★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-3247.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 6/29/2001 0:19

Linux Advisory Watch - June 29th 2001

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
6/29/2001

This week, advisories were released for apache, fetchmail, gnupg, samba, webmin, kdesu, iptables, XFree86, rxvt, exim, and ispell.  The vendors include Caldera, Conectiva, Debian, EnGarde, Immunix, Mandrake, Red Hat, and Progeny.  The samba vulnerability is present on many distributions.  Administrators should update their samba packages immediately.
 
 
Package Vendor
apache EnGarde
fetchmail EnGarde, Caldera
gnupg Caldera
samba Red Hat, Debian, Trustix, Immunix, Conectiva
webmin Mandrake
kdesu Mandrake
iptables Red Hat
XFree86 Red Hat
rxvt Immunix
exim Progeny
ispell Immunix

Jeff Fields of Newsforge writes, ""With minimal system access allowed and every precaution taken, Engarde Secure Linux just might be the best distribution for Web/mail servers yet."  http://www.newsforge.com/article.pl?sid=01/06/11/2356238&mode=thread

FREE Apache SSL Guide from Thawte Certification - Do your online customers demand the best available protection of their personal information? Thawte's guide explains how to give this to your customers by implementing SSL on your Apache Web Server. Click here to get our FREE Thawte Apache Guide.
http://www.thawte.com/ucgi/gothawte.cgi?a=n366607510022000

Linux Advisory Watch is a comprehensive newsletter that outlinesthe security vulnerabilities that have been announced throughout the week.It includes pointers to updated packages and descriptions of each vulnerability.



 

apache

There is a vulnerability in apache by which an attacker can get a directory listing even when an index file (such as index.html) is present. By sending apache a very long path containing slashes, an attacker can  trick mod_negotiation and mod_dir/mod_autoindex into displaying a  directory listing.  This was fixed in apache version 1.3.18 (which was  an internal release not made available to the public).  This updated  package will now return a 403 (FORBIDDEN) when such a request is made.

http://ftp.engardelinux.org/pub/engarde/stable/updates/
 
EnGarde Linux Packages:
i386/apache-1.3.20-1.0.25.i386.rpm
MD5 Sum:  084e9b7630af62f540e539e7a66af559

i686/apache-1.3.20-1.0.25.i686.rpm
MD5 Sum:  aab4dc51aca297660eee675a56fc506b

EnGarde Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1452.html

fetchmail-ssl

There is a buffer overflow vulnerability in the fetchmail-ssl package which could potentially be exploited remotely, although no exploit is known of at this time.

http://ftp.engardelinux.org/pub/engarde/stable/updates/
 
EnGarde Linux Packages:
i386/fetchmail-ssl-5.8.7-1.0.2.i386.rpm
MD5 Sum:  fc034811543e4aa5ad913bfa444f7e7f

i686/fetchmail-ssl-5.8.7-1.0.2.i686.rpm
MD5 Sum:  dcb18d42dd572432ddb60bd917e2418d

EnGarde Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1451.html


 

fetchmail

In previous versions of fetchmail, there were buffer overflows when handling mail messages with very long header fields.  This hole could theoretically be exploited remotely by sending messages with such headers.

Caldera 2.4: i386

ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS/
RPMS/fetchmail-5.2.0-2.i386.rpm
2d278844840df47146795ae11e638493
 
Caldera Vendor Advisory:
http://www.linuxsecurity.com/advisories/caldera_advisory-1453.html


 

gnupg

There is a format string problem in the printing of filenames of GnuPG. It is possible that a remote attacker creates a mailmessage that when opened with a mailprogram exploits the problem and allows the attacker to gain access to the users account.

Caldera 2.4: i386

ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS/
RPMS/gnupg-1.0.6-1.i386.rpm
f4931404eab64b6365b4abba69a42ef4

Caldera Vendor Advisory:
http://www.linuxsecurity.com/advisories/caldera_advisory-1464.html

samba

Since the NetBIOS name is limited to 15 characters and the `log file' command could have an extension to the filename the results
of this are limited. However if the attacker is also able to create symbolic links on the samba server he could trick samba into
appending any data he wants to all files on the filesystem which samba can write to.
 

Debian Architecture independent archives:
http://security.debian.org/dists/stable/updates/
main/binary-all/samba-doc_2.0.7-3.4_all.deb
MD5 checksum: 5e9e67fd0b0647945106ec4af85aec6e

Debian Vendor Advisory:
http://www.linuxsecurity.com/advisories/
debian_advisory-1455.html

Red Hat: i386

ftp://updates.redhat.com/7.1/en/os/i386/
samba-2.0.10-2.i386.rpm
988c5e7b554b659827897e52f8d13784

ftp://updates.redhat.com/7.1/en/os/i386/
samba-common-2.0.10-2.i386.rpm
9d5e0051d258f875236c3a317611f333

ftp://updates.redhat.com/7.1/en/os/i386
/samba-client-2.0.10-2.i386.rpm
5fe71e403bfd27da1de2325b734d28f8

ftp://updates.redhat.com/7.1/en/os/i386/
samba-swat-2.0.10-2.i386.rpm
dc667f249bd0c9024dcf751e513962f4

Red Hat Vendor Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1459.html
 

Trustix Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1463.html

Immunix Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1462.html

Conectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1458.html
 

webmin

Recently, Caldera found that when webmin starts a system daemon from the web frontend it does not clear its environment variables.  Since these variables contain the authorization of the administrator, any daemon would also get these variables.

http://www.linux-mandrake.com/en/ftp.php3

Mandrake Linux 8.0:
8.0/RPMS/webmin-0.84-7.1mdk.noarch.rpm
6034d9ba36ac1908842a2629f196cdff

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1447.html


 

kdesu

A problem exists with the kdesu component of kdelibs.  It created a world-readable temporary file to exchange authentication information and delete it shortly after.  This can be abused by a local user to gain access to the X server and could result in a compromise of the account that kdesu would access.

PLEASE SEE ADVISORY FOR UPDATE

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1466.html


 

FTP iptables

A vulnerability in iptables "RELATED" connection tracking has been discovered. When using iptables to allow FTP "RELATED" connections through the firewall, carefully constructed PORT commands can open arbitrary holes in the firewall. Default installations of Red Hat Linux 7.1 are not vulnerable; however upgrading to this kernel is recommended regardless in order to benefit from
the other bug fixes in this kernel.

PLEASE SEE RED HAT ADVISORY FOR UPDATE

Red Hat Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1456.html


 

XFree86

Since the initial release of XFree86 3.3.6, many bugs have been fixed in the XFree86 stable branch of CVS (xf-3_3-branch).  This includes several security updates, various driver and library bug fixes, and performance improvements.  In addition to the updated release from XFree86.org are several further enhancements included - such as updated S3 drivers, i810/815, and other improvements.

PLEASE SEE VENDOR ADVISORY FOR UPDATE

Red Hat Vendor Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1457.html

rxvt

Samuel "Zorgon" Dralet has discovered a buffer overflow in rxvt, a  terminal emulator for X11. This attack is stopped by tackGuard, so  any exploits can at best kill rxvt; no code can be executed as a  result of this vulnerability. This release checks the size of a buffer before writing data to it, preventing possible DoS attacks against  rxvt.

Immunix 6.2 are available at:
http://download.immunix.org/ImmunixOS/6.2/updates/
RPMS/rxvt-2.6.1-8_StackGuard_1.i386.rpm

Immunix Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1465.html

exim

The exim mail server contains a printf(3) vulnerability that could allow unauthorized local access if the headers_check_syntax option is turned on.

Progeny i386:
http://archive.progeny.com/progeny/updates/
newton/exim_3.16-4progeny2_i386.deb
d94b0457e884c6e22a6f5c1a6f46f1e2

Progeny Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1461.html


 

ispell

Jarno Huuskonen has found an unsafe use of mktemp(3) in ispell that would make ispell vulnerable to symlink attacks. This patch, from OpenBSD, fixes this problem as well as changing some uses of gets(3) to fgets(3), fixing possible buffer overflows.  The symlink attacks would grant an attacker the ability to overwrite files owned by the user executing ispell.

PLEASE SEE VENDOR ADVISORY FOR UPDATE

Immunix Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1454.html

FTC prepares to bust spammers
Feb 11

Scanning for Rootkits
Feb 11

Security Quick-Start HOWTO for Linux Updated
Feb 11

Operating system security stats hard to compare, but more Linux vulnerabilities being reported
Feb 11

Aide Host Intrusion Detection v0.8 Released
Feb 11

Linux Security Week - February 11th 2002
Feb 11

Running Your Firewall in runlevel 0
Feb 10

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000