SecurityFocus Linux Newsletter #148

Kelly Martin <[email protected]> Tue, 9 Sep 2003 10:16:54 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #148
------------------------------------
This Issue is Sponsored by: Astaro

FREE TRIAL - LinuxWorld Best Security Solution software
Astaro Security Linux is the pre-integrated software
security solution that costs less to implement and manage
- Firewall
- VPN
- Spam protection
- Virus protection and URL blocking options
Powers the solution that InfoWorld rated "Excellent,"
praising its ".performance, ease of use and price."
Download a free trial at:

http://www.securityfocus.com/sponsor/Astaro_linux-secnews_030908
------------------------------------------------------------------------


I. FRONT AND CENTER
     1. Intrusion Detection Terminology (Part One)
II. LINUX VULNERABILITY SUMMARY
     1. LinuxNode Remote Buffer Overflow Vulnerability
     2. Exim EHLO/HELO Remote Heap Corruption Vulnerability
     3. PADL Software PAM_LDAP PAM Filter Access Restriction Failure...
     4. Asterisk SIP Request Buffer Overrun Vulnerability
III. LINUX FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2003-09-01 to 2003-09-08.
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. Sophos Anti-Virus
     2. Zorp
     3. F-Secure Policy Manager
     4. Gordano Messaging Suite
     5. LANDesk Management Suite 7
     6. ActiveScout Enterprise
V. NEW TOOLS FOR LINUX PLATFORMS
     1. Sussen v0.6
     2. Devil-Linux v0.5
     3. BO2K  v1.1.1
     4. slidentd v1.0.0
     5. Arno's IPTABLES Firewall Script v1.8.1BETA-5
     6. beltane v2.0
VI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1. Intrusion Detection Terminology (Part One)
By Andy Cuff

This is the first of a two-part series that discusses IDS terminology,
including terms where there may be disagreement from within the security
community.

http://www.securityfocus.com/infocus/1728


II. LINUX VULNERABILITY SUMMARY
-------------------------------
1. LinuxNode Remote Buffer Overflow Vulnerability
BugTraq ID: 8512
Remote: Yes
Date Published: Aug 29 2003
Relevant URL: http://www.securityfocus.com/bid/8512
Summary:
LinuxNode is an amateur packet radio node program.

It has been reported that LinuxNode is prone to a remote buffer overflow
condition.  The issue presents itself due to insufficient bounds checking.
A remote attacker may ultimately exploit this issue remotely and execute
arbitrary code in the context of the user who is running the vulnerable
software.  Successful exploitation may allow a attacker to gain
unauthorized access to the vulnerable host.

Explicit technical details regarding this vulnerability are not currently
available. This BID will be updated, as further details regarding this
issue are made public.

Although LinuxNode 0.3.0 has been reported to be vulnerable to this
problem, other versions may be affected as well.

2. Exim EHLO/HELO Remote Heap Corruption Vulnerability
BugTraq ID: 8518
Remote: Yes
Date Published: Sep 01 2003
Relevant URL: http://www.securityfocus.com/bid/8518
Summary:
Exim is a message transfer agent (MTA) developed at the University of
Cambridge and available under the GNU Public License. It is available for
the Linux operating system.

A heap buffer overflow vulnerability has been discovered in Exim. The
problem is said to affect all Exim3 and Exim4 versions prior to Exim 4.21.
I

This issue occurs due to insufficient bounds checking performed when
handling user-supplied SMTP EHLO/HELO command data. The vulnerability
specifically occurs within the 'smtp_in.c' source file when handling
invalid EHLO/HELO arguments.  If EHLO/HELO arguments contain 506 leading
spaces followed by a NUL byte and a CRLF, a static string intended for a
syntax error message will be appended to the command argument data. The
interpolated string will now exceed the size of the reserved buffer in
heap-based memory. The entire string will be copied, without the spaces
being stripped, into the affected command buffer, this will result in heap
memory management structures adjacent to the affected buffer being
corrupted with superfluous data.

It has been reported that this vulnerability is unlikely to be exploitable
to execute arbitrary code. This is because a free() call is never made on
the attacker-controlled malloc chunk. Exploitation attempts will also be
hindered because the uncontrollable static string 'o argument given)\0' is
appended to attacker-supplied data, and will complicate the valid
corruption of the adjacent malloc header.

3. PADL Software PAM_LDAP PAM Filter Access Restriction Failure...
BugTraq ID: 8535
Remote: Yes
Date Published: Sep 03 2003
Relevant URL: http://www.securityfocus.com/bid/8535
Summary:
PAM_LDAP is the PAM module package designed to allow authentication with
LDAP servers via PAM-compliant authentication mechanisms.  It is available
for the Unix and Linux platforms.

A problem in the PAM filter portion of PAM_LDAP has been identified that
may fail to restrict access to certain systems.  This may allow
unauthorized access to network resources.

The problem is in the handling of values supplied to PAM filter.  When PAM
filter is used to restrict the ability of users logging in from
unauthorized hosts, PAM filter may fail to restrict access by the user.
This could result in a user gaining access to a system from an
unauthorized host.  This will also create a false sense of security, as
the PAM filter has been configured to restrict access and is not
performing as expected.

4. Asterisk SIP Request Buffer Overrun Vulnerability
BugTraq ID: 8546
Remote: Yes
Date Published: Sep 04 2003
Relevant URL: http://www.securityfocus.com/bid/8546
Summary:
Asterisk is a software-based PBX system, which is available for Linux
operating systems.  Asterisk includes support for the SIP (Session
Initiation Protocol).

Asterisk is prone to a remote exploitable buffer overrun.  This is due to
insufficient bounds checking of SIP MESSAGE and INFO requests.

In particular, due to a programming error in the chan_sip.c source file,
data supplied via either of these requests is used as a size argument for
a strncat() operation.  By passing 1024 bytes in the request body,
strncat() will be invoked with a negative number for the size argument,
causing memory to be corrupted.  A null is included in the affected page
of memory, limiting the amount of memory that is corrupted in the
operation and preventing a page fault, which will permit the saved return
address to be overwritten with attacker-supplied data.  As a result, it
will be possible to control execution flow of the program and execute
arbitrary code.

This issue may be exploited by an unauthenticated remote attacker to
execute arbitrary code in the context of the software.


III. LINUX FOCUS LIST SUMMARY
-----------------------------
NO NEW POSTS FOR THE WEEK 2003-09-01 to 2003-09-08.


IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. Sophos Anti-Virus
By: Sophos
Platforms: AIX, DOS, FreeBSD, HP-UX, Linux, MacOS, Netware, OS/2, Solaris,
UNIX, VMS, Windows 3.x, Windows 95/98, Windows NT
Relevant URL: http://www.sophos.com/products/sav/
Summary:

Sophos Anti-Virus is a unique solution to the virus problem, providing
true cross-platform protection in a single, fully integrated product. The
network-centric design provides a host of benefits for the protection of
servers, workstations and portables. Sophos's ground-breaking architecture
maximises protection, while minimising performance and administrative
overheads.

2. Zorp
By: Balabit IT Security Ltd.
Platforms: Linux
Relevant URL: http://www.balabit.com/products/zorp/
Summary:

Zorp is a proxy firewall suite making it possible to finetune proxy
decisions (with its built in script language), to fully analyze complex
protocols (like SSH with several forwarded TCP connections), to use
outband authentication techniques (unlike common practices where proxy
authentication had to be hacked into the protocol). Combined the power
explained above, source code is provided under the GNU/GPL.

3. F-Secure Policy Manager
By: F-Secure Corporation
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.f-secure.com/products/policy-man/index.shtml
Summary:

With F-Secure Policy Manager, your system administrator can manage all the
critical security applications from antivirus protection to file and
network encryption from one single console. The administrator can
automatically and remotely install, configure and update the applications.
It is possible to manage the security applications on almost any device
and across the enterprise so that even the security of mobile workers'
laptops is guaranteed. In addition to all this, the administrator can
easily monitor the network by generating extensive reports on the security
status of the network.

4. Gordano Messaging Suite
By: Gordano
Platforms: AIX, Linux, Solaris, Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.gordano.com/
Summary:

Gordano's Messaging Suite provides robust and secure email, instant and
SMS messaging for small, medium and large businesses.

5. LANDesk Management Suite 7
By: LANDesk Software
Platforms: AIX, HP-UX, Linux, MacOS, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Relevant URL: http://www.landesk.com/products/ilms/
Summary:

LANDesk Management Suite 7 is a comprehensive, integrated management
solution that's easy to use. Enabling proactive management of desktops,
server and mobile devices across heterogeneous IT environments.
 - Keep up with security patches and virus updates
 - Efficiently install and maintain software on the desktop
 - Decrease software license costs and respond to audits
 - Reduce the cost of helpdesk support
 - Discover and manage hardware and software assets
 - Migrate many users and their profiles to new operating systems

6. ActiveScout Enterprise
By: ForeScout Technologies
Platforms: Linux, Solaris, Windows 2000, Windows 95/98, Windows NT
Relevant URL: http://www.forescout.com/enterprise.html
Summary:

ActiveScout Enterprises actively protects a network with multiple access
points. In addition to the identification of attackers and automatic
action to stop them, this solution offers full management capabilities,
from configuration and reporting, to the sharing of threat information
between multiple deployed scouts.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. Sussen v0.6
By: lorenb420
Relevant URL: http://sussen.sourceforge.net/
Platforms: Linux, POSIX
Summary:

Sussen is a GNOME client for the Nessus Security Scanner. Sussen is
incredibly easy to use, allowing you to perform a vulnerabiltiy assessment
with just a few mouse clicks.

2. Devil-Linux v0.5
By: Heiko Zuerker <[email protected]>
Relevant URL: http://www.devil-linux.org/download.htm
Platforms: Linux
Summary:

Devil-Linux is a special Linux distribution which is used for
firewalls/routers. The goal of Devil-Linux is to have a small,
customizable, and secure Linux system. Configuration is saved on a floppy
disk, and it has several optional packages.

3. BO2K  v1.1.1
By: andrereis and j_aroche
Relevant URL: http://www.bo2k.com/
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT
Summary:

BO2K is a remote administration tool for Windows systems. It comes with a
client and a server. The server is lightweight and inobtrusive. A dynamic
plugin architechture allows for easy system extension.

4. slidentd v1.0.0
By: Sean Hunter
Relevant URL: http://www.uncarved.com/slidentd/
Platforms: Linux, POSIX
Summary:

slidentd is a minimal ident (RFC1413) daemon which runs from inetd,
xinetd, or tcpserver. It is similar in purpose to pidentd, which is
installed with most Linux systems. However its design goals are somewhat
different. It was written because the author wanted a very small, simple
daemon that would not give out any sensitive information (such as
usernames). In this regard it is not RFC compliant (RFC 1413 requires the
daemon to be insecure by default with secure settings as an option).

5. Arno's IPTABLES Firewall Script v1.8.1BETA-5
By: Arno
Relevant URL: http://rocky.molphys.leidenuniv.nl
Platforms: Linux, POSIX
Summary:

Arno's Iptables firewall is a script which was originally derived from
Seven's iptables script. One of the biggest differences is that this
script also has support for ADSL modems. It also features stealth scan
detection, extensive user-definable logging with rate limiting to prevent
log flooding, masquerading and port forwarding (NAT), optimizing the
throughput of your connection, protection against SYN/ICMP flooding, and
much more. It's easy to configure and highly customizable. It includes a
filter script (fwfilter) to make your firewall log more readable.

6. beltane v2.0
By: rainer
Relevant URL: http://www.la-samhna.de/beltane/
Platforms: Linux
Summary:

Beltane is a Web-based central management console for the samhain file
integrity system. If samhain is used in a client/server setup, beltane
enables the administrator to browse client reports, acknowledge them, and
update file signature databases stored centrally on the log server.


VI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: Astaro

FREE TRIAL - LinuxWorld Best Security Solution software
Astaro Security Linux is the pre-integrated software
security solution that costs less to implement and manage
- Firewall
- VPN
- Spam protection
- Virus protection and URL blocking options
Powers the solution that InfoWorld rated "Excellent,"
praising its ".performance, ease of use and price."
Download a free trial at:

http://www.securityfocus.com/sponsor/Astaro_linux-secnews_030908
------------------------------------------------------------------------