★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-1564.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 9/15/2000 0:58

Linux Advisory Watch - September 15th, 2000

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
9/15/2000

This week, advisories were released for xpdf, xchat, screen, pam_smb, pine4, eject, listmanager, mailman, mod_php3, mgetty, horde, and glibc. The vendors include RedHat, Slackware, SuSE, FreeBSD, Mandrake, Conectiva, Debian, Caldera, and TurboLinux. It is critical that you update all vulnerable packages. Many of the advisories included warn of potential root compromises.

Recently, major problems in pam_smb were announced. Versions 1.1.5 and before contain a buffer overflow that can allow a remote root shell. Vulnerable versions of pam_smb can be used to authenticate attackers attempting to use services such as ssh, and telnet. If this package is installed, we advise that you remove/upgrade it immediately.

Our sponsor this week is OpenDoc Publishing. Their 480-page comprehensive security book, Securing and Optimizing Linux, takes a hands-on approach to installing, optimizing, configuring, and securing Red Hat Linux. Topics include sendmail 8.10.1, OpenSSL, ApacheSSL, OpenSSH and much more! Includes Red Hat 6.2 and Red Hat 6.2 PowerTools edition.

https://secure.linuxports.com/cart/security/

Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security advisories.


Advisories This Week:


September 14th, 2000 -- RedHat: Updated 'xpdf' packages available -- There is a security problem when using tmpnam() and fopen() in versions prior to 0.91. The problem is seen when a root user overwrites files where a symlink is created between the calls to tmpname() and fopen(). There is also a problem with URL-type links in PDF documents that contain quote characters which could also be used to execute arbitrary commands.

Updated Packages: ftp://updates.redhat.com/5.2/
Package Name: xpdf-0.91-1.5x

http://www.linuxsecurity.com/advisories/redhat_advisory-717.html
 
 

September 14th, 2000 -- Slackware: 'xchat' vulnerability -- An input validation bug was found to affect Slackware Linux 7.0, 7.1, and current. Users of Slackware 7.0, 7.1, and -current are urged to upgraded to the xchat.tgz package available in the Slackware -current branch.

Updated Packages: ftp://ftp.slackware.com/pub/slackware/slackware-current/slakware/gtk/
Package Name: xchat.tgz

http://www.linuxsecurity.com/advisories/slackware_advisory-718.html
 
 

September 14th, 2000 -- RedHat: 'screen' format string exploit -- Screen allows the user to overload the visual bell with a text message that can be set by the user. This text message is handled as a format string, instead of as a pure string, so maliciously written format strings are allowed to overwrite the stack. Since screen in Red Hat Linux 5.2 and earlier releases was setuid root, this security hole could be exploited to gain a root shell.

Updated Packages: ftp://updates.redhat.com/5.2/
Package Name: screen-3.7.4-4

http://www.linuxsecurity.com/advisories/redhat_advisory-719.html
 

September 13th, 2000 -- SuSE: 'pam_smb' vulnerability -- Versions 1.1.5 and before contain a buffer overflow that would allow a remote attacker to gain root access on the target host, provided that the target host has the module installed and configured.

Updated Packages: ftp://ftp.suse.com/pub/suse/i386/update
Package Name: pam_smb-1.1.6-0

http://www.linuxsecurity.com/advisories/suse_advisory-707.html
 

September 13th, 2000 -- FreeBSD: 'screen' vulnerability -- The screen port, versions 3.9.5 and before, contains a vulnerability mwhich allows local users to gain root privileges. This is accomplished by inserting string-formatting operators into configuration parameters, which may allow arbitrary code to be executed.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports
Package Name: screen-3.9.8.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-709.html
 

September 13th, 2000 -- FreeBSD: 'pine4' vulnerability -- The pine4 port, versions 4.21 and before, contained a bug which would cause the program to crash when processing a folder which contains an email message with a malformed X-Keywords header. The message itself could be deleted within pine if identified, but other operations such as closing the folder with the message still present would cause the program to crash with no apparent cause, discarding changes to the mailbox.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports
Package Name: pine-4.21.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-711.html
 
 

September 13th, 2000 -- FreeBSD: 'xchat' vulnerability -- The xchat IRC client provides the ability to launch URLs displayed in an IRC window in a web browser by right clicking on the URL. However this was handled incorrectly in versions prior to 1.4.3, and prior to 1.5.7 in the 1.5 development series, and allowed a malicious IRC user to embed command strings in a URL which could cause an arbitrary command to be executed as the local user if the URL were to be "launched" in a browser as described above.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/
Package Name: xchat-1.4.3.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-712.html
 
 

September 13th, 2000 -- FreeBSD: 'eject' vulnerability -- The eject program is installed setuid root, and contains several exploitable buffers which can be overflowed by local users, yielding root privileges.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/
Package Name: eject-1.4.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-713.html
 
 

September 13th, 2000 -- FreeBSD: 'listmanager' vulnerability -- The listmanager port, versions prior to 2.105.1, contained several locally exploitable buffer overflow vulnerabilities which could be used to gain root privileges.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports
Package Name: listmanager-2.105.1.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-714.html
 
 

September 13th, 2000 -- FreeBSD: 'mailman' vulnerability -- The mailman port, versions prior to 2.0b5, contained several locally exploitable vulnerabilities which could be used to gain root privileges.

Updated Packages: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/
Package Name: mailman-2.0b5.tgz

http://www.linuxsecurity.com/advisories/freebsd_advisory-715.html
 
 

September 13th, 2000 -- Mandrake: 'mod_php3' vulnerability -- It is possible for a remote attacker to supply an arbitrary file name as the value for $FOO by submitting a standard form input tag by that name, and thus cause the PHP script to process arbitrary files. The vulnerability exists in various scripts, and not necessarily with PHP itself, as the script determines what actions to perform on the uploaded file. The new versions of both PHP3 and PHP4 make it easier to secure scripts from this particular vulnerability.

Updated Packages: ftp://ftp.free.fr/pub/Distributions_Linux/Mandrake/updates
Package Name: mod_php3-3.0.17

http://www.linuxsecurity.com/advisories/mandrake_advisory-716.html
 
 

September 13th, 2000 -- Conectiva: 'xpdf' vulnerability -- Insecure file creation in /tmp which could be exploited via symlink attacks; Shell commands inserted in URLs would be expanded and executed by the shell when the user opened such an URL from within xpdf. Please note that xpdf is not SUID and therefore any attack which uses these vulnerabilities will only have the privileges of the user running xpdf.

Updated Packages: ftp://atualizacoes.conectiva.com.br
Package Name: xpdf-0.91-1cl

http://www.linuxsecurity.com/advisories/other_advisory-708.html
 
 

September 12th, 2000 -- Debian: 'libpam-smb' vulnerability -- libpam-smb contains a buffer overflow that can be used to execute arbitrary commands with root privilege. libpam-smb was not shipped with Debian 2.1 (slink), but was included in Debian 2.2 (potato).

Updated Packages: http://security.debian.org/dists/stable/updates/main/
Package Name: libpam-smb_1.1.6

http://www.linuxsecurity.com/advisories/debian_advisory-705.html
 
 

September 12th, 2000 -- Conectiva: 'pam_smb' vulnerability -- There is a buffer overflow in pam_smb versions 1.1.5 and below that could be exploited to gain root privileges. This package is not used by default in Conectiva Linux, but it is part of the distribution. Remote root access could be gained if a vulnerable pam_smb were to be used to authenticate users in remote services, such as ssh, telnet and others.

Updated Packages: ftp://atualizacoes.conectiva.com.br/5.1/
Package Name: pam_smb-1.1.6-1cl

http://www.linuxsecurity.com/advisories/other_advisory-706.html
 
 

September 11th, 2000 -- Caldera: 'xpdf' vulnerabilities -- There are two security problems in xpdf, the PDF file viewer. The first is that temporary files were created insecurely. The second problem is that xpdf was not cautious enough when the user clicked on a URL. Xpdf would start the URL viewer (netscape by default) via the system shell, not properly taking care of shell meta characters. This problem could be exploited by creating PDF files that ran malicious code when the user selected a URL in the document.

Updated Packages:
ftp://ftp.calderasystems.com/pub/updates/eServer/2.3/current/RPMS/
f0cf08c9febe6c7e16500812a140f846 RPMS/xpdf-0.91-3.i386.rpm

ftp://ftp.calderasystems.com/pub/updates/eDesktop/2.4/current/RPMS/
696e6851ecd8b348a9b4c0ef18fd94bd RPMS/xpdf-0.91-3.i386.rpm

http://www.linuxsecurity.com/advisories/caldera_advisory-702.html
 
 

September 11th, 2000 -- Mandrake: 'mod_perl' vulnerability -- The configuration file, /etc/httpd/conf/addon-modules/mod_perl.conf contained an Options directive that was not entirely secure and allowed people to browse the /perl/ directory. This update adds the "-Indexes" directive to the Options command, thus making the directory non-browseable.

Updated Packages: ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates
Package Name: mod_perl

http://www.linuxsecurity.com/advisories/mandrake_advisory-704.html
 
 

September 11th, 2000 -- RedHat: Updated 'mgetty' packages available -- The mgetty-sendfax package contains a vulnerability which allows any user with access to the /var/tmp directory to destroy any file on any mounted filesystem.

Updated Packages: ftp://updates.redhat.com/5.2/
                  ftp://updates.redhat.com/6.2/
Package Name: mgetty-1.1.22-1.5

http://www.linuxsecurity.com/advisories/redhat_advisory-703.html
 
 

September 10th, 2000 -- Debian: horde and imp vulnerabilities -- imp as distributed in Debian GNU/Linux 2.2 suffered from insufficient checking of user supplied data: the IMP webmail interface did not check the $from variable which contains the sender address for shell metacharacters. This could be used to run arbitrary commands on the server running imp.

Updated Packages: http://security.debian.org/dists/stable/updates/main/
Package Name: horde_1.2.1-0

http://www.linuxsecurity.com/advisories/debian_advisory-699.html
 
 

September 10th, 2000 -- Debian: xpdf vulnerabilities -- xpdf as distributed in Debian GNU/Linux 2.2 suffered from two problems: 1. creation of temporary files was not done safely which made xpdf vulnerable to a symlink attack. 2. when handling URLs in documents no checking was done for shell metacharacters before starting the browser. This makes it possible to construct a document which cause xpdf to run arbitrary commands when the user views an URL.

Updated Packages: http://security.debian.org/dists/stable/updates/main/
Package Name: xpdf_0.90-7

http://www.linuxsecurity.com/advisories/debian_advisory-700.html
 
 

September 8th, 2000 -- TurboLinux: glibc vulnerabilities -- There have been two major security vulnerabilities involving glibc, one involving ld.so and unsetenv that allows local user's to gain root privileges due to environment variables not getting cleared out in some circumstances. Another vulnerability is lack of good checking on the locale file specification which can be set to a file provided by an attacker to crash an application and gain root access.

Updated Packages: ftp://ftp.turbolinux.com/pub/updates/6.0/
Package Name: glibc-2.1.2

http://www.linuxsecurity.com/advisories/turbolinux_advisory-698.html

Cyberdefense students using PKI
Feb 22

Cryptography in Your Pocket
Feb 21

Attrition statement on NY Times defacement greeting
Feb 21

lcrzo and lcrzoex Version 3.03
Feb 21

Is your web server running unnecessary software?
Feb 21

Net anonymity firms seek their market
Feb 21

Unbreakable Code Said To Leave Hackers 'Helpless'
Feb 20

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000