LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: July 4th, 2008
Linux Security Week: June 30th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Linux Advisory Watch: February 29th, 2008 Print E-mail
User Rating:      How can I rate this item?
Source: LinuxSecurity.com Contributors - Posted by Benjamin D. Thomas   
Linux Advisory Watch This week, advisories were released for ghostscript, koffice, diatheke, turba2, iceape, alsa-driver, linux kernel, wordpress, dspam, splitvt, thunderbird, settroubleshoot, dbus, python, and pcre. The distributors include Debian, Fedora, Gentoo, Mandriva, and Ubuntu.

Linux+DVD Magazine Our magazine is read by professional network and database administrators, system programmers, webmasters and all those who believe in the power of Open Source software. The majority of our readers is between 15 and 40 years old. They are interested in current news from the Linux world, upcoming projects etc.

In each issue you can find information concerning typical use of Linux: safety, databases, multimedia, scientific tools, entertainment, programming, e-mail, news and desktop environments.


LinuxSecurity.com Feature Extras:

Meet the Anti-Nmap: PSAD - Introduction

Having a great defense involves proper detection and recognition of an attack. In our security world we have great IDS tools to properly recognize when we are being attacked as well as firewalls to prevent such attacks from happening. However, certain attacks are not blindly thrown at you - a good attacker knows that a certain amount of reconnaissance and knowledge about your defenses greatly increases the chances of a successful attack. How would you know if someone is scanning your defenses? Is there any way to properly respond to such scans? You bet there is...

Open Source Tool of February: Nmap! - This February, the team at Linuxsecurity.com has chosen NMAP as the Open Source Security Tool of the Month!



In January, we chose GnuPG in part because it had just celebrated its 10th anniversary. Well, it wasn't alone. As of this past December Nmap ("Network Mapper"), the free and open source utility for network exploration and auditing, celebrated its 10th Anniversary as well! And because of its popularity, chances are very good that you've already used NMAP for quite some time. Even if you have, it's always good to take a look at how it all got started and what it's all about...

Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headline.


  EnGarde Secure Community v3.0.18 Now Available! (Dec 4)
 

Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.18 (Version 3.0, Release 18). This release includes the brand new Health Center, new packages for FWKNP and PSAD, updated packages and bug fixes, some feature enhancements to Guardian Digital WebTool and the SELinux policy, as well as other new features.

In distribution since 2001, EnGarde Secure Community was one of the very first security platforms developed entirely from open source, and has been engineered from the ground-up to provide users and organizations with complete, secure Web functionality, DNS, database and e-mail security, integrated intrusion detection and SELinux policies and more.

http://www.linuxsecurity.com/content/view/131851

  Debian: New ghostscript packages fix arbitrary code execution (Feb 27)
 

Chris Evans discovered a buffer overflow in the color space handling code of the Ghostscript PostScript/PDF interpreter, which might result in the execution of arbitrary code if a user is tricked into processing a malformed file.

http://www.linuxsecurity.com/content/view/134944
  Debian: New koffice packages fix multiple vulnerabilities (Feb 25)
 

Several vulnerabilities have been discovered in xpdf code that is embedded in koffice, an integrated office suite for KDE. These flaws could allow an attacker to execute arbitrary code by inducing the user to import a specially crafted PDF document.

http://www.linuxsecurity.com/content/view/134803
  Debian: New diatheke packages fix arbirary shell command execution (Feb 25)
 

Dan Dennison discovered that Diatheke, a CGI program to make a bible website, performs insufficient sanitising of a parameter, allowing a remote attacker to execute arbitrary shell commands as the web server user.

http://www.linuxsecurity.com/content/view/134800
  Debian: New turba2 packages fix permission testing (Feb 24)
 

Peter Paul Elfferich discovered that turba2, a contact management component for horde framework did not correctly check access rights before allowing users to edit addresses. This could result in valid users being able to alter private address records.

http://www.linuxsecurity.com/content/view/134796
  Debian: New iceape packages fix several vulnerabilities (Feb 24)
 

Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems: Jesse Ruderman, Kai Engert, Martijn Wargers, Mats Palmgren and Paul Nickerson discovered crashes in the layout engine, which might allow the execution of arbitrary code.

http://www.linuxsecurity.com/content/view/134795
  Debian: New alsa-driver packages fix kernel memory leak (Feb 22)
 

Takashi Iwai supplied a fix for a memory leak in the snd_page_alloc module. Local users could exploit this issue to obtain sensitive information from the kernel (CVE-2007-4571).

http://www.linuxsecurity.com/content/view/134792
  Debian: New Linux kernel 2.6.8 packages fix several issues (Feb 22)
 

Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:LMH reported a potential local DoS which could be exploited by a malicious user with the privileges to mount and read a corrupted cramfs filesystem.

http://www.linuxsecurity.com/content/view/134791
  Debian: New Linux kernel 2.4.27 packages fix several issues (Feb 22)
 

Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: infamous41md reported multiple integer overflows in the Sbus PROM driver that would allow for a DoS (Denial of Service) attack by a local user, and possibly the execution of arbitrary code.

http://www.linuxsecurity.com/content/view/134790
  Debian: New wordpress packages fix multiple vulnerabilities (Feb 21)
 

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php.

http://www.linuxsecurity.com/content/view/134788
  Debian: New dspam packages fix information disclosure (Feb 21)
 

Tobias Gruetzmacher discovered that a Debian-provided CRON script in dspam, a statistical spam filter, included a database password on the command line when using the MySQL backend. This allowed a local attacker to read the contents of the dspam database, such as emails.

http://www.linuxsecurity.com/content/view/134786
  Debian: New splitvt packages fix privilege escalation (Feb 21)
 

Mike Ashton discovered that splitvt, a utility to run two programs in a split screen, did not drop group privileges prior to executing 'xprop'. This could allow any local user to gain the privileges of group utmp.

http://www.linuxsecurity.com/content/view/134785

  Fedora 7 Update: thunderbird-2.0.0.12-1.fc7 (Feb 28)
 

Several flaws were found in the way Thunderbird processed certain malformed HTML mail content.

http://www.linuxsecurity.com/content/view/135013
  Fedora 8 Update: setroubleshoot-plugins-2.0.4-3.fc8 (Feb 28)
 

This is a major upgrade of setroubleshoot. The primary difference is how audit data is captured, analyzed, and stored. Security vulnerabilities, performance, usability, and robustness have been addressed in addition to general bug fixes.

http://www.linuxsecurity.com/content/view/135004
  Fedora 8 Update: setroubleshoot-2.0.5-2.fc8 (Feb 28)
 

This is a major upgrade of setroubleshoot. The primary difference is how audit data is captured, analyzed, and stored. Security vulnerabilities, performance, usability, and robustness have been addressed in addition to general bug fixes.

http://www.linuxsecurity.com/content/view/135005
  Fedora 8 Update: dbus-1.1.2-9.fc8 (Feb 28)
 

This update fixes CVE-2008-0595.

http://www.linuxsecurity.com/content/view/134979
  Fedora 7 Update: dbus-1.0.2-7.fc7 (Feb 28)
 

This update fixes CVE-2008-0595.

http://www.linuxsecurity.com/content/view/134960

  Gentoo: xine-lib User-assisted execution of arbitrary code (Feb 26)
 

xine-lib is vulnerable to multiple buffer overflows when processing FLAC and ASF streams.

http://www.linuxsecurity.com/content/view/134942
  Gentoo: Python PCRE Integer overflow (Feb 23)
 

A vulnerability within Python's copy of PCRE might lead to the execution of arbitrary code.

http://www.linuxsecurity.com/content/view/134794

  Mandriva: Updated dbus packages fix vulnerability (Feb 28)
 

A vulnerability was discovered by Havoc Pennington in how the dbus-daemon applied its security policy.

http://www.linuxsecurity.com/content/view/135020
  Mandriva: Updated pcre packages fix vulnerability (Feb 27)
 

A buffer overflow in PCRE 7.x before 7.6 allows remote attackers to execute arbitrary code via a regular expression that contains a character class with a large number of characters with Unicode code points greater than 255.

http://www.linuxsecurity.com/content/view/134949
  Mandriva: Updated cacti packages fix multiple (Feb 27)
 

A number of vulnerabilities were found in the Cacti program, including XSS vulnerabilities, SQL injection vulnerabilities, CRLF injection vulnerabilities, and information disclosure vulnerabilities. This update provides Cacti 0.8.6k which corrects these issues.

http://www.linuxsecurity.com/content/view/134948
  Mandriva: Updated cups packages fix vulnerabilities (Feb 26)
 

A flaw was found in how CUPS handled the addition and removal of remote printers via IPP that could allow a remote attacker to send a malicious IPP packet to the UDP port causing CUPS to crash. The updated packages have been patched to correct these issues.

http://www.linuxsecurity.com/content/view/134941
  Mandriva: Updated cups packages fix multiple vulnerabilities (Feb 26)
 

Dave Camp at Critical Path Software discovered a buffer overflow in CUPS 1.1.23 and earlier could allow local admin users to execute arbitrary code via a crafted URI to the CUPS service (CVE-2007-5848). The Red Hat Security Team also found two flaws in CUPS 1.1.x where a malicious user on the local subnet could send a set of carefully crafted IPP packets to the UDP port in such a way as to cause CUPS to crash (CVE-2008-0597) or consume memory and lead to a CUPS crash (CVE-2008-0596).

http://www.linuxsecurity.com/content/view/134940
  Mandriva: Updated nss_ldap package fixes race condition (Feb 25)
 

A race condition in nss_ldap, when used in applications that use pthread and fork after a call to nss_ldap, does not properly handle the LDAP connection, which might cause nss_ldap to return the wrong user data to the wrong process, giving one user access to data belonging to another user, in some cases. The updated package hais been patched to prevent this issue.

http://www.linuxsecurity.com/content/view/134797
  Mandriva: Updated Firefox packages fix multiple (Feb 22)
 

A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.12. This update provides the latest Firefox to correct these issues.

http://www.linuxsecurity.com/content/view/134793
  Mandriva: Updated x11-driver-video-openchrome package (Feb 21)
 

The openchrome driver version shipped with Mandriva 2008.0 is not fully functional with most chrome based video cards available in the market. This update, requested by upstream developers, should correct the problems, and provide a more mature driver.

http://www.linuxsecurity.com/content/view/134784

  Ubuntu: PCRE vulnerability (Feb 21)
 

It was discovered that PCRE did not correctly handle very long strings containing UTF8 sequences. In certain situations, an attacker could exploit applications linked against PCRE by tricking a user or automated system in processing a malicious regular expression leading to a denial of service or possibly arbitrary code execution.

http://www.linuxsecurity.com/content/view/134787
  Ubuntu: libcdio vulnerability (Feb 21)
 

Devon Miller discovered that the iso-info and cd-info tools did not properly perform bounds checking. If a user were tricked into using these tools with a crafted iso image, an attacker could cause a denial of service via a core dump, and possibly execute arbitrary code.

http://www.linuxsecurity.com/content/view/134781
  Ubuntu: Qt vulnerability (Feb 21)
 

It was discovered that QSslSocket did not properly verify SSL certificates. A remote attacker may be able to trick applications using QSslSocket into accepting invalid SSL certificates.

http://www.linuxsecurity.com/content/view/134782

Write Comment
  • Please keep the topic of messages relevant to the subject of the article.
  • Personal verbal attacks will be deleted.
  • Please don't use comments to plug your web site.. Such material will be removed.
Name:
Title:
Comment:

Code:* Code

Powered by AkoComment!

 
< Prev   Next >
    
Partner:

 

Latest Features
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
Yesterday's Edition

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.