SecurityFocus Linux Newsletter #421

[email protected] Wed, 7 Jan 2009 11:52:28 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #421
----------------------------------------

This issue is sponsored by the Computer Forensics Show

THE COMPUTER FORENSICS SHOW IS THE "DON'T MISS" EVENT OF THE YEAR FOR ALL=
 LITIGATION, ACCOUNTING AND IT PROFESSIONALS

April 27-29, 2009
Washington DC Convention Center
Washington, DC

August 3-5, 2009
San Jose Convention Center
San Jose, CA

www.computerforensicshow.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.MD5 Hack Interesting, But Not Threatening
       2.Time to Exclude Bad ISPs
II.  LINUX VULNERABILITY SUMMARY
       1. xterm DECRQSS Remote Command Execution Vulnerability
       2. Audio File Library (libaudiofile) 'msadpcm.c' WAV File Processi=
ng Buffer Overflow Vulnerability
       3. Retired: Linux Kernel Malformed 'msghdr' Structure Local Denial=
 of Service Vulnerability
       4. GForge 'GroupJoinRequest.class' SQL Injection Vulnerability
       5. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerabili=
ty
       6. Samba Registry Share Name Unauthorized Access Vulnerability
       7. Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution V=
ulnerability=20
       8. OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulne=
rability
III. LINUX FOCUS LIST SUMMARY
       1. CfP DIMVA 2009
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.MD5 Hack Interesting, But Not Threatening
By Tim Callan
A few days ago at the Chaos Communication Congress in Berlin, researchers=
 presented a paper in which they had used an MD5 collision attack and sub=
stantial computing firepower to create a false SSL certificate using the =
RapidSSL brand of SSL certificate. In the intervening time we have seen a=
 great deal of confusion and misinformation in the press and blogosphere =
about the specifics of this attack and what it means to the online ecosys=
tem.=20
http://www.securityfocus.com/columnists/488

2.Time to Exclude Bad ISPs
By Oliver Day
In recent months, three questionable Internet service providers - EstDoma=
ins, Atrivo, and McColo - were effectively taken offline resulting in not=
iceable drops of malware and spam.=20
http://www.securityfocus.com/columnists/487


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. xterm DECRQSS Remote Command Execution Vulnerability
BugTraq ID: 33060
Remote: Yes
Date Published: 2008-12-28
Relevant URL: http://www.securityfocus.com/bid/33060
Summary:
The 'xterm' program is prone to a remote command-execution vulnerability =
because it fails to sufficiently validate user input.

Successfully exploiting this issue would allow an attacker to execute arb=
itrary commands on an affected computer in the context of the affected ap=
plication.

The issue affects xterm with patch 237; other versions may also be affect=
ed.

2. Audio File Library (libaudiofile) 'msadpcm.c' WAV File Processing Buff=
er Overflow Vulnerability
BugTraq ID: 33066
Remote: Yes
Date Published: 2008-12-30
Relevant URL: http://www.securityfocus.com/bid/33066
Summary:
Audio File Library ('libaudiofile') is prone to a heap-based buffer-overf=
low vulnerability because it fails to properly bounds-check user-supplied=
 data.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of applications using the vulnerable library. Failed exploit a=
ttempts will likely cause denial-of-service conditions.

This issue affects libaudiofile 0.2.6; other versions may also be vulnera=
ble.

3. Retired: Linux Kernel Malformed 'msghdr' Structure Local Denial of Ser=
vice Vulnerability
BugTraq ID: 33079
Remote: No
Date Published: 2009-01-01
Relevant URL: http://www.securityfocus.com/bid/33079
Summary:
The Linux Kernel is prone to a local denial-of-service vulnerability.

A local attacker can exploit this issue to crash the affected computer, d=
enying service to legitimate users.

This BID is being retired as a duplicate of the vulnerability covered in =
BID 32154 (Linux Kernel '__scm_destroy()' Local Denial of Service Vulnera=
bility).

4. GForge 'GroupJoinRequest.class' SQL Injection Vulnerability
BugTraq ID: 33086
Remote: Yes
Date Published: 2009-01-02
Relevant URL: http://www.securityfocus.com/bid/33086
Summary:
GForge is prone to an SQL-injection vulnerability because it fails to suf=
ficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

GForge 4.5 and 4.6 are vulnerable; other versions may also be affected.

5. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
BugTraq ID: 33113
Remote: Yes
Date Published: 2009-01-05
Relevant URL: http://www.securityfocus.com/bid/33113
Summary:
The Linux Kernel is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

The issue affects Linux Kernel 2.6.28; other versions may also be vulnera=
ble.

6. Samba Registry Share Name Unauthorized Access Vulnerability
BugTraq ID: 33118
Remote: Yes
Date Published: 2009-01-05
Relevant URL: http://www.securityfocus.com/bid/33118
Summary:
Samba is prone to an unauthorized-access vulnerability that occurs when r=
egistry shares are enabled.=20

An attacker who has authenticated access to the affected application can =
exploit this issue to gain access to the root filesystem.

7. Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerab=
ility=20
BugTraq ID: 33137
Remote: Yes
Date Published: 2009-01-06
Relevant URL: http://www.securityfocus.com/bid/33137
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability because=
 the browser fails to properly validate the 'mime-type' of files before c=
alling the 'xdg-open' utility, as defined in '/etc/mailcap'.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected browser.=20

This issue affects Firefox running on Slackware Linux 12.2. Other version=
s may also be vulnerable.

8. OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerabilit=
y
BugTraq ID: 33150
Remote: Yes
Date Published: 2009-01-07
Relevant URL: http://www.securityfocus.com/bid/33150
Summary:
OpenSSL is prone to a signature-verification vulnerability.

An attacker would likely leverage this issue by first carrying out a man-=
in-the-middle attack. They are most likely to exploit this issue to condu=
ct phishing attacks or to impersonate legitimate sites. Other attacks are=
 likely possible.
=20
 OpenSSL releases prior to 0.9.8j are affected.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. CfP DIMVA 2009
http://www.securityfocus.com/archive/91/499756

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by the Computer Forensics Show

THE COMPUTER FORENSICS SHOW IS THE "DON'T MISS" EVENT OF THE YEAR FOR ALL=
 LITIGATION, ACCOUNTING AND IT PROFESSIONALS

April 27-29, 2009
Washington DC Convention Center
Washington, DC

August 3-5, 2009
San Jose Convention Center
San Jose, CA

www.computerforensicshow.com