SecurityFocus Linux Newsletter #422

[email protected] Thu, 15 Jan 2009 10:21:47 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #422
----------------------------------------

This issue is sponsored by the Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.The Drew Verdict Makes Us All Hackers
       2.MD5 Hack Interesting, But Not Threatening
II.  LINUX VULNERABILITY SUMMARY
       1. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerabili=
ty
       2. Samba Registry Share Name Unauthorized Access Vulnerability
       3. Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution V=
ulnerability=20
       4. OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulne=
rability
       5. Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verific=
ation Vulnerability
       6. Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalatio=
n Vulnerability
       7. Git gitweb Unspecified Remote Command Execution Vulnerability
       8. libmikmod Multiple Sound Channel Media Playback Remote Denial o=
f Service Vulnerability
       9. Linux Kernel 'locks_remove_flock()' Local Race Condition Vulner=
ability
       10. libmikmod '.XM' File Remote Denial of Service Vulnerability
       11. HP Linux Imaging and Printing System 'hplip.postinst' Local Pr=
ivilege Escalation Vulnerability
       12. Sun Java System Access Manager Information Disclosure Vulnerab=
ility
       13. Sun Java System Access Manager 'sub-realm' Privilege Escalatio=
n Vulnerability
       14. Linux Kernel 64 Bit ABI System Call Parameter Privilege Escala=
tion Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. CfP DIMVA 2009
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.The Drew Verdict Makes Us All Hackers
Mark Rasch
Last month, Lori Drew - the middle-aged Missouri mother who participated =
in a plan to deceive a 13-year-old girl that ultimately led to the girl's=
 suicide - was convicted by a Los Angeles federal jury of several misdeme=
anor counts of unauthorized access to MySpace's computers.
http://www.securityfocus.com/columnists/489

2.MD5 Hack Interesting, But Not Threatening
By Tim Callan
A few days ago at the Chaos Communication Congress in Berlin, researchers=
 presented a paper in which they had used an MD5 collision attack and sub=
stantial computing firepower to create a false SSL certificate using the =
RapidSSL brand of SSL certificate. In the intervening time we have seen a=
 great deal of confusion and misinformation in the press and blogosphere =
about the specifics of this attack and what it means to the online ecosys=
tem.=20
http://www.securityfocus.com/columnists/488


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
BugTraq ID: 33113
Remote: Yes
Date Published: 2009-01-05
Relevant URL: http://www.securityfocus.com/bid/33113
Summary:
The Linux Kernel is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

The issue affects Linux Kernel 2.6.28; other versions may also be vulnera=
ble.

2. Samba Registry Share Name Unauthorized Access Vulnerability
BugTraq ID: 33118
Remote: Yes
Date Published: 2009-01-05
Relevant URL: http://www.securityfocus.com/bid/33118
Summary:
Samba is prone to an unauthorized-access vulnerability that occurs when r=
egistry shares are enabled.=20

An attacker who has authenticated access to the affected application can =
exploit this issue to gain access to the root filesystem.

3. Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerab=
ility=20
BugTraq ID: 33137
Remote: Yes
Date Published: 2009-01-06
Relevant URL: http://www.securityfocus.com/bid/33137
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability because=
 the browser fails to properly validate the 'mime-type' of files before c=
alling the 'xdg-open' utility, as defined in '/etc/mailcap'.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected browser.=20

This issue affects Firefox running on Slackware Linux 12.2. Other version=
s may also be vulnerable.

UPDATE (January 8, 2009): The exact fault for this issue is currently unc=
lear. This could be a configuration problem in Slackware Linux, a failure=
 to sanitize input in Firefox, or a problem in 'xdg-open'. We will update=
 this BID pending further investigation.

4. OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerabilit=
y
BugTraq ID: 33150
Remote: Yes
Date Published: 2009-01-07
Relevant URL: http://www.securityfocus.com/bid/33150
Summary:
OpenSSL is prone to a signature-verification vulnerability.

An attacker would likely leverage this issue by first carrying out a man-=
in-the-middle attack. The attacker would most likely exploit this issue t=
o conduct phishing attacks or to impersonate legitimate sites. Other atta=
cks are likely possible.
=20
 Releases prior to OpenSSL 0.9.8j are affected.

5. Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verification V=
ulnerability
BugTraq ID: 33151
Remote: Yes
Date Published: 2009-01-07
Relevant URL: http://www.securityfocus.com/bid/33151
Summary:
Multiple vendors' products using OpenSSL are prone to a signature-verific=
ation vulnerability.

An attacker would likely leverage this issue by first carrying out a man-=
in-the-middle attack. The attacker would most likely exploit this issue t=
o conduct phishing attacks or to impersonate legitimate sites. Other atta=
cks are likely possible.

6. Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulne=
rability
BugTraq ID: 33211
Remote: No
Date Published: 2009-01-12
Relevant URL: http://www.securityfocus.com/bid/33211
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to execute arbitrary code with su=
peruser privileges. A successful exploit will result in the complete comp=
romise of affected computers. Failed exploit attempts will result in a de=
nial-of-service condition.
=20
 Versions prior to Linux kernel 2.6.24.1 are vulnerable.

7. Git gitweb Unspecified Remote Command Execution Vulnerability
BugTraq ID: 33215
Remote: Yes
Date Published: 2009-01-12
Relevant URL: http://www.securityfocus.com/bid/33215
Summary:
Git gitweb is prone to a remote command-execution vulnerability.

An attacker may exploit this issue to execute arbitrary commands within t=
he context of the affected application; this may aid in further attacks.

Git 1.5.2.4 and 1.5.6.6 are vulnerable to this issue; other versions may =
also be affected

8. libmikmod Multiple Sound Channel Media Playback Remote Denial of Servi=
ce Vulnerability
BugTraq ID: 33235
Remote: Yes
Date Published: 2009-01-13
Relevant URL: http://www.securityfocus.com/bid/33235
Summary:
The 'libmikmod' library is prone to a remote denial-of-service vulnerabil=
ity because the software fails to perform adequate boundary checks on use=
r-supplied input.

Attackers can exploit this issue by enticing an unsuspecting victim to op=
en multiple specially crafted media files.

Successfully exploiting this issue will cause an affected application to =
crash, denying service to legitimate users. Attackers may also be able to=
 run arbitrary code, but this has not been confirmed.

This issue affects libmikmod 3.1.9 through 3.2.0; other versions or appli=
cations that use the library may also be affected.

9. Linux Kernel 'locks_remove_flock()' Local Race Condition Vulnerability
BugTraq ID: 33237
Remote: No
Date Published: 2009-01-13
Relevant URL: http://www.securityfocus.com/bid/33237
Summary:
The Linux kernel is prone to a local race-condition vulnerability because=
 it fails to properly handle POSIX locks.

A local attacker may exploit this issue to crash the computer or gain ele=
vated privileges.

10. libmikmod '.XM' File Remote Denial of Service Vulnerability
BugTraq ID: 33240
Remote: Yes
Date Published: 2009-01-13
Relevant URL: http://www.securityfocus.com/bid/33240
Summary:
The 'libmikmod' library is prone to a remote denial-of-service vulnerabil=
ity because it fails to perform adequate boundary checks on user-supplied=
 input.=20

Attackers can exploit this issue by enticing an unsuspecting victim to op=
en a specially crafted '.XM' file.

Successfully exploiting this issue will cause an affected application to =
crash, denying service to legitimate users. Attackers may also be able to=
 run arbitrary code, but this has not been confirmed.

This issue affects libmikmod 3.1.9 through 3.2.0; other versions or appli=
cations that use the library may also be affected.

11. HP Linux Imaging and Printing System 'hplip.postinst' Local Privilege=
 Escalation Vulnerability
BugTraq ID: 33249
Remote: No
Date Published: 2009-01-13
Relevant URL: http://www.securityfocus.com/bid/33249
Summary:
HP Linux Image and Printing System (HPLIP) is prone to a local privilege-=
escalation vulnerability because an installation script changes ownership=
 and permission on certain files in users' home directories.

Local attackers can exploit this issue to gain elevated privileges on the=
 affected computer.  Successful exploits may completely compromise the co=
mputer.

12. Sun Java System Access Manager Information Disclosure Vulnerability
BugTraq ID: 33265
Remote: Yes
Date Published: 2009-01-14
Relevant URL: http://www.securityfocus.com/bid/33265
Summary:
Sun Java System Access Manager is prone to a remote information-disclosur=
e vulnerability.

Attackers can exploit this issue to obtain potentially sensitive informat=
ion that may aid in further attacks.

13. Sun Java System Access Manager 'sub-realm' Privilege Escalation Vulne=
rability
BugTraq ID: 33266
Remote: Yes
Date Published: 2009-01-14
Relevant URL: http://www.securityfocus.com/bid/33266
Summary:
Sun Java System Access Manager is prone to a privilege-escalation vulnera=
bility.=20

Attackers can exploit this issue to elevate their privileges. Successfull=
y exploiting this issue may result in the complete compromise of affected=
 applications.

14. Linux Kernel 64 Bit ABI System Call Parameter Privilege Escalation Vu=
lnerability
BugTraq ID: 33275
Remote: No
Date Published: 2009-01-14
Relevant URL: http://www.securityfocus.com/bid/33275
Summary:
The Linux Kernel is prone to a local privilege-escalation vulnerability.

A local attacker may be able to exploit this issue to read or write to un=
intended address spaces. This may result in denial-of-service conditions,=
 the disclosure of sensitive information, or privilege escalation.

This issue affects Linux 2.6 on some 64-bit architectures, including s390=
, PowerPC, SPARC64, and MIPS. Additional architectures may also be affect=
ed.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. CfP DIMVA 2009
http://www.securityfocus.com/archive/91/499756

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by the Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.