★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-3330.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 7/13/2001 19:30

Linux Security Week - July 13th 2001

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
7/13/2001

This week, advisories were released for cfingerd, hangterm, xinetd, w3m, samba, gnupg, fetchmail, freebsd kernel, openssl, allcommerce, sudo, and xloadimage. The vendors include Debain, EnGarde, FreeBSD, Mandrake, Red Hat, and Trustix. FreeBSD users should pay particular close attention to this weeks newsletter because of the number of advisories released.

We have just released the first issue of our EnGarde newsletter. It contains details on EnGarde development, usage tips, news & reviews pertaining to EnGarde, and information on the latest software released by Guardian Digital for EnGarde. Read it here: http://www.engardelinux.org/docs/newswire-07-en.html

**Worried About Web Security?** Worried about Web security for your Apache servers? Find out how to implement SSL from the Apache experts. Get a FREE Thawte Apache SSL Guide and find the answers to all your Apache SSL security issues and more at: http://www.gothawte.com/rd14.html
Package Vendor
cfingerd Debian
hangterm FreeBSD
xinetd FreeBSD, Mandrake, Red Hat
w3m FreeBSD
samba FreeBSD
gnupg FreeBSD
fetchmail FreeBSD, Mandrake
FreeBSD kernel FreeBSD
openssl EnGarde, Trustix
allcommerce EnGarde
sudo EnGarde
xloadimage Red Hat

We at Guardian Digital are striving to bring you the best support and documentation for EnGarde Secure Linux. Please take a look at our new FAQ: http://www.engardelinux.org/engardefaq.html Our documentation collection is constantly growing. For a complete listing please visit: http://www.engardelinux.org/documentation.html

Linux Advisory Watch is a comprehensive newsletter that outlinesthe security vulnerabilities that have been announced throughout the week.It includes pointers to updated packages and descriptions of each vulnerability.


cfingerd

Steven van Acker reported on bugtraq that the version of cfingerd (a configurable finger daemon) as distributed in Debian GNU/Linux 2.2 suffers from two problems: 1. The code that reads configuration files (files in which $ commands are expanded) copied its input to a buffer without checking for a buffer overflow. When the ALLOW_LINE_PARSING feature is enabled that code is used for reading users files as well, so local users could exploit this. 2. There also was a printf call in the same routine that did not protect against printf format attacks.

Debian Intel IA-32 architecture: http://security.debian.org/dists/stable/updates/main/ binary-i386/cfingerd_1.4.1-1.2_i386.deb MD5 checksum: 2281e1aa8dc439680b1df546a5139aae

Debian Vendor Advisory: http://www.linuxsecurity.com/advisories/debian_advisory-1485.html

hangterm

The hanterm binary is installed with setuid root permissions, but contains insecure code which allows unprivileged local users to obtain root access on the local system. The hanterm ports are not installed by default, nor is it "part of FreeBSD" as such: it is part of the FreeBSD ports collection, which contains over 5400 third-party applications in a ready-to-install format. The ports collections shipped with FreeBSD 4.3 contain this problem since it was discovered after the release.

FreeBSD [i386] ko-hanterm: ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/ korean/ko-hanterm-3.1.5_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/ korean/ko-hanterm-3.1.5_1.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1481.html

xinetd

The xinetd port, versions prior to xinetd-2.3.0, contains a potentially exploitable buffer overflow in the logging routines. If xinetd is configured to log the userid of remote clients obtained via the RFC1413 ident service, a remote user may be able to cause xinetd to crash by returning a specially-crafted ident response. This may also potentially execute arbitrary code as the user running xinetd, normally root.

FreeBSD [i386] ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/ security/xinetd-2.3.0.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current /security/xinetd-2.3.0.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1486.html

Mandrake Linux 8.0: i586 http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/xinetd-2.3.0-1.1mdk.i586.rpm d9e1bdc5a29712a75608c4753f6d6490

8.0/RPMS/xinetd-ipv6-2.3.0-1.1mdk.i586.rpm 9f95def40b777f13fc8339bf321b9547

Mandrake Vendor Advisory: http://www.linuxsecurity.com/advisories/mandrake_advisory-1478.html

Red Hat i386: ftp://updates.redhat.com/7.1/en/os/i386/xinetd-2.3.0-1.71.i386.rpm af532d612480937736f76b6fbeb8218d

Red Hat Vendor Advisory: http://www.linuxsecurity.com/advisories/redhat_advisory-1480.html

w3m

he w3m port, versions prior to w3m-0.2.1_1, contains a buffer overflow in the parsing of MIME headers. A malicious server which is visited by a user with the w3m browser can exploit the browser security holes in order to execute arbitrary code on the local machine as the local user.

FreeBSD [i386] ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/ www/w3m-ssl-0.2.1_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current /www/w3m-ssl-0.2.1_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/ www/w3m-ssl-0.2.1_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/ www/w3m-ssl-0.2.1_1.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1487.html

samba

The samba ports, versions prior to samba-2.0.10, samba-devel-2.2.0a, and ja-samba-2.0.9.j1.0_1, fail to properly validate NetBIOS names. By sending a specially crafted NetBIOS name containing unix path characters, a remote user may be able to cause the samba server to write the log files to arbitrary locations on the local filesystems.

FreeBSD [i386] ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-4-stable/net/samba-2.0.10.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386 /packages-5-current/net/samba-2.0.10.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-4-stable/net/samba-2.2.0a.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-5-current/net/samba-2.2.0a.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-4-stable/japanese/ja-samba-2.0.9.j1.0_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-5-current/japanese/ja-samba-2.0.9.j1.0_1.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1488.html

gnupg

The gnupg port, versions prior to gnupg-1.0.6, contains a format string vulnerability. If gnupg attempts to decrypt a file whose filename does not end in '.gpg', the filename is copied to the prompt string, allowing a user-supplied format string. This may allow a malicious user to cause arbitrary code to be executed as the user running gnupg.

FreeBSD [i386] ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-4-stable/security/gnupg-1.0.6_1.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-5-current/security/gnupg-1.0.6_1.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1489.html

fetchmail

The fetchmail port, versions prior to fetchmail-5.8.6, contains a potentially exploitable buffer overflow when rewriting headers longer than 512 bytes. This problem may allow remote users to cause fetchmail to crash and potentially execute arbitrary code as the user running fetchmail.

FreeBSD [i386] ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-4-stable/mail/fetchmail-5.8.6.tgz ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/ packages-5-current/mail/fetchmail-5.8.6.tgz

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1490.html

Mandrake Linux 8.0: i586 http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/fetchmail-5.7.4-5.1mdk.i586.rpm 3b1e12c828e28e9a31947bf5046a59d0

8.0/RPMS/fetchmail-daemon-5.7.4-5.1mdk.i586.rpm d4efb43e905b1e7039b407a6649c2812

8.0/RPMS/fetchmailconf-5.7.4-5.1mdk.i586.rpm 18f72c84c4eeb6740ebcd71825a0605a

Mandrake Vendor Advisory: http://www.linuxsecurity.com/advisories/mandrake_advisory-1479.html

FreeBSD kernel

A flaw exists in FreeBSD signal handler clearing that would allow for some signal handlers to remain in effect after the exec. Most of the signals were cleared, but some signal hanlders were not. This allowed an attacker to execute arbitrary code in the context of a setuid binary.

PLEASE SEE VENDOR ADVISORY

FreeBSD Vendor Advisory: http://www.linuxsecurity.com/advisories/freebsd_advisory-1491.html

openSSL

A weakness exists in the pseudo-random number generator (PRNG) in all version of OpenSSL up to and including 0.9.6a. Given knowledge of past results of PRNG queries an attacker can predict future results.

EnGarde i386 Binary Packages: ftp://ftp.engardelinux.org/pub/engarde/stable/updates/

i386/openssl-0.9.6-1.0.14.i386.rpm MD5 Sum: 347000c0645194ab5feb83eb92d2355c

i386/openssl-devel-0.9.6-1.0.14.i386.rpm MD5 Sum: 09125870402b05ad8ab75d74271893a3

i386/openssl-misc-0.9.6-1.0.14.i386.rpm MD5 Sum: e865af2f976115e92f99a6ce7fd1cb1b

EnGarde Vendor Advisory: http://www.linuxsecurity.com/advisories/other_advisory-1483.html

Trustix: i386

./1.2/RPMS/openssl-devel-0.9.6-2tr.i586.rpm e2c6604fc4013abea33c23b6b9a7cbad

0a64aca805351c89eb87eb992c0005d1 ./1.2/RPMS/openssl-0.9.6-2tr.i586.rpm

Trustix Vendor Advisory: http://www.linuxsecurity.com/advisories/other_advisory-1484.html

allcommerce

There is a temporary file creation vulnerability in AllCommerce which can allow an attacker to exploit a victim via a symlink attack as the 'webd' user.

EnGarde: i386 ftp://ftp.engardelinux.org/pub/engarde/stable/updates/

noarch/AllCommerce-1.0.4.1-1.0.25.noarch.rpm MD5 Sum: 9f60b894068f946757b6ca127672b3d9

EnGarde Vendor Advisory: http://www.linuxsecurity.com/advisories/other_advisory-1492.html

sudo

The configuration file for the sudo package which shipped with EnGarde Secure Linux 1.0.1 can allow users in the 'admin' group to gain elevated privileges by leveraging certain commands.

EnGarde: i386: PLEASE SEE VENDOR ADVISORY FOR UPDATE

EnGarde Vendor Advisory: http://www.linuxsecurity.com/advisories/other_advisory-1493.html

xloadimage

These updated packages fix a buffer overflow in the faces reader. This is normally not a security problem; however, xloadimage is called by the 'plugger' program from inside Netscape to handle some image types. Hence, a remote site could cause arbitrary code to be executed as the user running Netscape. It is recommended that users of Netscape and plugger update to the fixed xloadimage packages.

Red Hat i386: ftp://updates.redhat.com/7.1/en/os/i386/xloadimage-4.1-20.i386.rpm 39cdfa020253bcd3388b5aebf94adbb3

Red Hat Vendor Advisory: http://www.linuxsecurity.com/advisories/redhat_advisory-1482.html

Lapse At SANS May Have Been Self-Inflicted
Jul 17

Hardening BSD
Jul 17

Security expert: Tighter measures needed
Jul 17

Which Is More Secure? -- Open Source Vs. Proprietary
Jul 17

Flaws in Wireless Security Detailed
Jul 16

Global Monitoring System, ECHELON, has its day. Jam Echelon Day October 21st
Jul 16

IBM develops wireless LAN security analyzer
Jul 16

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000