SecurityFocus Linux Newsletter #147

John Boletta <[email protected]> Tue, 2 Sep 2003 13:17:52 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #147
------------------------------------

This Issue is Sponsored by BlackHat

Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
technical IT security event.  Modeled after the famous Black Hat event in
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
Symantec is the Diamond sponsor.  Early-bird registration ends September
6.

http://www.securityfocus.com/sponsor/BlackHat_linux-secnews_030825
------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Pocket-Sized Wireless Detection
     2. Securing MySQL: step-by-step
II. LINUX VULNERABILITY SUMMARY
     1. Real Networks Helix Universal Server Remote Buffer Overflow ...
     2. Glibc Getgrouplist Function Buffer Overrun Vulnerability
     3. Glibc Malloc Routine Race Condition Vulnerability
     4. Red Hat Linux IPTables Firewall Failure Vulnerability
     5. Whois Client Command Line Buffer Overrun Vulnerability
     6. Sendmail DNS Maps Remote Denial of Service Vulnerability
     7. newsPHP Remote File Include Vulnerability
     8. newsPHP Authentication Bypass Vulnerability
     9. Pam_SMB Remote Buffer Overflow Vulnerability
     10. SLRN XRef Buffer Overflow Vulnerabilty
     11. DocView File Disclosure Vulnerability
     12. Attila PHP SQL Injection Unauthorized Privileged Access Vuln...
     13. BProc Local Arbitrary File Deletion Vulnerability
     14. ISC INN Innfeed Config File Command Line Format String Vulne...
     15. LinuxNode Remote Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2003-08-26 to 2003-09-02.
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. Sophos Anti-Virus
     2. Zorp
     3. F-Secure Policy Manager
     4. Gordano Messaging Suite
     5. LANDesk Management Suite 7
     6. ActiveScout Enterprise
V. NEW TOOLS FOR LINUX PLATFORMS
     1. cryptoswap v0.0.3
     2. Email v2.1
     3. floppyfw v2.0.7
     4. PAM SMB v1.1.7
     5. pam_dotfile v0.7
     6. Openwall Linux kernel patch v2.4.22-ow1
VI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1. Pocket-Sized Wireless Detection
By Bob Rudis

This article provides a comparison of two tiny 802.11 detectors and
discusses how they would fit into your overall WiFi security framework.

http://www.securityfocus.com/infocus/1727

2. Securing MySQL: step-by-step
By Artur Maj

This article describes the basic steps which should be performed in order
to secure a MySQL database against both local and remote attacks.

http://www.securityfocus.com/infocus/1726


II. LINUX VULNERABILITY SUMMARY
-------------------------------
1. Real Networks Helix Universal Server Remote Buffer Overflow ...
BugTraq ID: 8476
Remote: Yes
Date Published: Aug 22 2003
Relevant URL: http://www.securityfocus.com/bid/8476
Summary:
Helix Universal Server is a multiple type media server distributed and
maintained by Real Networks. It is available for Unix, Linux, and
Microsoft Windows platforms.

Real Networks has announced that a vulnerability is present in Helix
Universal Server version 9 and prior that will allow for attackers to
remotely compromise servers.  The condition occurs when URLs containing an
excessive number of '../' sequences are sent to the Server's protocol
parsers.  A remote attacker may pass a malicious request that is
sufficient to overflow a 1024 byte buffer on the stack.  Ultimately the
attacker may influence execution flow into attacker controlled heap based
memory.  This will result in arbitrary attacker supplied instructions
being executed in the context of the affected Helix server.

The vulnerability is reportedly present in the "View Source" plug-in and
may be eliminated if the plug-in is disabled.  The plug-in is used for
reading and displaying file format header information of files accessible
on the server filesystem.  It also supports the "Content Browsing"
feature, which will not function if the plug-in is disabled.
Additionally, disabling the plug-in will not adversely affect on-demand or
live streaming delivery or the logging and authentication services of the
server.

It has been reported that exploitation of this issue is hindered somewhat
on SPARC systems or other systems that are word aligned.

Note:  The announcement by RealNetworks may be related to issues reported
earlier by Symantec (possibly BIDs 7020, 6454, 6458 or 6456).  This has
not been confirmed.  However, if this is indeed the case, this BID will be
retired.

2. Glibc Getgrouplist Function Buffer Overrun Vulnerability
BugTraq ID: 8477
Remote: Unknown
Date Published: Aug 23 2003
Relevant URL: http://www.securityfocus.com/bid/8477
Summary:
The GNU C library, glibc, contains standard C libraries called by various
applications.

The getgrouplist function in glibc does not perform adequate bounds
checking on data it retrieves, allowing a potential for the buffer to be
overrun.

When getgrouplist retrieves the group list for a user who is a member of
more groups than the group list can hold, the buffer is overrun.  This may
result in segmentation faults in user applications.

Consequences of this vulnerability are dependant on the application
calling the getgrouplist function.

3. Glibc Malloc Routine Race Condition Vulnerability
BugTraq ID: 8478
Remote: Unknown
Date Published: Aug 23 2003
Relevant URL: http://www.securityfocus.com/bid/8478
Summary:
The GNU C library, glibc, contains standard C libraries called by various
applications.

An unspecified race condition issue exists in the malloc function of
glibc.  This issue may result in memory corruption, possibly allowing
sensitive areas in memory to be overwritten.

Specific details of this issue are not currently known.  This record will
be updated when further information becomes available.

This issue was reported to only affect IA64 platforms.

4. Red Hat Linux IPTables Firewall Failure Vulnerability
BugTraq ID: 8481
Remote: No
Date Published: Aug 25 2003
Relevant URL: http://www.securityfocus.com/bid/8481
Summary:
iptables is a firewall infrastructure developed for the Linux kernel.

iptables on Red Hat Linux systems has been reported prone to a
vulnerability, which may prevent the iptables firewall from functioning
correctly.

The issue presents itself, due to recent Red Hat kernel updates. It has
been reported that a recent kernel update failed to update the iptables
utility thereby preventing iptables operations, for example owner match,
from functioning.

Ultimately this issue may prevent an iptables firewall from restarting
after a kernel-upgrade has been applied.

This issue may lead an administrator into a false sense of security, as
the administrator may believe that an effective firewall is running.

5. Whois Client Command Line Buffer Overrun Vulnerability
BugTraq ID: 8483
Remote: Yes
Date Published: Aug 22 2003
Relevant URL: http://www.securityfocus.com/bid/8483
Summary:
Whois is an enhanced whois client for Linux/Unix platforms.

Whois is prone to a buffer overrun vulnerability when handling command
line parameters of excessive length.  The cause of the issue is that
command line parameters are copied using an sprintf() operation without
sufficient bounds checking.  While the client is not setuid/setgid, it is
often invoked by external scripts.  This could present a security
vulnerability if the program is invoked with untrusted input.  In such a
case, successful exploitation would permit an attacker to execute
arbitrary code in the context of the program.

A typical scenario would be if a CGI script called the program with
parameters that could be controlled by a remote attacker.  This could
possibly the attacker to execute arbitrary code with the privileges of the
web server, which would be invoking the vulnerable program.

6. Sendmail DNS Maps Remote Denial of Service Vulnerability
BugTraq ID: 8485
Remote: Yes
Date Published: Aug 25 2003
Relevant URL: http://www.securityfocus.com/bid/8485
Summary:
A potential vulnerability has been discovered in Sendmail when
implementing the use of DNS Maps. This behavior can be enabled through the
sendmail.cf configuration file.

The problem lies in the sm_resolve.c source file, and is exclusive to
Sendmail 8.12.x releases, prior to 8.12.9 only. Specifically, it has been
discovered that the dns_parse_reply() function fails to initialize
RESOURCE_RECORD_T structures after allocation. These structures are used
in a chain, designed to keep track of varoius DNS data. Each structure
includes a 'rr_next' variable, which is a pointer to the next structure in
the list.

When an invalid DNS reply is received by Sendmail, i.e. one with a reply
size differing from the announced reply size, the dns_free_data() function
is called. This function is designed to free allocated chains of
RESOURCE_RECORD_T structures, and traverses the chain until a 'rr_next'
variable points to NULL. Due to the failure to initialize these
structures, the last structure in the chain will not contain a NULL
'rr_next' variable. As such, the dns_free_data() function may traverse
into random memory by referencing this garbage 'rr_next' pointer, which
could potentially result in the free() function being called on random
memory.

This could potentially allow for a denial of service condition, as an
attacker may trigger a situation under which invalid memory will be
dereferenced. Theoretically, if this garbage data were to be controlled by
an attacker at some point during execution, it may be possible to exploit
this issue to execute arbitrary code. This however has not been confirmed.

It should be noted that the default configuration of Sendmail is not
affected by this issue.

7. newsPHP Remote File Include Vulnerability
BugTraq ID: 8488
Remote: Yes
Date Published: Aug 25 2003
Relevant URL: http://www.securityfocus.com/bid/8488
Summary:
newsPHP is a web-based content management system. It is implemented in PHP
and is available for a variety of platforms including Microsoft Windows
and Linux variant operating systems.

newsPHP is reported to be prone to a vulnerability that may allow remoter
attackers to include files containing arbitrary code to be executed on a
host running the vulnerable software.  This issue is exploitable via the
LangFile variable of nphpd.php module.  It has been reported that the
LangFile variable is not set by default in newPHP and may be exploited by
influencing its path to point to a malicious file supplied by the
attacker.

This vulnerability may lead to execution of arbitrary code by an attacker
in the form of PHP commands in the context of the web server hosting the
vulnerable version of newsPHP.

newsPHP v216 is reported to be vulnerable to this issue, however other
versions may be affected as well.

8. newsPHP Authentication Bypass Vulnerability
BugTraq ID: 8489
Remote: Yes
Date Published: Aug 25 2003
Relevant URL: http://www.securityfocus.com/bid/8489
Summary:
newsPHP is a web-based content management system. It is implemented in PHP
and is available for a variety of platforms including Microsoft Windows
and Linux variant operating systems.

It has been reported that newsPHP contains an authentication bypass
vulnerability allowing an unauthenticated attacker to gain access to
sensitive data or perform unauthorized actions.  The issue occurs due to
the failure of newPHP to check authentication credentials of a remote
user.  An attacker may send a request to perform an action via a specially
crafted URI containing illegitimate authentication credentials in order to
gain access to sensitive data.

The issue is reported to exist in newPHP v216, however other versions may
be affected as well.

9. Pam_SMB Remote Buffer Overflow Vulnerability
BugTraq ID: 8491
Remote: Yes
Date Published: Aug 26 2003
Relevant URL: http://www.securityfocus.com/bid/8491
Summary:
pam_smb is a pluggable authentication module (PAM) that provides for
authentication of UNIX users to a Server Message Block (SMB) server.

pam_smb has been reported prone to a buffer overflow vulnerability. It has
been reported that systems using pam_smb to authenticate to a remotely
accessible service may be vulnerable to a condition that may allow a
remote attacker to supply and execute arbitrary code in the context of the
vulnerable module.

Specifically, insufficient bounds checking is carried out on user-supplied
passwords before being copied into internal memory space. As a result, an
attacker may be capable of overwriting sensitive locations in memory.

It has been reported that all versions of pam_smb prior to, and including
version 1.1.6 and 2.0.0-rc development versions are affected by this
vulnerability.

10. SLRN XRef Buffer Overflow Vulnerabilty
BugTraq ID: 8493
Remote: Yes
Date Published: Aug 26 2003
Relevant URL: http://www.securityfocus.com/bid/8493
Summary:
slrn is an open source, freely available newsreader. It is actively
maintained by the SLRN Development Team, distributed through Sourceforge,
and included with many distributions of Linux.

slrn has been reported prone to a remote buffer overflow condition.

The issue has been reported to present itself when handling malicious Xref
headers. It has been reported that, when handled, an Xref header value
sufficient to trigger this issue may overrun the bounds of a reserved
memory buffer, and corrupt adjacent memory within the slrn process.
Although unconfirmed, due to the nature of this vulnerability it has been
conjectured that a remote attacker may exploit this issue to influence the
execution flow of the affected slrn application. This could result in
arbitrary code execution in the context of the user running slrn.

This vulnerability has been reported to affect all versions of slrn prior
to slrn version 0.9.8.0.

11. DocView File Disclosure Vulnerability
BugTraq ID: 8498
Remote: Yes
Date Published: Aug 26 2003
Relevant URL: http://www.securityfocus.com/bid/8498
Summary:
docview is a proprietary package included with SCO OpenLinux and UnixWare,
and is licensed under the GPL. It is designed to allow viewing of man
pages via an HTTP interface.

docview has been reported prone to a remotely exploitable file disclosure
vulnerability. The issue has been reported to present itself due to an
Apache web server configuration issue. It has been reported that anonymous
remote attackers may exploit this condition, by invoking a malicious URL
request against the affected docview utility to disclose the contents of
publicly readable files. Due to the nature of this vulnerability it has
been conjectured that a remote attacker may also disclose contents of web
server readable files, this, however, has not been confirmed.

Information harvested in this manner may be used to aid in further attacks
that are launched against the target system.

12. Attila PHP SQL Injection Unauthorized Privileged Access Vuln...
BugTraq ID: 8502
Remote: Yes
Date Published: Aug 26 2003
Relevant URL: http://www.securityfocus.com/bid/8502
Summary:
Attila PHP is a PHP content management system designed for portal sites.
It is available for Unix, Linux, and Microsoft Windows platforms.

An SQL injection vulnerability has been reported in Attila PHP that could
allow an attacker to gain unauthorized privileged access to a target site.
The problem occurs due to Attila PHP failing to sufficiently enapsulate
the 'cook_id' variable within quotes. As a result, an attacker may
injection SQL commands within the variable, and influence the result of an
SQL query carried out by the program. This could ultimately allow an
attacker to be granted access to the site as an arbitrary user, possibly
an administrator.

Privileged access to a site implementing Attila PHP could allow an
attacker to reveal or modify sensitive information or potentially launch
other attacks. It should be noted that, although unconfirmed it may be
possible for an attacker to injection SQL commands into the query that
could aid in launching attacks against the underlying database.

This vulnerability is said to affect Attila PHP 3.0.

13. BProc Local Arbitrary File Deletion Vulnerability
BugTraq ID: 8509
Remote: No
Date Published: Aug 28 2003
Relevant URL: http://www.securityfocus.com/bid/8509
Summary:
BProc (Beowulf Distributed Process Space) is a set of kernel
modifications, utilities and library files that are designed to facilitate
the invocation and handling of processes on remote systems. BProc is
designed for use with the Linux kernel.

Bproc is prone to a vulnerability that could allow malicious local users
to delete arbitrary system files. The problem is said to be due to
incorrect permission checking when handling I/O redirection. As a result,
an attacker may be capable of gaining limited access to arbitrary system
files with elevated privileges. This issue could be exploited by an
attacker to delete arbitrary system files, potentially rendering the
system unusable.

The problem is believed to occur due to BProc failing to sufficiently
setup I/O prior to the execution of setuid programs from within another
program. This may make it possible for an attacker to access descriptors
used by the privileged program. This could possibly be accomplished by
creating a process under which file descriptors are shared with the
parent, and subsequently having the child invoke a setuid application.
This however, has not been confirmed.

It should be noted that the precise technical details regarding this issue
are currently unknown. As further information becomes available this BID
will be updated accordingly.

This vulnerability was reported for 3.2.5 however, earlier versions may
also be affected.

14. ISC INN Innfeed Config File Command Line Format String Vulne...
BugTraq ID: 8510
Remote: Yes
Date Published: Aug 28 2003
Relevant URL: http://www.securityfocus.com/bid/8510
Summary:
ISC INN (InterNetNews) is an NNTP implementation for Unix/Linux variants.

A format string vulnerability has been reported in ISC INN (InterNetNews).
The issue exists in the innfeed binary and may be triggered by including
format specifiers as an argument when specifying a config file via the -c
command line switch.  The innfeed program is a streaming NNTP feeder.

The source of the problem is that the program does not include format
specifiers when using logging functions, which will enable an attacker to
supply their own format specifiers.  This could be leveraged to overwrite
arbitrary locations in memory with attacker-supplied data, which will
allow for an attacker to control the execution flow of the program.

This vulnerability could be exploited by a user with a group ID of news to
execute arbitrary code in the context of the program, which may allow an
attacker to gain the user ID of news on some systems.  Further privilege
escalation may be possible if this issue is successfully exploited.

15. LinuxNode Remote Buffer Overflow Vulnerability
BugTraq ID: 8512
Remote: Yes
Date Published: Aug 29 2003
Relevant URL: http://www.securityfocus.com/bid/8512
Summary:
LinuxNode is an amateur packet radio node program.

It has been reported that LinuxNode is prone to a remote buffer overflow
condition.  The issue presents itself due to insufficient bounds checking.
A remote attacker may ultimately exploit this issue remotely and execute
arbitrary code in the context of the user who is running the vulnerable
software.  Successful exploitation may allow a attacker to gain
unauthorized access to the vulnerable host.

Explicit technical details regarding this vulnerability are not currently
available. This BID will be updated, as further details regarding this
issue are made public.

Although LinuxNode 0.3.0 has been reported to be vulnerable to this
problem, other versions may be affected as well.


III. LINUX FOCUS LIST SUMMARY
-----------------------------
NO NEW POSTS FOR THE WEEK 2003-08-26 to 2003-09-02.


IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. Sophos Anti-Virus
By: Sophos
Platforms: AIX, DOS, FreeBSD, HP-UX, Linux, MacOS, Netware, OS/2, Solaris,
UNIX, VMS, Windows 3.x, Windows 95/98, Windows NT
Relevant URL: http://www.sophos.com/products/sav/
Summary:

Sophos Anti-Virus is a unique solution to the virus problem, providing
true cross-platform protection in a single, fully integrated product. The
network-centric design provides a host of benefits for the protection of
servers, workstations and portables. Sophos's ground-breaking architecture
maximises protection, while minimising performance and administrative
overheads.

2. Zorp
By: Balabit IT Security Ltd.
Platforms: Linux
Relevant URL: http://www.balabit.com/products/zorp/
Summary:

Zorp is a proxy firewall suite making it possible to finetune proxy
decisions (with its built in script language), to fully analyze complex
protocols (like SSH with several forwarded TCP connections), to use
outband authentication techniques (unlike common practices where proxy
authentication had to be hacked into the protocol). Combined the power
explained above, source code is provided under the GNU/GPL.

3. F-Secure Policy Manager
By: F-Secure Corporation
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.f-secure.com/products/policy-man/index.shtml
Summary:

With F-Secure Policy Manager, your system administrator can manage all the
critical security applications from antivirus protection to file and
network encryption from one single console. The administrator can
automatically and remotely install, configure and update the applications.
It is possible to manage the security applications on almost any device
and across the enterprise so that even the security of mobile workers'
laptops is guaranteed. In addition to all this, the administrator can
easily monitor the network by generating extensive reports on the security
status of the network.

4. Gordano Messaging Suite
By: Gordano
Platforms: AIX, Linux, Solaris, Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.gordano.com/
Summary:

Gordano's Messaging Suite provides robust and secure email, instant and
SMS messaging for small, medium and large businesses.

5. LANDesk Management Suite 7
By: LANDesk Software
Platforms: AIX, HP-UX, Linux, MacOS, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Relevant URL: http://www.landesk.com/products/ilms/
Summary:

LANDesk Management Suite 7 is a comprehensive, integrated management
solution that's easy to use. Enabling proactive management of desktops,
server and mobile devices across heterogeneous IT environments.
 - Keep up with security patches and virus updates
 - Efficiently install and maintain software on the desktop
 - Decrease software license costs and respond to audits
 - Reduce the cost of helpdesk support
 - Discover and manage hardware and software assets
 - Migrate many users and their profiles to new operating systems

6. ActiveScout Enterprise
By: ForeScout Technologies
Platforms: Linux, Solaris, Windows 2000, Windows 95/98, Windows NT
Relevant URL: http://www.forescout.com/enterprise.html
Summary:

ActiveScout Enterprises actively protects a network with multiple access
points. In addition to the identification of attackers and automatic
action to stop them, this solution offers full management capabilities,
from configuration and reporting, to the sharing of threat information
between multiple deployed scouts.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. cryptoswap v0.0.3
By: W. Michael Petullo
Relevant URL: http://www.flyn.org/projects/cryptoswap/index.html
Platforms: Linux
Summary:

The cryptoswap package supports creating an encrypted swap partition when
a system boots. This may be necessary on systems that use encrypted
filesystems because plaintext secrets may be written to disk when memory
is swapped to disk. The project also includes the ability to build a Linux
initrd that supports booting with an encrypted root filesystem.

2. Email v2.1
By: Geekoid <[email protected]>
Relevant URL: http://email.cleancode.org
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, POSIX, Solaris, SunOS
Summary:

Email sends email to remote SMTP servers via the command line, which makes
it useful in cron jobs. It will send to any RFC standard remote ESMTP
server, and will allow you to encrypt, sign, and design your message on
the fly. It has the capability to use signature files with dynamic
options, address book functionality, and users can also attach pictures,
binary files, documents, or whatever they want. It is completely
compatible with GNUPG for encryption and signing, and is easy to configure
and use.

3. floppyfw v2.0.7
By: Thomas Lundquist, [email protected]
Relevant URL: http://www.zelow.no/floppyfw/
Platforms: Linux
Summary:

floppyfw is a router and simple firewall on one single floppy. It uses
Linux basic firewall capabilities and have a very simple packaging system.
It is perfect for masquerading and securing networks on ADSL and cable
lines using both static IP and DHCP. It has a simple installation, mostly
only needed to edit one file on the floppy.

4. PAM SMB v1.1.7
By: Dave Airlie
Relevant URL: http://www.csn.ul.ie/~airlied/pam_smb/
Platforms: Linux
Summary:

pam_smb is a module which allows Linux users to be authenticated from
Samba, NT or Windows 95/8 machines.

5. pam_dotfile v0.7
By: Mezcalero
Relevant URL:
http://www.stud.uni-hamburg.de/users/lennart/projects/pam_dotfile/
Platforms: Linux, UNIX
Summary:

pam_dotfile is a PAM module which allows users to have more than one
password for a single account, each for a different service. This is
desirable because many users have objections to using the same password
for (as an example) an IMAP4 mailbox and SSH access.

6. Openwall Linux kernel patch v2.4.22-ow1
By: Solar Designer <[email protected]>
Relevant URL: http://www.openwall.com/linux/
Platforms: Linux
Summary:

The Openwall Linux kernel patch is a collection of security "hardening"
features for the Linux kernel. In addition to the new features, some
versions of the patch contain various security fixes. The "hardening"
features of the patch, while not a complete method of protection, provide
an extra layer of security against the easier ways to exploit certain
classes of vulnerabilities and/or reduce the impact of those
vulnerabilities. The patch can also add a little bit more privacy to the
system by restricting access to parts of /proc so that users may not see
what others are doing.


VI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by BlackHat

Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
technical IT security event.  Modeled after the famous Black Hat event in
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
Symantec is the Diamond sponsor.  Early-bird registration ends September
6.

http://www.securityfocus.com/sponsor/BlackHat_linux-secnews_030825
------------------------------------------------------------------------