Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.

LinuxSecurity.com Feature Extras:

What You Need to Know About Linux Rootkits - Rootkits are a way attackers hide their tracks and keep access to the machines they control. The good rootkits are very hard to detect and remove. They can be running on ones computer and no one can even know they have been running. Read more to learn how to detect them on your system.

Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition - Mark Sobell again delivers the answers to common Linux administration challenges, and provides thorough and step-by-step instructions to configuring many of the common Linux Internet services in A Practical Guide to Fedora and Red Hat Enterprise Linux, Fifth Edition.



(Jul 28)

Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code. [More...]

(Jul 28)

The PNG library libpng has been affected by several vulnerabilities. The most critical one is the identified as CVE-2011-2690. Using this vulnerability, an attacker is able to overwrite memory with an arbitrary amount of data controlled by her via a crafted PNG image. [More...]

(Jul 26)

Several vulnerabilities were discovered in phpMyAdmin, a tool to administrate MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]

(Jul 25)

Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]

(Jul 25)

Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Florian Kohlar, Marco Kampmann and Joerg Schwenk discovered that Shibboleth, a federated web single sign-on system is vulnerable to XML signature wrapping attacks. More details can be found in the Shibboleth [More...]

(Jul 25)

Tim Zingelmann discovered that due an incorrect configure script the kerborised FTP server failed to set the effective GID correctly, resulting in privilege escalation. [More...]

(Jul 25)

Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware: CVE-2011-2212 [More...]

(Jul 21)

Sebastian Krahmer discovered that opie, a system that makes it simple to use One-Time passwords in applications, is prone to a privilege escalation (CVE-2011-2490) and an off-by-one error, which can lead to the execution of arbitrary code (CVE-2011-2489). Adam Zabrocki and [More...]


Mandriva: 2011:121: samba (Jul 27)

Multiple vulnerabilities has been discovered and corrected in samba: All current released versions of Samba are vulnerable to a cross-site request forgery in the Samba Web Administration Tool (SWAT). By tricking a user who is authenticated with SWAT into clicking a [More...]

Mandriva: 2011:120: freetype2 (Jul 27)

A vulnerability was discovered and corrected in freetype2: Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted [More...]

Mandriva: 2011:119: libsndfile (Jul 25)

A vulnerability was discovered and corrected in libsndfile: An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way the libsndfile library processed certain Ensoniq PARIS Audio Format (PAF) audio files. An attacker could [More...]

Mandriva: 2011:118: wireshark (Jul 24)

This advisory updates wireshark to the latest version (1.2.18), fixing one security issue: The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial [More...]

Mandriva: 2011:117: krb5-appl (Jul 22)

A vulnerability was discovered and corrected in krb5-appl: ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass [More...]

Mandriva: 2011:116: curl (Jul 22)

A vulnerability was discovered and corrected in curl: The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote [More...]


Red Hat: 2011:1105-01: libpng: Moderate Advisory (Jul 28)

Updated libpng packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1104-01: libpng: Moderate Advisory (Jul 28)

Updated libpng packages that fix two security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1103-01: libpng: Moderate Advisory (Jul 28)

Updated libpng and libpng10 packages that fix one security issue are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1102-01: libsoup: Moderate Advisory (Jul 28)

Updated libsoup packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1100-01: icedtea-web: Moderate Advisory (Jul 27)

Updated icedtea-web packages that fix two security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1089-01: systemtap: Moderate Advisory (Jul 25)

Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1088-01: systemtap: Moderate Advisory (Jul 25)

Updated systemtap packages that fix two security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2011:1087-01: java-1.5.0-ibm: Critical Advisory (Jul 22)

Updated java-1.5.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 and 6 Supplementary. [More...]

Red Hat: 2011:1085-01: freetype: Important Advisory (Jul 21)

Updated freetype packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2011:1073-01: bash: Low Advisory (Jul 21)

An updated bash package that fixes one security issue, several bugs, and adds one enhancement is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More...]

Red Hat: 2011:1005-01: sysstat: Low Advisory (Jul 21)

An updated sysstat package that fixes one security issue, various bugs, and adds one enhancement is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More...]

Red Hat: 2011:1000-01: rgmanager: Low Advisory (Jul 21)

An updated rgmanager package that fixes one security issue, several bugs, and adds multiple enhancements is now available for Red Hat Enterprise Linux 5. [More...]

Red Hat: 2011:0975-01: sssd: Low Advisory (Jul 21)

Updated sssd packages that fix one security issue, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More...]

Red Hat: 2011:0999-01: rsync: Moderate Advisory (Jul 21)

An updated rsync package that fixes one security issue, several bugs, and adds enhancements is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]


SuSE: 2011-031: Linux kernel (Jul 25)

The SUSE Linux Enterprise 11 Service Pack 1 kernel was updated to 2.6.32.43 and fixes various bugs and security issues. Following security issues were fixed: CVE-2011-2496: The normal mmap paths all avoid creating a mapping where the pgoff inside the mapping could wrap around due to [More...]


Ubuntu: 1181-1: libsoup2.4 vulnerability (Jul 28)

An attacker could send crafted URLs to a SoupServer application and obtainunintended access to files.

Ubuntu: 1180-1: libvirt vulnerability (Jul 28)

An authenticated attacker could send crafted input to libvirt and cause itto crash.

Ubuntu: 1179-1: ClamAV vulnerability (Jul 28)

An attacker could send crafted input to ClamAV and cause it tocrash.

Ubuntu: 1177-1: QEMU vulnerability (Jul 27)

QEMU could be made to run with adminstrator group privileges under certaincircumstances.

Ubuntu: 1176-1: DBus vulnerability (Jul 26)

DBus could be made to crash if it processed a specially crafted message.

Ubuntu: 1175-1: libpng vulnerabilities (Jul 26)

Libpng could be made to run programs as your login if it opened aspecially crafted file.

Ubuntu: 1174-1: libsndfile vulnerability (Jul 25)

An application using libsndfile could be made to crash or possibly runprograms as your login if it opened a specially crafted file.

Ubuntu: 1173-1: FreeType vulnerability (Jul 25)

FreeType could be made to run programs as your login if it opened aspecially crafted font file.

Ubuntu: 1172-1: logrotate vulnerabilities (Jul 21)

An attacker could cause logrotate to run programs, stop working, or readand write arbitrary files.