SecurityFocus Linux Newsletter #420

[email protected] Wed, 31 Dec 2008 11:53:08 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #420
----------------------------------------

This issue is sponsored by Purewire

NEW! White Paper:
"Hackers Announce Open Season on Web 2.0 Users and Browsers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's.
Download this white paper now to mitigate your online security risks.
http://www.purewire.com/lp/sec


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Time to Exclude Bad ISPs
       2.Standing on Other's Shoulders
II.  LINUX VULNERABILITY SUMMARY
       1. Qemu and KVM VNC Server Remote Denial of Service Vulnerability
       2. PHP 'mbstring' Extension Buffer Overflow Vulnerability
       3. Git gitweb 'diff.external' Local Privilege Escalation Vulnerabi=
lity
       4. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerabilit=
y
       5. Audio File Library (libaudiofile) 'msadpcm.c' WAV File Processi=
ng Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Time to Exclude Bad ISPs
By Oliver Day
In recent months, three questionable Internet service providers - EstDoma=
ins, Atrivo, and McColo - were effectively taken offline resulting in not=
iceable drops of malware and spam.=20
http://www.securityfocus.com/columnists/487

2. Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Qemu and KVM VNC Server Remote Denial of Service Vulnerability
BugTraq ID: 32910
Remote: Yes
Date Published: 2008-12-22
Relevant URL: http://www.securityfocus.com/bid/32910
Summary:
Qemu and KVM are prone to a remote denial-of-service vulnerability which =
affects the included VNC server.

Attackers can exploit this issue to create a denial-of-service condition.

The following are vulnerable to this issue:
=20
 Qemu 0.9.1 and prior.
 KVM-79 and prior.

2. PHP 'mbstring' Extension Buffer Overflow Vulnerability
BugTraq ID: 32948
Remote: Yes
Date Published: 2008-12-21
Relevant URL: http://www.securityfocus.com/bid/32948
Summary:
PHP is prone to a buffer-overflow vulnerability because it fails to perfo=
rm boundary checks before copying user-supplied data to insufficiently si=
zed memory buffers. The issue affects the 'mbstring' extension included i=
n the standard distribution.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected webserver. Failed exploit attempts will likely=
 crash the webserver, denying service to legitimate users.=20

PHP 4.3.0 up to and including 5.2.6 are vulnerable.

3. Git gitweb 'diff.external' Local Privilege Escalation Vulnerability
BugTraq ID: 32967
Remote: No
Date Published: 2008-12-22
Relevant URL: http://www.securityfocus.com/bid/32967
Summary:
Git gitweb is prone to a local privilege-escalation vulnerability.

A local attacker may exploit this issue to gain elevated privileges.

Versions prior to Git 1.5.4.7, 1.5.5.6, 1.5.6.6, and 1.6.0.6 are vulnerab=
le.

4. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerability
BugTraq ID: 32985
Remote: No
Date Published: 2008-12-23
Relevant URL: http://www.securityfocus.com/bid/32985
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this issue to cause a soft lockup, denying se=
rvice to legitimate users.

Versions prior to Linux kernel 2.6.25 are vulnerable.

5. Audio File Library (libaudiofile) 'msadpcm.c' WAV File Processing Buff=
er Overflow Vulnerability
BugTraq ID: 33066
Remote: Yes
Date Published: 2008-12-30
Relevant URL: http://www.securityfocus.com/bid/33066
Summary:
Audio File Library (libaudiofile) is prone to a heap-based buffer-overflo=
w vulnerability because it fails to properly bounds-check user-supplied d=
ata.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of applications using the vulnerable library. Failed exploit a=
ttempts will likely cause denial-of-service conditions.

This issue affects libaudiofile 0.2.6; other versions may also be vulnera=
ble.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Purewire

NEW! White Paper:
"Hackers Announce Open Season on Web 2.0 Users and Browsers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's.
Download this white paper now to mitigate your online security risks.
http://www.purewire.com/lp/sec