Earn an NSA recognized IA Masters Online - The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.
LinuxSecurity.com Feature Extras:
RFID with Bio-Smart Card in Linux - In this paper, we describe the integration of fingerprint template and RF smart card for clustered network, which is designed on Linux platform and Open source technology to obtain biometrics security. Combination of smart card and biometrics has achieved in two step authentication where smart card authentication is based on a Personal Identification Number (PIN) and the card holder is authenticated using the biometrics template stored in the smart card that is based on the fingerprint verification. The fingerprint verification has to be executed on central host server for security purposes. Protocol designed allows controlling entire parameters of smart security controller like PIN options, Reader delay, real-time clock, alarm option and cardholder access conditions.
Linux File & Directory Permissions Mistakes - One common mistake Linux administrators make is having file and directory permissions that are far too liberal and allow access beyond that which is needed for proper system operations. A full explanation of unix file permissions is beyond the scope of this article, so I'll assume you are familiar with the usage of such tools as chmod, chown, and chgrp. If you'd like a refresher, one is available right here on linuxsecurity.com.
Take advantage of our Linux Security discussion
list! This mailing list is for general security-related questions and comments.
To subscribe send an e-mail to
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headline.
Debian | ||
Debian: New fetchmail packages fix information disclosure | ||
14th, February, 2007
Updated package. advisories/debian/debian-new-fetchmail-packages-fix-information-disclosure |
||
Debian: New imagemagick package fix arbitrary code execution | ||
14th, February, 2007
Updated package. advisories/debian/debian-new-imagemagick-package-fix-arbitrary-code-execution |
||
Fedora | ||
Fedora Core 6 Update: eclipse-cdt-3.1.1-8.fc6 | ||
14th, February, 2007
This updates the Autotools sub-component plugin to 0.0.7. advisories/fedora/fedora-core-6-update-eclipse-cdt-311-8fc6-16-46-00-127070 |
||
Gentoo | ||
Gentoo: Netkit FTP Server Privilege escalation | ||
13th, February, 2007
The original fix introduced a new vulnerability allowing the listing of any arbitrary directory with root group permissions due to a typo in the setgid() call. New fixed packages are available. Also, this update adds a second CVE reference which was not originally mentionned while it was covered by the original fix. |
||
Gentoo: Samba Multiple vulnerabilities | ||
13th, February, 2007
Multiple flaws exist in the Samba suite of programs, the most serious of which could result in the execution of arbitrary code. |
||
Gentoo: ProFTPD Local privilege escalation | ||
13th, February, 2007
A flaw in ProFTPD may allow a local attacker to obtain root privileges. |
||
Gentoo: Snort Denial of Service | ||
13th, February, 2007
Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service. |
||
Gentoo: RAR, UnRAR Buffer overflow | ||
13th, February, 2007
RAR and UnRAR contain a buffer overflow allowing the execution of arbitrary code. |
||
Mandriva | ||
Mandriva: Updated postgresql packages address multiple vulnerabilities | ||
8th, February, 2007
Jeff Trout discovered that the PostgreSQL server did not sufficiently check data types of SQL function arguments in some cases. A user could then exploit this to crash the database server or read out arbitrary locations of the server's memory, which could be used to retrieve database contents that the user should not be able to see. Note that a user must be authenticated in order to exploit this (CVE-2007-0555). |
||
Mandriva: Updated ImageMagick packages fix buffer overflow vulnerability | ||
9th, February, 2007
Vladimir Nadvornik discovered a buffer overflow in GraphicsMagick and ImageMagick allows user-assisted attackers to cause a denial of service and possibly execute execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. This is related to an earlier fix for CVE-2006-5456 that did not fully correct the issue. |
||
Mandriva: Updated smb4k packages fix numerous vulnerabilities | ||
12th, February, 2007
Kees Cook performed an audit on the Smb4K program and discovered a number of vulnerabilities and security weaknesses that have been addressed and corrected in Smb4K 0.8.0 which is being provided with this update. |
||
Red Hat | ||
RedHat: Moderate: dbus security update | ||
8th, February, 2007
Updated dbus packages that fix a security issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team. advisories/red-hat/redhat-moderate-dbus-security-update-RHSA-2009-0008-01 |
||
RedHat: Critical: IBMJava2 security update | ||
8th, February, 2007
IBMJava2-JRE and IBMJava2-SDK packages that correct several security issues are available for Red Hat Enterprise Linux 2.1. This update has been rated as having critical security impact by the Red Hat Security Response Team. advisories/red-hat/redhat-critical-ibmjava2-security-update-RHSA-2007-0072-01 |
||
RedHat: Critical: java-1.5.0-ibm security update | ||
9th, February, 2007
java-1.5.0-ibm packages that correct several security issues are available for Red Hat Enterprise Linux 4 Extras. This update has been rated as having critical security impact by the Red Hat Security Response Team. advisories/red-hat/redhat-critical-java-150-ibm-security-update-89380 |
||
Ubuntu | ||
Ubuntu: MoinMoin vulnerability | ||
9th, February, 2007
A flaw was discovered in MoinMoin's page name sanitizer which could lead to a cross-site scripting attack. By tricking a user into viewing a crafted MoinMoin page, an attacker could execute arbitrary JavaScript as the current MoinMoin user, possibly exposing the user's authentication information for the domain where MoinMoin was hosted. advisories/ubuntu/ubuntu-moinmoin-vulnerability |
||
Ubuntu: Linux kernel vulnerabilities | ||
10th, February, 2007
Mark Dowd discovered that the netfilter iptables module did not correcly handle fragmented IPv6 packets. advisories/ubuntu/ubuntu-linux-kernel-vulnerabilities-39223 |
||
Ubuntu: PostgreSQL regression | ||
12th, February, 2007
USN-417-2 fixed a severe regression in the PostgreSQL server that was introduced in USN-417-1 and caused some valid queries to be aborted with a type error. This update fixes a similar (but much less prominent) error. At the same time, PostgreSQL is updated to version 8.1.8, which fixes a range of important bugs. advisories/ubuntu/ubuntu-postgresql-regression |
||