SecurityFocus Linux Newsletter #430

[email protected] Wed, 11 Mar 2009 15:40:34 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #430
----------------------------------------

This issue is sponsored by Sophos

Laws, regulations and compliance: Top tips for keeping your data under yo=
ur control=20
=20
http://dinclinx.com/Redirect.aspx?36;4035;35;189;0;5;259;787c0986ab9c445a


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Contracting For Secure Code
       2. Free Market Filtering
II.  LINUX VULNERABILITY SUMMARY
       1. MPFR Library 'printf.c' Multiple Buffer Overflow Vulnerabilitie=
s
       2. Avahi 'avahi-core/server.c' Multicast DNS Denial Of Service Vul=
nerability
       3. Linux Kernel 'seccomp' System Call Security Bypass Vulnerabilit=
y
       4. Linux Kernel Audit System 'audit_syscall_entry()' System Call S=
ecurity Bypass Vulnerability
       5. NovaStor NovaNET 'DtbClsLogin()' Remote Stack Buffer Overflow V=
ulnerability
       6. cURL/libcURL HTTP 'Location:' Redirect Security Bypass Vulnerab=
ility
       7. libsndfile CAF Processing Buffer Overflow Vulnerability
       8. ZABBIX 'locales.php' Local File Include and Remote Code Executi=
on Vulnerability
       9. NetworkManager Permission Enforcement Multiple Local Vulnrabili=
ties
       10. Arno's IPTables Firewall Script Restart Security Bypass Vulner=
ability
       11. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 an=
d -11 Multiple Remote Vulnerabilities
       12. Linux-PAM Configuration File Non-ASCII User Name Handling Loca=
l Privilege Escalation Vulnerability
       13. IBM Director CIM Server Consumer Name Remote Denial of Service=
 Vulnerability
       14. Mahara Multiple Cross Site Scripting Vulnerabilities
       15. IBM Director CIM Server Privilege Escalation Vulnerability
       16. openSUSE Linux gtk2 Package Search Path Remote Command Executi=
on Vulnerability
       17. PostgreSQL Low Cost Function Information Disclosure Vulnerabil=
ity
       18. Asterisk Pedantic Mode SIP Channel Driver INVITE Header Remote=
 Denial of Service Vulnerability
       19. Sun xVM VirtualBox Local Privilege Escalation Vulnerability
       20. Linux Kernel '/proc/net/rt_cache' Remote Denial of Service Vul=
nerability
       21. Wesnoth Compressed Data Remote Denial of Service Vulnerability
       22. Mandriva perl-MDK-Common Unspecified Privilege Escalation Vuln=
erability
       23. PostgreSQL Conversion Encoding Remote Denial of Service Vulner=
ability
       24. DASH '.profile' Local Privilege Escalation Vulnerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Contracting For Secure Code
By Chris Wysopal
Forcing suppliers to attest to the security of provided software is gaini=
ng adherents: Just ask Kaspersky Lab.=20
http://www.securityfocus.com/columnists/494

2. Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. MPFR Library 'printf.c' Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 33945
Remote: Yes
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33945
Summary:
The MPFR library is prone to multiple buffer-overflow vulnerabilities bec=
ause it fails to properly bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.

An attacker can exploit these issues to execute arbitrary code in the con=
text of applications using the vulnerable library. Failed exploit attempt=
s will likely cause denial-of-service conditions.

Versions prior to MPFR 2.4.1 are vulnerable.

2. Avahi 'avahi-core/server.c' Multicast DNS Denial Of Service Vulnerabil=
ity
BugTraq ID: 33946
Remote: Yes
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33946
Summary:
Avahi is prone to a denial-of-service vulnerability.

A remote attacker may exploit this issue to crash the affected applicatio=
n, denying further service to legitimate users.

Avahi 0.6.23 is vulnerable; other versions may also be affected.

3. Linux Kernel 'seccomp' System Call Security Bypass Vulnerability
BugTraq ID: 33948
Remote: No
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33948
Summary:
The Linux kernel is prone to a local security-bypass vulnerability.

A local attacker may be able to exploit this issue to bypass access contr=
ol and make restricted system calls, which may result in an elevation of =
privileges.

4. Linux Kernel Audit System 'audit_syscall_entry()' System Call Security=
 Bypass Vulnerability
BugTraq ID: 33951
Remote: No
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33951
Summary:
The Linux kernel is prone to a local security-bypass vulnerability.

A local attacker may be able to exploit this issue to bypass audit mechan=
isms imposed on system calls. This may allow malicious behavior to escape=
 notice.

5. NovaStor NovaNET 'DtbClsLogin()' Remote Stack Buffer Overflow Vulnerab=
ility
BugTraq ID: 33954
Remote: Yes
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33954
Summary:
NovaStor NovaNET is prone to a stack-based buffer-overflow vulnerability =
because it fails to adequately bounds-check user-supplied data before cop=
ying it to an insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected application or cause a denial-of-service condition.

NovaNET 12 is vulnerable; other versions may also be affected.

6. cURL/libcURL HTTP 'Location:' Redirect Security Bypass Vulnerability
BugTraq ID: 33962
Remote: Yes
Date Published: 2009-03-03
Relevant URL: http://www.securityfocus.com/bid/33962
Summary:
cURL/libcURL is prone to a security-bypass vulnerability.=20

Remote attackers can exploit this issue to bypass certain security restri=
ctions and carry out various attacks.

This issue affects cURL/libcURL 5.11 through 7.19.3. Other versions may a=
lso be vulnerable.

7. libsndfile CAF Processing Buffer Overflow Vulnerability
BugTraq ID: 33963
Remote: Yes
Date Published: 2009-03-03
Relevant URL: http://www.securityfocus.com/bid/33963
Summary:
The 'libsndfile' library is prone to a heap-based buffer-overflow vulnera=
bility because it fails to perform adequate boundary checks on user-suppl=
ied data.

Attackers can exploit this issue to execute arbitrary code in the context=
 of an application using the library. This can compromise the affected ap=
plication and possibly the underlying computer. Failed attacks will likel=
y cause denial-of-service conditions.
=20
This issue affects libsndfile 1.0.18; previous versions may also be vulne=
rable.

8. ZABBIX 'locales.php' Local File Include and Remote Code Execution Vuln=
erability
BugTraq ID: 33965
Remote: Yes
Date Published: 2009-03-03
Relevant URL: http://www.securityfocus.com/bid/33965
Summary:
ZABBIX is prone to multiple local file-include vulnerabilities and a remo=
te code-execution vulnerability that occur in the front-end web interface=
.

Attackers can exploit these issues to execute arbitrary code within the c=
ontext of the webserver or obtain sensitive information. Other attacks ar=
e also possible.=20

ZABBIX 1.6.2 is vulnerable; prior versions may also be affected.

9. NetworkManager Permission Enforcement Multiple Local Vulnrabilities
BugTraq ID: 33966
Remote: No
Date Published: 2009-03-03
Relevant URL: http://www.securityfocus.com/bid/33966
Summary:
NetworkManager is prone to multiple local vulnerabilities because the sof=
tware fails to properly enforce permissions.=20

Local attackers can exploit these issue to perform dbus queries to view n=
etwork connection passwords and pre-shared keys and to modify or delete n=
etwork connections. Other attacks may also be possible.

10. Arno's IPTables Firewall Script Restart Security Bypass Vulnerability
BugTraq ID: 33981
Remote: Yes
Date Published: 2009-03-04
Relevant URL: http://www.securityfocus.com/bid/33981
Summary:
Arno's IPTables Firewall Script is prone to a security-bypass vulnerabili=
ty because it fails to properly restrict network traffic following a rest=
art of the application.

An attacker can exploit this issue to bypass intended security restrictio=
ns and send network packets to an affected computer.

Versions prior to Arno's IPTables Firewall Script 1.9.0b are vulnerable.

11. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 M=
ultiple Remote Vulnerabilities
BugTraq ID: 33990
Remote: Yes
Date Published: 2009-03-04
Relevant URL: http://www.securityfocus.com/bid/33990
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.

Attackers can exploit these issues to bypass same-origin restrictions, ob=
tain potentially sensitive information, and execute arbitrary script code=
 with elevated privileges; other attacks are also possible.

12. Linux-PAM Configuration File Non-ASCII User Name Handling Local Privi=
lege Escalation Vulnerability
BugTraq ID: 34010
Remote: No
Date Published: 2009-03-05
Relevant URL: http://www.securityfocus.com/bid/34010
Summary:
Linux-PAM is prone to a vulnerability related to the parsing of user name=
s containing non-ASCII characters from PAM configuration files. Specifica=
lly, this issue is caused by an error in the '_pam_StrTok()' function, wh=
ich may strip a single trailing non-ASCII character from user names befor=
e returning them as 'arg3'.

Note that root access is required to modify the affected configuration fi=
les.

A local attacker may exploit this issue to authenticate as additional use=
rs. The attacker may be able to create a denial-of-service condition or p=
ossibly to execute arbitrary code as the affected process, but this has n=
ot been confirmed.

Versions prior to Linux-PAM 1.0.4 are vulnerable.

13. IBM Director CIM Server Consumer Name Remote Denial of Service Vulner=
ability
BugTraq ID: 34061
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34061
Summary:
The CIM Server of IBM Director is prone to a remote denial-of-service vul=
nerability because the application fails to properly handle specially cra=
fted requests.

Successfully exploiting this issue allows remote attackers to trigger cra=
shes, which would deny further service to legitimate users.

This issue affects versions prior to IBM Director 5.20.3 Service Update 2=
.

14. Mahara Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 34064
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34064
Summary:
Mahara is prone to multiple cross site scripting vulnerabilities because =
the application fails to sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the=
 affected site, potentially allowing the attacker to steal cookie-based a=
uthentication credentials; other attacks are also possible.

Versions prior to Mahara 1.0.10 and 1.1.2 are vulnerable.

15. IBM Director CIM Server Privilege Escalation Vulnerability
BugTraq ID: 34065
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34065
Summary:
IBM Director is prone to a privilege-escalation vulnerability that affect=
s the CIM server.

Attackers can leverage this issue to execute arbitrary code with elevated=
 privileges in the context of the CIM server process.

Versions prior to IBM Director 5.20.3 Service Update 2 are affected.

16. openSUSE Linux gtk2 Package Search Path Remote Command Execution Vuln=
erability
BugTraq ID: 34068
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34068
Summary:
The openSUSE gtk2 package is prone to a remote command-execution vulnerab=
ility.

An attacker could exploit this issue by enticing an unsuspecting victim t=
o run a vulnerable application in a directory containing a malicious modu=
le file with a specific name. A successful exploit will allow arbitrary c=
ommands to run with the privileges of the currently logged-in user.

openSUSE 11.0 and 11.1 are vulnerable.

17. PostgreSQL Low Cost Function Information Disclosure Vulnerability
BugTraq ID: 34069
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34069
Summary:
PostgreSQL is prone to an information-disclosure vulnerability.=20

Local attackers can exploit this issue to gain access to sensitive inform=
ation. Information obtained may lead to further attacks.=20

PostgreSQL 8.3.6 is vulnerable; other versions may also be affected.

18. Asterisk Pedantic Mode SIP Channel Driver INVITE Header Remote Denial=
 of Service Vulnerability
BugTraq ID: 34070
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34070
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because it =
fails to adequately validate INVITE headers in pedantic mode.

Successful exploits can crash the SIP channel driver, resulting in denial=
-of-service conditions for legitimate users.

19. Sun xVM VirtualBox Local Privilege Escalation Vulnerability
BugTraq ID: 34080
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34080
Summary:
Sun xVM VirtualBox is prone to a local privilege-escalation vulnerability=
.

An attacker can exploit this vulnerability to run arbitrary code with sup=
eruser privileges.

The following versions for the Linux platform are vulnerable:

Sun xVM VirtualBox 2.0=20
Sun xVM VirtualBox 2.1

20. Linux Kernel '/proc/net/rt_cache' Remote Denial of Service Vulnerabil=
ity
BugTraq ID: 34084
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34084
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to properly flush the '/proc/net/rt_cache' file under some =
conditions.

Attackers can exploit this issue to cause the kernel to fail to respond t=
o network traffic, denying service to legitimate users.=20

Versions prior to Linux kernel 2.6.25 are vulnerable.

21. Wesnoth Compressed Data Remote Denial of Service Vulnerability
BugTraq ID: 34085
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34085
Summary:
Wesnoth is prone to a remote denial-of-service vulnerability.

Exploiting this issue may allow attackers to cause the application to cra=
sh, denying service to legitimate users.

22. Mandriva perl-MDK-Common Unspecified Privilege Escalation Vulnerabili=
ty
BugTraq ID: 34089
Remote: No
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34089
Summary:
Mandriva perl-MDK-Common is prone to an unspecified privilege-escalation =
vulnerability due to a failure to properly validate user supplied input.

An attacker may exploit this issue to gain elevated privileges.

23. PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
BugTraq ID: 34090
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34090
Summary:
PostgreSQL is prone to a remote denial-of-service vulnerability.

Exploiting this issue may allow attackers to terminate connections to the=
 PostgreSQL server, denying service to legitimate users.

24. DASH '.profile' Local Privilege Escalation Vulnerability
BugTraq ID: 34092
Remote: No
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34092
Summary:
DASH is prone to a local vulnerability that results in code execution wit=
h elevated privileges.

Successful exploits may allow attackers to execute arbitrary code within =
the context of the user running the affected application. This may allow =
local attackers to gain root-level privileges, resulting in a complete co=
mpromise of an affected computer.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Sophos

Laws, regulations and compliance: Top tips for keeping your data under yo=
ur control=20
=20
http://dinclinx.com/Redirect.aspx?36;4035;35;189;0;5;259;787c0986ab9c445a