compromise an affecte=
d computer.
=20
No further technical details are currently available. We will update this=
 BID as more information emerges.
=20
This issue affects Flash Player on Linux platforms.

Versions prior to Flash Player 10.0.15.3 and 9.0.152.0 are vulnerable.

3. libvirt Local Security Bypass Vulnerability
BugTraq ID: 32905
Remote: No
Date Published: 2008-12-18
Relevant URL: http://www.securityfocus.com/bid/32905
Summary:
libvirt is prone to a local security-bypass vulnerability.

Successful exploitation of this issue may give attackers access to privil=
eged operations.

This issue affects libvirt versions 0.3.2 through 0.5.1.

4. Courier-Authlib Non-Latin Character Handling Postgres SQL Injection Vu=
lnerability
BugTraq ID: 32926
Remote: Yes
Date Published: 2008-12-19
Relevant URL: http://www.securityfocus.com/bid/32926
Summary:
Courier-Authlib is prone to an SQL-injection vulnerability because it fai=
ls to sufficiently sanitize user-supplied data before using it in an SQL =
query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

Versions prior to Courier-Authlib 0.62.0 are vulnerable.

5. PHP 'mbstring' Extension Buffer Overflow Vulnerability
BugTraq ID: 32948
Remote: Yes
Date Published: 2008-12-21
Relevant URL: http://www.securityfocus.com/bid/32948
Summary:
PHP is prone to a buffer-overflow vulnerability because it fails to perfo=
rm boundary checks before copying user-supplied data to insufficiently si=
zed memory buffers. The issue affects the 'mbstring' extension included i=
n the standard distribution.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected webserver. Failed exploit attempts will likely=
 crash the webserver, denying service to legitimate users.=20

PHP versions 4.3.0 up to and including 5.2.6 are vulnerable.

6. Git gitweb 'diff.external' Local Privilege Escalation Vulnerability
BugTraq ID: 32967
Remote: No
Date Published: 2008-12-22
Relevant URL: http://www.securityfocus.com/bid/32967
Summary:
Git gitweb is prone to a local privilege-escalation vulnerability.

A local attacker may exploit this issue to gain elevated privileges.

Versions prior to Git 1.5.4.7, 1.5.5.6, 1.5.6.6 and 1.6.0.6 are vulnerabl=
e.

7. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerability
BugTraq ID: 32985
Remote: No
Date Published: 2008-12-23
Relevant URL: http://www.securityfocus.com/bid/32985
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this issue to cause a soft lockup, denying se=
rvice to legitimate users.

Versions prior to Linux kernel 2.6.25 are vulnerable.

8. Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
BugTraq ID: 33003
Remote: No
Date Published: 2008-12-17
Relevant URL: http://www.securityfocus.com/bid/33003
Summary:
The Linux kernel is prone to a buffer-underflow vulnerability because it =
fails to perform adequate boundary-checks on user-supplied data.=20

A local attacker can exploit this issue to execute arbitrary code with ke=
rnel-level privileges or crash the affected computer, denying service to =
legitimate users.=20

Versions prior to Linux kernel 2.6.28-rc1 are vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Purewire

NEW! White Paper:
"Hackers Announce Open Season on Web 2.0 Users and Browsers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's.
Download this white paper now to mitigate your online security risks.
http://www.purewire.com/lp/sec