★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-3633.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 9/7/2001 0:18

Linux Advisory Watch - September 7th 2001

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
9/7/2001

This week, advisories were released for xinet, windowmaker, sendmail, fetchmail, xli, telnetd, rmuser, NetBSD kernel, and fts.  The vendors include Conectiva, NetBSD, Mandrake, and SuSE.  Mandrake users are especially encouraged to update this week because there is such a great number of advisories.
 
 
Packages Vendors
xinet Mandrake
windowmaker Mandrake
sendmail Mandrake, NetBSD
fetchmail Mandrake, Conectiva
xli Mandrake
telnetd SuSE
rmuser FreeBSD
screen SuSE
NetBSD kernel NetBSD
fts NetBSD

Maximize your security with EnGarde!  EnGarde was designed from the ground up as a secure solution, starting with the principle of least privilege, and carrying it through every aspect of its implementation. http://www.engardelinux.org

Linux Advisory Watch is a comprehensive newsletter that outlinesthe security vulnerabilities that have been announced throughout the week.It includes pointers to updated packages and descriptions of each vulnerability.


xinet

An audit has been performed on the xinetd 2.3.0 source code by Solar Designer for many different possible vulnerabilities.  The 2.3.1 release incorporated his patches into the xinetd source tree.  The audit was very thorough and found and fixed many problems.  This xinetd update includes his audit patch.

Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/xinetd-2.3.0-5.1mdk.i586.rpm
2f559b028fe14780460c37de5a521bce

8.0/RPMS/xinetd-ipv6-2.3.0-5.1mdk.i586.rpm
81766c2104aa7e1f197dac9dce1c09af

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1588.html


 

WindowMaker

A buffer overflow exists in the WindowMaker window manager's window title handling code, as discovered by Alban Hertroys.  Many programs, such as web browsers, set the window title to something obtained from the network, such as the title of the currently-viewed web page.

Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/WindowMaker-0.64.0-8.1mdk.i586.rpm
10d20d21c895a09172fa0f32f6b7363b

8.0/RPMS/WindowMaker-devel-0.64.0-8.1mdk.i586.rpm
da9ffdad57c2dd4362e383a79ebf5951

8.0/RPMS/libwraster2-0.64.0-8.1mdk.i586.rpm
644f90bf9a1fa1efb9a34599b761a449

8.0/RPMS/libwraster2-devel-0.64.0-8.1mdk.i586.rpm
9ec21851b8e98f4a4a633addac5b81ba

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1589.html


 

sendmail

An input validation error exists in sendmail that may allow local users to write arbitrary data to process memory.  This could possibly allow the execute of code or commands with elevated privileges and may also allow a local attacker to gain access to the root account.

Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/sendmail-8.11.6-1.1mdk.i586.rpm
9ff57477c98a364588fa7a5ed95750b5

8.0/RPMS/sendmail-cf-8.11.6-1.1mdk.i586.rpm
7c53b2aa7fc6105892ddededf4e31898

8.0/RPMS/sendmail-doc-8.11.6-1.1mdk.i586.rpm
e3d814078cacf5e2cc2c40c2b104100e

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1590.html
 

NetBSD
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/
SA2001-017-sendmail.patch

NetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1599.html
 
 
 

fetchmail

A vulnerability was found by Salvatore Sanfilippo in both the IMAP and POP3 code of fetchmail where the input is not verified and no bounds checking is done.  This can be exploited by a remote attacker to write arbitrary data into memory.  The attacker must have control of the mail server the client is connecting to via fetchmail in order to exploit this vulnerability.

Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/fetchmail-5.7.4-5.2mdk.i586.rpm
d3d60c3ff5b5a07869a10b3f9519a592

8.0/RPMS/fetchmail-daemon-5.7.4-5.2mdk.i586.rpm
c7eb824dd7f7b4cd5144bf9d13608388

8.0/RPMS/fetchmailconf-5.7.4-5.2mdk.i586.rpm
dd686925435feb7777ff93e19e136897

Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1591.html

Conectiva 7.0: i386
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/
fetchmail-5.8.8-2U70_1cl.i386.rpm

ftp://atualizacoes.conectiva.com.br/7.0/RPMS/f
etchmailconf-5.8.8-2U70_1cl.i386.rpm

ftp://atualizacoes.conectiva.com.br/7.0/RPMS/
fetchmail-doc-5.8.8-2U70_1cl.i386.rpm

Conectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1595.html


 
 

xli

A buffer overflow exists in xli due to missing boundary checks.  This could be triggered by an external attacker to execute commands on the victim's machine.  An exploit is publically available.  xli is an image viewer that is used by Netscape's plugger to display TIFF, PNG, and Sun-Raster images.

Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php3

8.0/RPMS/xli-1.17.0-1.1mdk.i586.rpm
f1eff4c239eaebb0ff41f169de8ccd3e

Mandrake Vendot Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1592.html


 

nkitb/nkitserv/telnetd

The telnet server which is shipped with SuSE distributions contains a remotely exploitable buffer-overflow within its telnet option negotiation code.

i386 Intel Platform: SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/
telnet-server-1.0-69.i386.rpm
0adc05af9762bd4c63eee464ca3131d1

SuSE Vendor Advisory:
http://www.linuxsecurity.com/advisories/suse_advisory-1587.html


 

rmuser

For a brief amount of time while running rmuser, a world-readable copy of /etc/master.passwd is available.  A local attacker who reads this file can extract password hashes from the copy of /etc/master.passwd.  This information could be used by attackers to escalate their privileges, possibly yielding root privileges on the local system, by mounting an offline dictionary attack in order to guess the plaintext passwords of the accounts on the local system.

FreeBSD:
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/packages/SA-01:59/
security-patch-rmuser-01.59.tgz

FreeBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/freebsd_advisory-1593.html
 
 
 

screen

The screen package allows a local attacker to obtain root privileges if the /usr/bin/screen command is installed setuid root and if a directory below /tmp/screens/ exists.

SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/ap1/
screen-3.9.8-115.i386.rpm
e85453f50170ecdabe97dd2b33b51e4a

SuSE Vendor Avisory:
http://www.linuxsecurity.com/advisories/suse_advisory-1594.html


 

mailman

All mailman administrators should upgrade. It is recommended that the update be applied while the server is inactive, that is, the web interface should be disabled during this period as well as the MTA and crond, since many mailman processes are started at different times via cron.

Conectiva 7.0:
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/
mailman-2.0.6-1U70_1cl.i386.rpm

Conectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1596.html


 

 NetBSD kernel

A number of issues were found. In a number of places lengths or sizes passed from userland were used by the kernel without sufficient checks.

ftp://ftp.netbsd.org/pub/NetBSD/security/patches/
SA2001-015-kernlen-current.patch

NetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1597.html
 
 
 

fts

If any directory (or symlink to a directory) above the current directory fts was processing was moved, the fts-using application could be made to descend the wrong directory sub-tree, and/or ascend above the original starting directory.Once it has ascended above the starting directory, the process could descend into an unintended file system hierarchy.

NetBSD
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/
SA2001-016-fts.patch

NetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1598.html


 
 
 
 
Researcher scans the security scene
Nov 7

Reverse firewall dams DoS flood
Nov 7

Centralise security for success
Nov 7

ICANN scraps conference agenda, goes big on security
Nov 7

DoS Attacks: Easier To Launch, Harder to Fight
Nov 7

On the Security of PHP
Nov 7

Exploitation of vulnerability in SSH1 CRC-32 compensation attack detector
Nov 6

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000