Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-54-242-188-217.compute-1.amazonaws.com [54.242.188.217]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 11 / 2000

System: FreeBSD and other Unix
Topic: Vulnerability in tcpdump
Links: L-015
ID: ae-200011-050

Tcpdump is a free sniffer program. It is most commonly used to capture ethernet packets in a common format that many analysis tools can  read. It is the basis for many Intrusion Detection Software applications. Several overflowable buffers were discovered in the version of tcpdump included in many OS'. Some simply allow the remote attacker to crash the local tcpdump process. This is a problem for systems using tcpdump as a form of intrusion detection. A more serious vulnerability in the decoding of AFS ACL packets in the more recent version of tcpdump (tcpdump 3.5) which may allow a remote attacker to execute arbitrary code on the local system (usually at root privilege). For FreeBSD patches are available now.

System: Allaire
Topic: Denial-of-Service in JRun
Links: ASB00-30
ID: ae-200011-049

Under certain circumstances, the included JRun 3.0 http servlet server may improperly utilize server resources with deliberately malformed URIs. This behavior may lead to a Denial-of-Service condition if the server is flooded with these kinds of requests. A patch is available for systems under Windows and Unix.

System: Microsoft Exchange Server 5.5
Topic: DoS by Malformed MIME Header
Links: MS-082, ERS-2000.271
ID: ae-200011-048

As part of its normal processing of incoming mails, Exchange server checks for invalid values in the MIME header fields. If a particular type of invalid value is present in certain fields, the Exchange service will fail - Denial-of-Service. This issue will be fixed in SP4 for Exchange, a patch is available also.

System: Microsoft Windows NT and 2000
Topic: Buffer Overflow in Network Monitor
Links: ISS-067, MS-083, WinITSec, ISS-69, ERS-2000.279, L-016
ID: ae-200011-047

As we reported before, a vulnerability caused by a remotely exploitable buffer overflow condition in one of Network Monitor's protocol parsers has been found. This may allow a remote attacker to gain privileged access and execute arbitrary code on any machine running Network Monitor that displays  captured data. Now Microsoft has published patches for Microsoft Windows NT 4.0 Server and Windows NT 4.0 Server, Enterprise Edition, Microsoft Windows 2000 Server, Advanced Server and Datacenter Server, Microsoft Systems Management Server 1.2, and Microsoft Systems Management Server 2.0. The patch for Microsoft Windows NT 4.0 Server, Terminal Server Edition will be released shortly.

System: Microsoft Windows 2000
Topic: Vulnerability in Indexing Services, Cross-Site Scripting
Links: MS-084, ERS-2000.283
ID: ae-200011-046

A vulnerability could allow a malicious web site operator to misuse another web site as a means of attacking user - so called Cross-Site Scripting. It results when web applications don't properly validate inputs before using them in dynamic web pages. If the user loads pages from a malicious site, the operator of this site would be able to "inject" script into a Web page from another Web server, which would then be delivered to the user. The net effect would be to cause the malicious user's script to run on the user's machine using the trust afforded the other site. It's recommended to install a patch for Indexing Services under Windows 2000.

System: Microsoft IIS 4.x and 5.x
Topic: Vulnerability caused by Cross-Site Scripting
Links: MS-060
ID: ae-200011-045

This is a Re-Release of an earlier advisory regarding the Internet Information server. A vulnerability could allow a malicious web site operator to misuse another web site as a means of attacking user - so called Cross-Site Scripting. It results when web applications don't properly validate inputs before using them in dynamic web pages. If the user loads pages from a malicious site, the operator of this site would be able to "inject" script into a Web page from another Web server, which would then be delivered to the user. The net effect would be to cause the malicious user's script to run on the user's machine using the trust afforded the other site. Microsoft recommends to install patches for Internet Information Server 4.x  and 5.x.

System: Microsoft Windows 2000
Topic: Vulnerability caused by ActiveX
Links: MS-085, ERS-2000.284
ID: ae-200011-044

An ActiveX control that ships as part of Windows 2000 contains an unchecked buffer. If the control was called from a web page or HTML mail using a specially-malformed parameter, it would be possible to cause code to execute on the machine via a buffer overrun. This could potentially enable a malicious user to take any desire action on the user's machine, limited only by the permissions of the user. Affected are Windows 2000 Server, Professional, Advanced Server, and Datacenter Server.  It's recommended to install a patch

System: FreeBSD
Topic: Vulnerabilities in chpass, pine4, boa web server, tcpdump, top, and getnameinfo
Links: FreeBSD, ERS-2000.273, ERS-2000.274, ERS-2000.275, ERS-2000.276, ERS-2000.277, ERS-2000.278
ID: ae-200011-043

A "format string vulnerability" was discovered in code used by the vipw utility. The vipw utility does not run with increased privileges but this code is also shared with other utilities - namely chfn, chpass, chsh, ypchfn, ypchpass, ypchsh and passwd -- which do in fact run setuid root, a root-exploit included. The pine4 port, versions 4.21 and before, contains a buffer overflow vulnerability which allows a remote user to execute arbitrary code on the local client by the sending of a special-crafted email message.The boa port, versions after 0.92 but prior to 0.94.8.3, contains a vulnerability which allows remote users to view arbitrary files outside the document root. The vulnerability is that boa does not correctly restrict URL-encoded requests containing ".." in the path. Several overflowable buffers were discovered in the version of tcpdump included in FreeBSD. A "format string vulnerability" was discovered in the top(1) utility which allows unprivileged local users to cause the top process to execute arbitrary code. An off-by-one error exists in the processing of DNS hostnames which allows a long DNS hostname to crash the getnameinfo() function when an address resolution of the hostname is performed. Patches are available now.

System: Red Hat Linux 5.x, 6.x, 7.0
Topic: Vulnerabilities in nss_ldap, gnorpm, dump, pine, and imap
Links: RHSA-2000:024, RHSA-2000:072, RHSA-2000:100, ERS-2000.272, ERS-2000.281, ERS-2000.282, RHSA-2000:102, ERS-2000.288
ID: ae-200011-042

A race condition has been found in the nss_ldap package. On a system running nscd, an attacker can cause the system to hang. A locally-exploitable security hole was found where a normal user could trick root running GnoRPM into writing to arbitrary files due to a bug in the gnorpm tmp file handling. The Red Hat 7.0 dump is being released for Red Hat 6.x and Red Hat 5.x in order to remove root setuid bits to prevent a known dump exploit. By adding specific headers to messages, the pine mail reader and the imap server could be made to exit with an error message when users attempted to manipulate mail folders containing those messages.

System: HP-UX
Topic: Vulnerability in dtterm
Links: HP Security Bulletin #00128, ERS-2000.280, L-017
ID: ae-200011-041

Due to a security hole in dtterm users may gain unauthorized privileges on HP9000 systems running HP-UX releases 11.00, 11.04, 10.20, 10.24, and 10.10. Hewlett Packard has published patches:

System Patch-ID
HP-UX 10.10 not available yet
HP-UX 10.24 PHSS_22546
HP-UX 10.20 PHSS_22319
HP-UX 11.04 PHSS_22548
HP-UX 11.00 PHSS_22320
System: Linux Mandrake
Topic: Vulnerability in nss_ldap
Links: MDKSA-2000:066
ID: ae-200011-040

A race condition exists in versions of nss_ldap prior to version 121. On a system running nscd, a malicious user can cause the system to hang. A patch is available now.

System: Microsoft IIS 5.0 and 4.0
Topic: Vulnerability caused by Web Server File Request Parsing
Links: MS-086, L-018, ERS-2000.285, L-018a, ERS-2000.303
ID: ae-200011-039

When the Internet Information Server receives a valid request for an executable file, it passes the name of the requested file to the underlying operating system for processing. Due to an implementation flaw in IIS 5.0 and 4.0, it's possible to create a specially-malformed file request that contains both a file name and one or more operating system commands. The IIS would pass the entire string to the operating system, which would first process the file and then execute the commands. So it's possible to execute arbitrary commands on the system the IIS is running on. A patch for the IIS 5.0 is available in English, German, Japanese, Simplified Chinese, Traditional Chinese. Microsoft has updated the advisory and points out the latest patch for IIS 4.0 and IIS 5.0.

System: Microsoft Windows NT Terminal Server
Topic: Vulnerability caused by Login Buffer Overflow
Links: MS-087, WinITSec, ERS-2000.286
ID: ae-200011-038

An unchecked buffer in the Terminal Server login prompt could allow an attacker to cause the Terminal Server to execute arbitrary code, including adding, changing, or deleting data, runing code already on the server, or uploading new code to the server. The attacker would not need to successfully login to the Terminal Server remotely or direct. This vulnerability can only be exploited remotely if connection requests are not filtered. By default, Terminal Server listens on tcp port 3389. It's recommended to block this port to the Internet and to install the patch published by Microsoft.

System: Several systems
Topic: New ISS Summary
Links: ISS
ID: ae-200011-037

Within the last month, 103 (!) new vulnerabilities were found:

- linux-dump-execute-code - ultraseek-malformed-url-dos - allaire-jrun-servlet-dos
- ms-exchange-mime-dos - ewave-servletexec-file-upload - ewave-servletexec-dos
- samba-swat-brute-force - samba-swat-url-filename-dos - ftp-servu-brute-force
- samba-swat-logging-sym-link - samba-swat-logfile-info - pagelog-cgi-dir-traverse
- kw-whois-meta - iis-htw-cross-scripting - bftpd-user-bo
- nssldap-nscd-dos - news-update-bypass-password - iplanet-netscape-directory-traversal
- cisco-catalyst-remote-commands - tisfwtk-xgw-execute-code - iplanet-netscape-plaintext-password
- global-execute-remote-commands - cisco-vco-snmp-passwords - cyrus-sasl-gain-access
- iplanet-web-server-shtml-bo - pammysql-auth-input - iplanet-web-server-shtml-bo
- ntop-filename-bo-root - hotjava-browser-dom-access - allaire-jrun-webinf-access
- sun-compromised-certificate - allaire-jrun-ssifilter-url - allaire-jrun-jsp-execute
- halflife-rcon-format-string - ntop-i-bo - session-cookie-remote-retrieval
- avirt-mail-from-dos - avirt-rcpt-to-dos - hp-crontab-read-files
- pollit-admin-password-var - mysql-authentication - win-msiexec-reg-perm
- antivirus-nav-restore-directory - cisco-ios-query-dos - oracle-log-files-created
- oracle-home-bo - intel-email-username-bo - lpr-print-filters-execute
- ping-buf-bo - broker-ftp-username-dos - win-hyperterminal-telnet-bo
- ypbind-printf-format-string - oracle-oidldap-bo - vm-java-codebase-exe
- iis-unicode-translation - auction-weaver-delete-files - auction-weaver-username-bidfile
- wingate-view-files - hp-lpspooler-bo - cmd5checkpw-qmail-bypass-authentication
- halflife-server-changelevel-bo - netmeeting-desktop-sharing-dos - curl-error-bo
- winu-backdoor - freebsd-fingerd-files - win9x-share-level-password
- hp-virtualvault-nsapi-dos - communigate-email-verify - win-netbios-driver-type-dos
- php-logging-format-string - ie-cache-info - gnupg-message-modify
- netscape-messaging-email-verify - win-nmpi-packet-dos - hp-jetdirect-firmware-dos
- hp-jetdirect-ip-implementation - boa-webserver-config-cgi-exe - shambala-connection-dos
- extropia-webstore-fileread - shambala-password-plaintext - hassan-shopping-cart-dir-traversal
- web-shopper-directory-traversal - phpix-dir-traversal - icq-webfront-url-dos
- boa-webserver-get-dir-traversal - uclinux-apliophone-bin-execute - bsd-arp-request-dos
- word-mail-merge - linux-talkd-overwrite-root - aim-file-transfer-dos
- iis-index-dir-traverse - bsd-photurisd-format - bsd-eeprom-format
- bsd-fstat-format - bsd-libutil-format - winnt-invalid-lpc-request
- lpc-memory-consumption - spoofed-lpc-port-variant - linux-tmpwatch-fuser
- pegasus-file-forwarding - acme-thttpd-ssi - gnorpm-temp-symlink
- moreover-cgi-dir-traverse
System: HP-UX
Topic: Vulnerabilities in Aserver and MC/ServiceGuard
Links: HP Security Bulletin #00129, ERS-2000.287, S-00-49
ID: ae-200011-036

As reported before, a procedure to use /opt/audio/bin/Aserver to gain root access has been made public. The MC/ServiceGuard file and directory permissions are incorrect which may lead to a Denial-of-Service. Affected are HP-9000 machines. It's recommended to install the concerning patches:

System Patch-ID
HP-UX 10.xx PHSS_21662
HP-UX 11.00 PHSS_21663
PHSS_22540
HP-UX 11.11 PHSS_22540
System: Linux Mandrake
Topic: Vulnerability in bind
Links: MDKSA-2000:067
ID: ae-200011-035

A vulnerability exists with the bind nameserver dealing with compressed zone transfers. This vulnerability can be exploited by authorized zone transfers and used in a DoS attack. The named daemon will crash if it receives this type of zone transfer from an authorized source address. The crash is not necessarily immediate, but can range from a few seconds to a few minutes from the time of the attack. This new version of bind also fixes a bug in the handling of the compression pointer tables which can result in the nameserver entering an infinite loop. This bug has been known to occur in the standard processing of SRV records used with Windows 2000 Active Directory. Updates are available now.

System: Microsoft IE 5.x, Outlook and Outlook Express, Windows 2000 with Index Server
Topic: Vulnerability caused by ActiveX
Links: WinITSec
ID: ae-200011-034

As Georgi Guninski reports, using the "ixsso.query" ActiveX object the mentioned products gives an attacker the possibility of unauthorized file searching. A demonstration is available - but no patch yet.

System: Red Hat Linux 5.x, 6.x, 7.0
Topic: DoS in BIND
Links: RHSA-2000:107
ID: ae-200011-033

In BIND, the most used named, several possibilities for a Denial-of-Service were found.

System: Linux Mandrake
Topic: Vulnerabilities in bind, openssh, and tcsh
Links: MDKSA-2000:067, MDKSA-2000:068, MDKSA-2000:069
ID: ae-200011-032

In BIND several possibilities for a DoS were found. A vulnerability exists with all versions of OpenSSH prior to 2.3.0 with regards to the X11 forwarding and ssh-agent. If agent or X11 forwarding is disabled in the ssh client configuration, the client does not request these features during session setup. Another vulnerability exists with tcsh when using the in-here documents with the << syntax. When doing this, tcsh uses a temporary file to store the data. The temporary file is not created securely and standard symlink attacks can be used to make tcsh overwrite arbitrary files. Patches are available now.

System: OpenLinux
Topic: Vulnerability in bind
Links: CSSA-2000-040
ID: ae-200011-031

In BIND several possibilities for a DoS were found. Caldera has published the concerning patches.

System: Debian Linux
Topic: Vulnerablities in gnupg, tcsh, and bind
Links: Debian201111, Debian201111a, Debian201112
ID: ae-200011-030

The version of gnupg that is distributed in Debian GNU/Linux 2.2 has a logic error in the code that checks for valid signatures which could cause false positive results. Tcsh doesn't handle in-here documents correctly, so it's possible to overwrite arbitrary files on the system. In BIND several possibilities for a successful Denial-of-Service was found. Patches are available now.

System: many Unix
Topic: Multiple Denial-of-Service Problems in ISC BIND
Links: CA-2000-20, L-019, S-00-50
ID: ae-200011-029

Systems running Internet Software Consortium (ISC) BIND version 8.2 through 8.2.2-P6 and Systems running name servers derived from BIND version 8.2 through 8.2.2-P6 show several holes which can be exploited for a DoS. It's strongly recommended to update the systems to BIND 8.2.2-P7 or BIND 9.0.1. Further information about the security holes can be found here.

System: Rideway PN
Topic: Problem causes Denial-of-Service
Links: WinITSec
ID: ae-200011-028

Rideway PN V6.22 is a proxy application for Windows. As Strumpf Noir Society reports, it's vulnerable to a DoS-attack. If the Telnet Proxy is enabled and listening on port 23 (default Telnet port) an attacker could cause all proxy services to become unavailable.A patch is not available yet, but a demonstration is shown in the advisory.

System: Linux Mandrake
Topic: Vulnerabilities in cups and modutils
Links: MDKSA-2000:070, MDKSA-2000:071
ID: ae-200011-027

In Linux Mandrake 7.2 two problems in CUPS were found. CUPS printers are accessible from anywhere on the internet. A bug also exists where CUPS would broadcast to everywhere and thus keep open dial-on- demand lines. All 2.3.x versions of modutils (since March 12 1999) contain a vulnerability that can lead to a local root compromise. Patches are available now.

System: FreeBSD
Topic: Vulnerabilities in ncurses, telnet and ppp
Links: FreeBSD, ERS-2000.289, ERS-2000.290, S-00-51, S-00-52, S-00-53
ID: ae-200011-026

A vulnerability was found in ncurses: An overflowable buffer in the libncurses library in the processing of cursor movement may cause an attacker to execute arbitrary code on the local system with the privileges of the exploited binary. The telnet protocol allows for UNIX environment variables to be passed from the client to the user login session on the server. However, some of these environment variables have special meaning to the telnetd child process itself and may be used to affect its operation. It's possible, that an attacker may consume resources on the target system. 
The ppp(8) utility includes network address translation functionality for translating between public and private IP address ranges. It uses the libalias library to perform translation services. Users who are using the deny_incoming functionality in the expectation that it provides a "deny by default" firewall which only allows through packets known to be part of an existing NAT session, are in fact allowing other types of unsolicited IP traffic into their internal network. Patches are available now.

System: Microsoft Exchange 2000 Server
Topic: Backdoor by Known User Account
Links: MS-088, E
ID: ae-200011-025

In early shipments of Exchange 2000, setup creates an account with a known username and password. Under normal circumstances, this username and password can be only used to gain local user level access but on installations where Exchange is installed on a Domain Controller, Domain wide access could be obtained if one was to discover this username and password. Microsoft has provided a patch to fix this problem. RS-2000.291, WinITSec

System: Red Hat Linux 5.x, 6.x, 7.0
Topic: Vulnerability in modutils, Netscape, and joe
Links: RHSA-2000:108, ERS-2000.292, ERS-2000.293, RHSA-2000:109, ERS-2000.294, RHSA-2000:110, ERS-2000.300, L-020, ERS-2000.309, ERS-2000.311, L-022
ID: ae-200011-024

Modutils, a package that helps the kernel automatically load kernel modules (device drivers etc.) when they're needed, could be abused to execute code as root. A HTML Buffer Overflow in Netscape Communicator has been found and fixed. When exiting joe in a nonstandard way (such as a system crash, closing an xterm, or a network connection going down), joe will unconditionally append its open buffers to the file "DEADJOE". This could be exploited by the creation of DEADJOE symlinks in directories where root would normally use joe. In this way, joe could be used to append garbage to potentially sensitive files, resulting in a denial of service.

System: CA Inoculate IT for Exchange Server
Topic: Denial-of-Service possible
Links: WinITSec 
ID: ae-200011-023

It's possible to cause the AntiVirus Agent to fail when two separate Microsoft Exchange servers, both running Computer Associates Inoculate for Exchange communicate via the Microsoft Internet Mail Connector (IMC). There are multiple ways to accomplish this. Further information can be found in the advisory, a patch hasn't been released yet.

System: Debian Linux
Topic: Vunlerabilities in ssh, cron, and cupsys
Links: Debian201118, Debian201118a, Debian201119
ID: ae-200011-022

In Secure Shell, ssh, when the connection is established the remote ssh server can force the ssh client to enable agent and X11 forwarding. Several problems in Vixie Cron, including insecure permissions on temporary files and race conditions in their deletion, allow attacks from a Denial-of-Service to an escalation of priviledge. CUPS has a rather vague problem to the effect of "everyone on the Internet can get to your printers". Debian has published fixes that should be installed soon.

System: Microsoft IIS 4.x and 5.x
Topic: Vunlerability in Session ID Cookie Marking
Links: MS-080
ID: ae-200011-021

As reported before, there is a vulnerability in using Session ID Cookies (encrypted and plaintext) with ASP's. Now Microsoft has published a new patch for IIS 4.0 on x86 platforms (Alpha on request by Microsoft) and IIS 5.0.

System: HP-UX
Topic: Vulnerability in auto_parms
Links: HP Security Bulletin #00130, S-00-54, ERS-2000.302
ID: ae-200011-020

A security vulnerability was found in auto_parms and set_parms on HP9000 Series 700/800 running HP-UX releases 10.xx and 11.xx. It may allow remote users to gain root access or to disrupt normal operations. It's recommended to install the following patches:

System Patch
HP-UX 10.01 PHCO_21990
HP-UX 10.10 PHCO_21991
HP-UX 10.20 PHCO_21992
HP-UX 10.24 PHCO_22185
HP-UX 11.00 PHCO_21993
HP-UX 11.04 PHCO_22186
System:
Topic: New CERT-Summary
Links: CS-2000-04
ID: ae-200011-019

CERT has published a summary, pointing out the recent trends in security issues. The following were the most used exploits:
- Compromises Via an Input Validation Vulnerability in rpc.statd
- Compromises Via the 'SITE EXEC' Vulnerability in FTPd
- Compromises Via a Vulnerability in the IRIX Telnet Daemon
- VBS/Loveletter.AS Worm
- QAZ Worm
- Multiple Denial of Service Problems in ISC BIND

System: FreeBSD
Topic: Vulnerabilities in mgetty, curl, thttpd, mod_php3/mod_php4, tcsh, 44bsd-csh, and ncurses
Links: FreeBSD, ERS-2000.295, ERS-2000.296, ERS-2000.297, ERS-2000.298, ERS-2000.299, ERS-2000.301
ID: ae-200011-018

Exploiting a hole in mgetty local users may create or overwrite any file on the system. The curl port allows a client-side exploit through a buffer overflow in the error handling code. The thttpd port allows remote viewing of arbitrary files on the local server. The 'ssi' cgi script does not correctly restrict URL-encoded requests containing ".." in the path. The mod_php ports contain a potential vulnerablilty that may allow a remote attacker to execute arbitrary code as the user running the web server. The csh and tcsh code creates temporary files when the '<<' operator is used, however these are created insecurely and use a predictable filename based on the process ID of the shell. An attacker can exploit this vulnerability to overwrite an arbitrary file writable by the user running the shell. There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities. Patches are available now.

System: Microsoft Windows 2000, SP1
Topic: Vulnerability by Domain Account Lockout
Links: MS-089, ERS-2000.304, WinITSec
ID: ae-200011-017

A flaw in the way that NTLM authentication operates in Windows 2000 could allow a domain account lockout policy to be bypassed on a local Windows 2000 machine, even if the domain administrator had set such a policy. The ability of a malicious user to avoid the domain account lockout policy could increase the threat from a brute force password-guessing attack. This vulnerability only affects Windows 2000 machines that are members of non-Windows 2000 domains. In addition, the vulnerability only affects domain user accounts that have previously logged into the target machine and already have cached credentials established on that machine. Microsoft has published a patch

System: Open Linux
Topic: Two vulnerabilities in ghostscript
Links: CSSA-041
ID: ae-200011-016

Caldera reports about two new problems in ghostscript: temporary files are created insecurely and the program is linked in a way that makes it pick up shared libraries from the current directory it is in. Both problems can give increased privilege on the system, Patches are available.

System: Debian Linux
Topic: Vulnerabilities in modutils, tcpdump, ncurses, xmcd, cddb, joe, and ethereal
Links: Debian201120, Debian201120a, Debian201121, Debian201121a, Debian201122, Debian201122a, Debian201122c
ID: ae-200011-015

Local users to run arbitrary commands as root if the machine is running a kernel with kmod enabled. Another problem was found with giving parameters to modprobe. Tcpdump may crash by sending carefully crafted packets to a network that is being monitored with tcpdump. The version of the ncurses display library shipped with Debian GNU/Linux 2.2 is vulnerable to several buffer overflows. A buffer overflow in ncurses, linked to the "cda" binary, allows a root exploit. Two setuid helpers for accessing cddb databases and SCSI cdrom drives are vulnerable. These are xmcd and cddb. The porblem in joe concerning DEADJOE is also present in Open Linux. An attacker can exploit some overflows by sending carefully crafted packets to a network that is being monitored by ethereal. Patches are available now.

System: HP-UX
Topic: Vulnerability in EMS
Links: HP Security Bulletin #00131, ERS-2000.305
ID: ae-200011-014

A defect in the Event Monitoring System (EMS) version A.03.00 allows users to change file permissions on any file in the root partition. This affects ServiceGuard OPS edition as well as MC/ServiceGuard. It's recommended to migrate to EMS A.03.20.

System: Linux Mandrake
Topic: Vulnerabilities in gnome-media, joe, pine, and ghostscript
Links: MDKA-2000:016, MDKSA-2000:072, MDKSA-2000:073, MDKSA-2000:074
ID: ae-200011-013

A problem exists with the gmix program in the gnome-media package. When exiting joe in a non-standard way (such as a system crash, closing an xterm, or a network connection going down), joe will unconditionally append its open buffers to the file DEADJOE. This may corrupt files knowingly or unknowingly. By adding specific headers to messages, the pine mail reader could be made to exit with an error message when users attempted to manipulate mail folders containing those messages. The ghostscript package uses mktemp instead of mkstemp to create temporary files. It also uses improper LD_RUN_PATH values, which causes it to search for libraries in the current directory. Patches are available now.

System: Microsoft Windows Media Player 6.4 and 7
Topic: Vulnerabilities caused by .ASX Buffer Overrun and .WMS Script Execution
Links: MS-090, WinITSec, ERS-2000.306
ID: ae-200011-012

Two independent vulnerabilities have been found in the Windows Media Player:
1) Windows Media Player supports the use of Active Stream Redirector (.ASX) files to enable users to play streaming media that resides on intranet or Internet sites. The code that parses .ASX files has an unchecked buffer, and this could potentially enable an attacker to run code of his choice on the machine of another user. 
2) Windows Media Player 7 introduced a feature called "skins", that allows customization of the look and feel of Windows Media Player. A custom skin (.WMS) file could potentially include script, which would execute if Windows Media Player was run and that skin was selected. An attacker could either send a customized skin containing script to another user and try to entice her into using it, or he could host such a file on a web site and cause it to launch automatically whenever a user visited the site. Because the code would reside on the user's local machine, it would be able to execute ActiveX controls, including ones not marked "safe for scripting". This would enable the code to take any action that can be accomplished via an ActiveX control.
It's strongly recommended to install the patches for Windows Media Player 6.4 and Windows Media Player 7, respectively.

System: Debian Linux
Topic: Vulnerabilities in ghostscript
Links: Debian201123
ID: ae-200011-011

The way ghostscript uses temporary files is insecure: mktemp is used to create a name for a temporary file, but the file isn't opened safely. Another problem is that during build, the LD_RUN_PATH environment variable was set to the empty string, which causes the dynamic linker to look in the current directory for shared libraries. A patch is available now.

System: Red Hat Linux 5.x, 6.x, 7.0
Topic: Vulnerabilities in openssh and ghostscript
Links: RHSA-2000:111, RHSA-2000:114
ID: ae-200011-010

An OpenSSH client will do agent or X11 forwarding at the request of a server, even if the user has not requested that it be done. A malicious server can exploit this vulnerability to gain access to the user's display. ghostscript makes use of mktemp to create temp files, which is an insecure and predictable apporoach, it is now patched to use mkstemp, which avoid the race condition on the name.

System: Linux Mandrake
Topic: Vulnerabilities in modutils, userdrake, and pine
Links: MDKSA-2000:071, MDKA-2000:017, MDKSA-2000:073
ID: ae-200011-009

All 2.3.x versions of modutils (since March 12 1999) contain a vulnerability that can lead to a local root compromise. The version of userdrake has a serious problem on systems where shadow passwords are not used. By adding specific headers to messages, the pine mail reader could be made to exit with an error message when users attempted to manipulate mail folders containing those messages. Patches are available now.

System: OpenLinux
Topic: Vulnerability in bash
Links: CSSA-2000-042
ID: ae-200011-008

As Caldera reports, bash creates temp files for here scripts insecurely. This can be exploited via a symlink attack to create or write over arbitrary files on the system if the shell is run by root. A patch is available now.

System: Red Hat Linux 5.x, 6.x, 7.0
Topic: Vulnerabilities in ncurses and bash
Links: RHSA-2000:115, RHSA-2000:117, ERS-2000.307, ERS-2000.312
ID: ae-200011-007

There used to be an overflowable buffer in the part of the ncurses library handling cursor movement. The"<<" operator in bash 1.x used predictable filenames, leading to a potential denial of service attack.

System: Sun Microsystems
Topic: Vulnerability in JDK/JRE: Sun Security Bulletin
Links: #00199, ERS-2000.313, ERS-2000.315
ID: ae-200011-006

Under certain circumstances, the Java Runtime Environment may allow an untrusted Java class to call into a disallowed class - this is a  potential security issue. Patches are available now.

System: Windows NT 4.0, Windows 9x and Me
Topic: New possibility for Denial-of-Service
Links: MS-091, L-023, ERS-2000.316, WinITSec
ID: ae-200011-005

There is a denial of service vulnerability that affects Windows NT 4.0 Windows 95, 98, 98 Second Edition and Windows Me. By sending a flood of specially formed TCP/IP packets to a machine an attacker could cause either of two effects. In the most likely case, the flood would temporarily prevent any networking resources on an affected computer from responding to client requests; as soon as the packets stopped arriving, the machine would resume normal operation. In a less likely case, the system could hang, and remain unresponsive until it was rebooted. This vulnerability could only be exploited if TCP port 139 is open on the target machine. It's recommended to install a patch for Microsoft Windows NT, for the other systems a workaround has been published.

System: IBM AIX 4.2.x, 4.3.x
Topic: Vulnerabilities in BIND
Links: ERS-2000.005i, L-021
ID: ae-200011-004

The two vulnerabilities in BIND, published by ISC, affect the AIX Nameserver also. IBM has published fixes now.

System: SuSE Linux
Topic: Vulnerability in gnorpm
Links: SUSE-040
ID: ae-200011-003

Gnorpm is a graphical user interface to the rpm subsystem for the gnome desktop. The handling of temporary files is insecure, so the gnorpm package may overwrite arbitrary files on the system. A workaround and Patches are available now. 

System: Linux Mandrake
Topic: Vulnerabilities in bash1 and cups
Links: MDKSA-2000:075, MDKSA-2000:070
ID: ae-200011-002

The bash1 shell program has the same "<<" vulnerability that tcsh has and incorrectly creates temporary files. A problem exists with previous versions of CUPS that made CUPS printers accessible from anywhere on the internet. A bug also existed where CUPS would broadcast to everywhere and thus keep open dial-on-demand lines. Mandrake has published fixes now.

System:
Topic: DoS against TCP/IP Stacks
Links: CA-2000-21, S-00-55
ID: ae-200011-001

A variety of denial-of-service vulnerabilities has been explored and documented by BindView's RAZOR Security Team. These vulnerabilities allow attackers to consume limited resources on victim machines. BindView's RAZOR Security Team has referred to these vulnerabilities as Naptha vulnerabilities. Many systems are affected by these vulnerabilities - further information is pointed out in the advisory.



(c) 2000-2013 AERAsec Network Services and Security GmbH