★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-1620.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 9/22/2000 11:38

Linux Advisory Watch - September 22nd, 2000

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
9/22/2000

A majority of the advisories released this week were for syslogd/klogd. Caldera, SuSE, Mandrake, Trustix, Slackware, Debian, and RedHat have all made updated packages available. It is important that you update this package because the vulnerability could result in a local root compromise.

Other advisories included glint, screen, and xchat. Screen also has the risk of a local root compromise. The glint vulnerability can be used to maliciously destruct files.

Our sponsor this week is OpenDoc Publishing. Their 480-page comprehensive security book, Securing and Optimizing Linux, takes a hands-on approach to installing, optimizing, configuring, and securing Red Hat Linux. Topics include sendmail 8.10.1, OpenSSL, ApacheSSL, OpenSSH and much more! Includes Red Hat 6.2 and Red Hat 6.2 PowerTools edition.

https://secure.linuxports.com/cart/security

Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security advisories.


Advisories This Week:

September 21st, 2000 -- RedHat: 'glint' symlink vulnerability -- If a specific symlink exists in /tmp, glint will open it and write to it when run by root -- so destruction of any file is possible. Note that glint does not work with RPM 3.0 or higher. If you have RPM 3.0 or higher installed, just uninstall the glint package to remove this vulnerability.

Package Name: glint-2.6.3-1
URL: ftp://updates.redhat.com/5.2/

http://www.linuxsecurity.com/advisories/caldera_advisory-736.html

September 20th, 2000 -- Caldera: 'syslogd'klogd' vunlerabilities -- Several problems have been discovered in syslogd and klogd, the daemon programs responsible for system logging on Linux. 1. There is a format bug in klogd. 2.There is a single byte buffer overflow in syslogd. 3. When given long messages, syslogd broadcasts the message to all users currently logged in.

Package Name: sysklogd-1.4-2
URL: ftp://ftp.calderasystems.com/pub/updates/eDesktop/2.4/current/

September 20th, 2000 -- FreeBSD: 'screen' update -- The screen port, versions 3.9.5 and before, contains a vulnerability which allows local users to gain root privileges. This is accomplished by inserting string-formatting operators into configuration parameters, which may allow arbitrary code to be executed.

Package Name: screen-3.9.8.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/

http://www.linuxsecurity.com/advisories/freebsd_advisory-734.html

September 20th, 2000 -- SuSE: 'syslogd/klogd' vulnerability -- Errors in both the klogd and the syslogd can cause both daemons do die when specially designed strings get passed to the kernel by the user, eg. with a malformed structure in a system call.

Package Name: syslogd-1.3.33-161
URL: ftp://ftp.suse.com/pub/suse/

http://www.linuxsecurity.com/advisories/suse_advisory-732.html

September 19th, 2000 -- Mandrake: 'sysklogd' vulnerability -- A problem exists with the kernel logging daemon (klogd) in the sysklogd package. A "format bug" makes klogd vulnerable to local root compromise, as well as the possibility for remote vulnerabilities under certain circumstances, which are unprobable. There is also a more probable semi-remote exploit via knfsd. This update provides a patched version of klogd that fixes these vulnerabilities.

Package Name: sysklogd-1.3.31-15
URL: ftp://ftp.free.fr/pub/Distributions_Linux/Mandrake/updates

http://www.linuxsecurity.com/advisories/mandrake_advisory-730.html

September 19th, 2000 -- Trustix: 'sysklogd' vulnerability -- Trustix Secure Linux also suffers from a security hole in sysklogd. Everybody running 1.0x or 1.1 should upgrade. The hole is already fixed in the new beta (1.1.80).

Package Name: sysklogd-1.3.31-18tr.i586.rpm
URL: ftp://ftp.trustix.com/pub/Trustix/updates/1.1/RPMS

http://www.linuxsecurity.com/advisories/other_advisory-731.html

September 19th, 2000 -- Slackware: 'sysklogd' vunlerability -- A string format / buffer overflow bug has been discovered in klogd, the kernel logging daemon. Please upgrade to the new sysklogd 1.4 package available on the Slackware FTP site.

Package Name: sysklogd.tgz
URL:ftp://ftp.slackware.com/pub/slackware/slackware-current/slakware/a1/

http://www.linuxsecurity.com/advisories/slackware_advisory-729.html

* Debian: Info: Phasing out support for 2.1

Debian is phasing out support for Debian 2.1 (slink). We believe that this will have a minimal impact on our user community as we expect that most slink users have already upgraded to potato. We had originally announced that support would end Sep 30, 2000.

http://www.linuxsecurity.com/advisories/debian_advisory-720.html

September 19th, 2000 -- Debian: 'sysklogd' vulnerability -- Multiple vulnerabilities have been reported in syslogd and klogd. A local root exploit is possible, and remote exploits may be possible in some cases (though we are not currently aware of a remote exploit.)

Package Name: sysklogd_1.3-33
URL: ftp://security.debian.org/debian-security

http://www.linuxsecurity.com/advisories/debian_advisory-727.html

September 19th, 2000 -- TurboLinux: 'xchat' vulnerability -- There has been a well-known vulnerability existing with all un-patched xchat versions 1.4.2 and earlier. By supplying commands enclosed in backticks (``) in URL's sent to X-Chat, it is possible to execute arbitrary commands should the X-Chat user decide to view the link by clicking on it. This is due to the manner in which X-Chat launches pages for viewing.

http://www.linuxsecurity.com/advisories/turbolinux_advisory-723.html

September 19th, 2000 -- TurboLinux: 'sysklogd' vulnerability -- Package Name: sysklogd-1.3.31-6
URL: ftp://ftp.turbolinux.com/pub/updates/6.0/

http://www.linuxsecurity.com/advisories/turbolinux_advisory-725.html

September 18th, 2000 -- RedHat: 'syslogd' vulnerabilities -- Various vulnerabilities exist in syslogd/klogd. By exploiting these vulnerabilities, it could be possible for local users to gain root access. No remote exploit exists at this time, but it remains theoretically possible that this vulnerability could be exploited remotely under certain rare circumstances.

Package Name: sysklogd-1.3.31-1.6
URL: ftp://updates.redhat.com/5.2/
ftp://updates.redhat.com/6.2/

http://www.linuxsecurity.com/advisories/redhat_advisory-722.html

Firms fall through Unix security flaw
Mar 19

Crypto guru debates efficiency discovery
Mar 19

Best place for a break-in? The front door
Mar 19

Using SSH
Mar 19

Study: Hackers take a trip through Asia
Mar 19

How to Create an Incident Response Plan
Mar 19

Security-flaw guidelines hit pothole
Mar 19

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000