Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-107-22-156-205.compute-1.amazonaws.com [107.22.156.205]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 12 / 2002

System: Conectiva Linux
Topic: Vulnerability in cyrus-imapd
Links: CLA-2002:557, OAR-2002:1164
ID: ae-200212-080

The Cyrus IMAP Server is an E-Mail application that uses the Internet Message Access Protocol (IMAP). It allows an user to perform certain mail functions on a remote server rather than on a local computer. A remotely exploitable pre-login buffer overflow in cyrus imapd has been found. The problem resides in the way memory is managed. It may be exploited prior to authentication to the IMAP server and could allow a remote attacker to read other users' E-Mail and to execute arbitrary code with the privileges of the user running the IMAP server. A patch to fix this problem has been published now.

System: OpenBSD
Topic: Vulnerabilities in xpdf and mhonarc
Links: OpenBSD
ID: ae-200212-079

In xpdf and mhonarc some vulnerabilities have been found. Now, OpenBSD has pulished new packages for affected clients.

System: Gentoo Linux
Topic: Vulnerabilities in cyrus-sasl, cyrus-imapd, openldap, and cups
Links: OAR-2002:1165, OAR-2002:1166, OAR-2002:1167, OAR-2002:1168
ID: ae-200212-078

Some Vulnerabilities were found in cyrus-sasl, cyrus-imapd, openldap, and cups. At least the vulnerability in openldap might lead to a remote command execution. It's recommended to download and install the updated packages.

System: Several systems
Topic: New ISS Summary
Links: AS02-52
ID: ae-200212-077

Within the last the last week 29 new vulnerabilities have been reported:

- apache-printenv-xss - melange-msgtext-chatinterpretdata-bo - oracle-ldlibrarypath-gain-privileges
- wagora-editform-file-include - wagora-editform-xss - libpng-file-offset-bo
- oracle-appserver-jsp-source - oracle-appserver-insecure-permissions - oracle-appserver-webinf-access
- dthn-worm - phpnuke-crlf-injection - ncipher-pkcs-library-insecure
- kde-quoting-command-execution - matlab-tmp-file-symlink - chetcpasswd-shadow-file-disclosure
- hyperion-long-directory-bo - kde-smbview-password-viewable - internet-junkbuster-unauth-connect
- pdftops-integer-overflow - solaris-authdes-gain-privileges - monopd-messaging-framework-bo
- proftpd-long-password-bo - ie-multimedia-url-xss - skystream-emr5000-shell-bo
- php-wordwrap-bo - gallery-winxppublishing-command-execution - web-cyradm-imap-dos
- leafnode-nntp-dos - skystream-emr5000-shell-bo
System: Debian GNU/Linux
Topic: Vulnerabilties in typespeed and bugzilla
Links: DSA-217, DSA-218, ESB-2003.001
ID: ae-200212-076

Typespeed is a game that lets you measure your typematic speed. By overflowing a buffer a local attacker might execute arbitrary commands under the group id games.
Bugzilla is a web-based bug tracking system. It doesn't properly sanitize any input submitted by users. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running Bugzilla. This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
Patches are available now.

System: Several
Topic: New version of sendmail
Links: sendmail
ID: ae-200212-075

The new version Sendmail 8.12.7 has been published now. It fixes the vulnerability in smrsh and some other bugs.

System: Microsoft Windows
Topic: New worm called Dynamic Trojan Horse Network (DTHN)
Links: ISS
ID: ae-200212-074

ISS point out that a new worm called Dynamic Trojan Horse Network (DTHN) is spreading in the Internet. DTHN propagates through E-Mail and through open NetBIOS file shares. DTHN installs itself and establishes communication to a sophisticated peer-to-peer communications network, to further spread infections and launch additional attacks. So it's recommended to upgrade your security software.

System: OpenBSD
Topic: Vulnerabilities in KDE
Links: OpenBSD
ID: ae-200212-073

In KDE recently some vulnerabilities have been found. Now, OpenBSD has pulished new packages for affected clients.

System: Debian GNU/Linux
Topic: Vulnerabilty in fetchmail
Links: DSA-216, ESB-2002.723
ID: ae-200212-072

Fetchmail is an SSL enabled POP3, APOP and IMAP mail gatherer/forwarder. When fetchmail retrieves a mail all headers that contain addresses are searched for local addresses. If a hostname is missing, fetchmail appends it but doesn't reserve enough space for it. This heap overflow can be used by remote attackers to crash it or to execute arbitrary code with the privileges of the user running fetchmail. A fixed package has been published now.

System: Gentoo Linux
Topic: Vulnerabilities in perl, canna, wget, and KDE
Links: OAR-2002:1155, OAR-2002:1156, OAR-2002:1157, OAR-2002:1161
ID: ae-200212-071

Some Vulnerabilities were found in perl, canna, wget, and KDE. It's recommended to download and install the updated packages.

System: HP-UX
Topic: Vulnerability Java
Links: HPSBUX0212-234, ESB-2002.721
ID: ae-200212-070

Sendmail Restricted Shell (smrsh) may let local users bypass restrictions to execute code, so users might execute unauthorized programs. Affected are HP 9000 Series 700 and 800 running HP-UX 11.00, 11.11, 11.22 running sendmail version 8.11.1 ONLY. Until patches are available it's recommended to download and install fixed versions of /usr/sbin/smrsh from the ftp site.

System: Several systems
Topic: Several vulnerabilities in KDE
Links: KDE, OAR-2002:1160
ID: ae-200212-069

In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution. Affected are all KDE 2 releases and all KDE 3 releases. The vulnerabilities potentially enable local or remote attackers to compromise the privacy of a vicitim's data and to execute arbitrary shell commands with the victim's privileges, such as erasing files or accessing or modifying data. All known problems have been fixed in KDE 3.0.5a.

System: SuSE Linux
Topic: Vulnerability in cyrus-imapd
Links: SuSE-2002:048, OAR-2002:1154
ID: ae-200212-068

A buffer overflow in the Cyrus IMAP server has been found. It could be exploited by a remote attacker prior to logging in. A malicious user could craft a request to run commands on the server under the UID and GID of the cyrus server. A fixed package is available now.

System: HP-UX
Topic: Vulnerability Java
Links: HPSBUX0212-235, ESB-2002.720
ID: ae-200212-067

Javasoft has issued Security Bulletin 109 concerning problems with the Java Bytecode verifier initialization. The vulnerabilities are a potential denial of Service, information leakage, or arbitrary execution of code. Affected are HP-UX versions of Java (1.1.X, 1.2.X, 1.3.X, and 1.4.X only.). A security fix has been published now.

System: Debian GNU/Linux
Topic: Vulnerabilty in cyrus-imapd
Links: DSA-215, ESB-2002.722
ID: ae-200212-066

A buffer overflow in the Cyrus IMAP server has been found. It could be exploited by a remote attacker prior to logging in. A malicious user could craft a request to run commands on the server under the UID and GID of the cyrus server. A fixed package is available now.

System: OpenBSD
Topic: Vulnerability in MySQL
Links: OpenBSD
ID: ae-200212-065

In MySQL recently a security hole has been found. Now, OpenBSD has also pulished new packages for affected clients and servers.

System: Several systems
Topic: New ISS Summary
Links: AS02-51
ID: ae-200212-064

Within the last the last week, 40 new vulnerabilities have been found:

- suse-gfxmenu-password-bypass - xoops-pmlite-view-messages - weblogic-xerces-parser-dos
- micq-0xfe-dos - phpnuke-path-disclosure - phpnuke-variable-multiple-xss
- ssh-transport-length-bo - ssh-transport-empty-lists-bo - ssh-transport-multiple-bo
- ssh-transport-null-string-bo - sybase-easerver-xmlparser-dos - cryptainer-plaintext-password
- phpnuke-html-xss - infinite-webmail-logger-xss - zkfingerd-putlog-format-string
- zkfingerd-say-format-string - pfinger-log-format-string - coldfusion-app-log-xss
- archive-tar-directory-traversal - goahead-script-source-disclosure - community-wizard-sql-injection
- linux-protread-mmap-dos - winamp-mp3-artist-bo - winamp-mp3-medialibrary-bo
- winxp-windows-shell-bo - cisco-ios-eigrp-dos - open-webmail-command-execution
- wanewsletter-php-file-include - cups-multiple-int-overflow - cups-certs-race-condition
- cups-udp-add-printers - cups-neg-memcpy-bo - cups-strncat-options-bo
- cups-zero-width-images - cups-file-descriptor-dos - viewstation-asecurity-plaintext-passwords
- helix-rtsp-setup-bo - helix-rtsp-describe-bo - helix-http-get-bo
- axis-http-auth-bo
System: SuSE Linux
Topic: Vulnerabilities in mysql and cups
Links: SuSE-8.0, SuSE-8.1
ID: ae-200212-063

Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient.
Another vulnerability has been found in cups. It might lead to local or remote root-access.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilties in kdenetwork
Links: DSA-214, ESB-2002.719
ID: ae-200212-062

KDE lanbrowsing service LISa is used to identify CIFS and other servers on the local network, and consists of two main modules: "lisa", a network daemon, and "reslisa", a restricted version of the lisa daemon. One vulnerability found is a buffer overflow in the lisa daemon. It can be exploited by an attacker on the local network to obtain root privilege on a machine running the lisa daemon. Another vulnerability is a buffer overflow in the rlan:// URL handler. It can possibly be exploited by remote attackers to gain access to the victim user's account, for instance by causing the user to follow a bad rlan:// link in a HTML document. Fixed packages are available now.

System: Cisco IOS
Topic: Vulnerability in ssh
Links: Cisco, ESB-2002.718, ae-200212-044
ID: ae-200212-061

Several Cisco products are vulnerable to a Denial of Service (DoS) if the SSH server is enabled on the device. A malformed SSH packet directed at the affected device can cause a reload of the device. Patches are not available yet.

System: Conectiva Linux
Topic: Vulnerabilities in openldap
Links: OAR-2002:1144
ID: ae-200212-060

Several buffer overflows were found in both the OpenLDAP server and in the libraries provided with the OpenLDAP package. Some of these vulnerabilities can be exploited by attackers remotely or locally to compromise the OpenLDAP server or applications linked against the vulnerable libraries. Patches are available now.

System: Trustix Linux
Topic: Vulnerabilities in mysql, wget, lynx-ssl, perl, tcpdump, and kernel
Links: OAR-2002:1145, OAR-2002:1146, OAR-2002:1147, OAR-2002:1148, OAR-2002:1149, OAR-2002:1150
ID: ae-200212-059

Vulnerabilities were found in the packages mysql, wget, lynx-ssl, perl, tcpdump, and kernel. Fixed packages are available now.

System: SCO OpenLinux
Topic: Vulnerability in BIND
Links: CSSA-2002-059, OAR-2002:1151
ID: ae-200212-058

Multiple vulnerabilities have been found in BIND (Berkeley Internet Name Domain). Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilty in libpng
Links: DSA-213, ESB-2002.710
ID: ae-200212-057

In libpng the starting offsets for the loops are calculated incorrectly which causes a buffer overrun beyond the beginning of the row buffer. Fixed packages are available now.

System: Conectiva Linux
Topic: Vulnerabilities in mysql
Links: OAR-2002:1136
ID: ae-200212-056

Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient. So also PHP is affected by these problems.
Fixed packages of MySQL solve these problems.

System: HP-UX
Topic: Vulnerabilities in bind and smrsh
Links: N-030, ESB-2002.712, ESB-2002.714, ESB-2002.715
ID: ae-200212-055

Potential buffer overflows were found in the DNS resolver libraries.
Sendmail Restricted Shell (smrsh) may let local users bypass restrictions to execute code.
Patches are available now.

System: Microsoft Windows XP
Topic: Vulnerability in Windows Shell
Links: MS02-072, ESB-2002:709, S-02-118, VU#591890, CA-2002-37, N-029, WinITSec
ID: ae-200212-054

No further comment due to Microsoft insisting on their copyright on advisories.

System: Mandrake Linux
Topic: Vulnerabilities in apache and mysql
Links: MDKSA-2002:068-1, MDKSA-2002:087, OAR-2002:1140, OAR-2002:1141
ID: ae-200212-053

New apache packagees are available for Mandrake Single Network Firewall 7.2.
Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient. So also PHP is affected by these problems. Patches are available now.

System: Conectiva Linux
Topic: Vulnerabilities in kernel and fetchmail
Links: OAR-2002:1131, OAR-2002:1132
ID: ae-200212-052

The linux kernel is vulnerable to a local Denial-of-Service attack. Local users with non-root rights can cause the machine to freeze.
A vulnerability allows a remote attacker to crash Fetchmail and potentially execute arbitrary code by sending a carefully crafted email which is then parsed by Fetchmail.
Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilty in mysql
Links: DSA-212, ESB-2002.706
ID: ae-200212-051

Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient. So also PHP is affected by these problems.
Fixed packages of MySQL solve these problems.

System: Gentoo Linux
Topic: Vulnerabilities in mysql, fetchmail, squirrelmail, and exim
Links: OAR-2002:1123, OAR-2002:1124, OAR-2002:1125, OAR-2002:1126
ID: ae-200212-050

Vulnerabilities were found in mysql, fetchmail, squirrelmail, and exim. Updated packages are available now.

System: Macromedia
Topic: Vulnereability in Flash Player
Links: MPSB02-15, ESB-2002:703, S-02-117
ID: ae-200212-049

There exists a vulnerability within Macromedia's Flash software and its handling of malformed Flash files. Attackers can use this vulnerability to compromise users of Macromedia's Flash software. A corrupt file may be placed on a website or in some cases within an HTML email. Patches are available now.

System: Red Hat Linux
Topic: Vulnerabilities in fetchmail and Net-SNMP
Links: RHSA-2002-293, RHSA-2002-228, ESB-2002.707, ESB-2002.708
ID: ae-200212-048

This bug allows a remote attacker to crash Fetchmail and potentially execute arbitrary code by sending a carefully crafted email which is then parsed by Fetchmail.
The SNMP daemon included in the Net-SNMP package can be caused to crash if it is sent a specially crafted packet. Successful exploitation of this issue would require knowledge of a known SNMP community string.
Updated packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS02-50
ID: ae-200212-047

Within the last the last week, 60 new vulnerabilities have been found:

- linksys-etherfast-stack-bo - linksys-etherfast-heap-bo - canna-irwthrough-bo
- canna-improper-request-validation - ie-dialog-style-access - netscape-enterprise-log-script
- kismac-installer-overwrite-permissions - akfingerd-connect-dos - akfingerd-plan-symlink-dos
- akfingerd-read-files - fortres-101-bypass-restrictions - openldap-multiple-bo
- gnuplot-french-documentation-bo - wuimapd-authenticated-user-bo - xoops-html-attribute-xss
- vbulletin-forum-msg-xss - ikonboard-html-photo-xss - ikonboard-xforwardedfor-header-xss
- enceladus-cd-bo - cyrus-sasl-username-bo - cyrus-sasl-saslauthd-bo
- cyrus-sasl-logwriter-bo - pccillin-pop3trap-bo - apt-www-proxy-format-string
- apt-www-proxy-dos - tftp32-dos-device-dos - kunani-dotdot-directory-traversal
- wget-ftp-filename-traversal - ftp-client-filename-traversal - proxyserver-mtpsr1120-telnet-access
- cisco-catalyst-osm-dos - coldfusion-jrun-soap-dos - myserver-dotdot-directory-traversal
- msvm-jdbc-gain-access - vim-modeline-command-execution - hp-xnptd-dos
- hp-vizualizeconf-insecure-permissions - win-smb-policy-modification - visnetic-website-url-dos
- mysql-comtabledump-dos - mysql-comchangeuser-password-bypass - mysql-comchangeuser-password-bo
- mysql-libmysqlclient-readrows-bo - mysql-libmysqlclient-readonerow-bo - wget-url-filename-bo
- visnetic-website-referer-xss - mambo-phpinfo-disclose-path - mambo-search-xss
- mambo-character-account-locked - mambo-index-path-disclosure - mambo-default-admin-password
- mambo-phpmyadmin-gain-access - mambo-name-field-xss - iasp-dotdot-directory-traversal
- flash-swf-bo - webshots-desktop-screenlock-bypass - eserv-helo-bo
- fetchmail-address-header-bo - sef-realaudio-proxy-bo - myphplinks-index-sql-injection
System: IBM AIX
Topic: Vulnerabilities in AutoFS and dump_smutil.sh
Links: OAR-2002:1116, OAR-2002:1117
ID: ae-200212-046

A vulnerability has been found that allows a malicious user to execute arbitrary code with root privileges when AutoFS is used in conjunction with name-to-location executable maps.
The shell script dump_smutil.sh creates a temporary file in /tmp in an insecure way.
Patches are available now.

System: Conectiva Linux
Topic: Vulnerability in wget
Links: OAR-2002:1122
ID: ae-200212-045

A buffer overrun was found in the url_filename function of wget. In addition wget does not verify the FTP server response to a NLST command. A patch is available now.

System: Various systems
Topic: Vulnerabilities in Various SSH Implementations
Links: CA-2002-36, VU#389665, ESB-2002.705, N-028, S-02-116
ID: ae-200212-044

A number of vulnerabilities has been found in different vendors' SSH products. These vulnerabilities include buffer overflows, and they occur before user authentication takes place. Affected by these vulnerabilities are SSH products of following vendors: F-Secure, Intersoft International Inc., Pragma Systems, PuTTY, and SSH Communications Security. Details can be found in the advisories.

System: Various
Topic: Vulnerabilities in MySQL
Links: e-matters2002-04, S-02-115
ID: ae-200212-043

Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient. So also PHP is affected by these problems.
Fixed packages of MySQL solve these problems.

System: EnGarde Secure Linux
Topic: Vulnerabilities in MySQL and PHP
Links: e-matters2002-04, ESA-20021213-033, OAR-2002:1120
ID: ae-200212-042

Two flaws in the MySQL server can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. An arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address have been found. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient. So also PHP is affected by these problems.
Fixed packages of MySQL solve these problems.

System: Debian GNU/Linux
Topic: Vulnerabilty in micq
Links: DSA-211, ESB-2002.704
ID: ae-200212-041

The text based ICQ client mICQ shows a problem when receiving certain ICQ messages: Under certain circumstances all versions crash. This problem has been fixed with a new package.

System: SGI IRIX
Topic: Vulnerability in FTP client
Links: SGI#20021205-01, OAR-2002:1121
ID: ae-200212-040

As reported in VU#210409, some ftp clients contain directory traversal vulnerabilities that allow a malicious FTP server to overwrite files on the client host. Currently, SGI is investigating about the problem and will not give further information at the moment.

System: SuSE Linux
Topic: Vulnerabilities in htdig and libldap
Links: SuSE-8.0, SuSE-8.1
ID: ae-200212-039

In htdig the command line parameters might lead to security related problems, when htdig is executed as a cgi-program at a Web-Server.
Additionally, for libldap a security update has been published. It's necessary, if LDAP client applications use setuid. Other vulnerabilities in the man-pages for ldapmodify and ldapadd as well as a bug in the group-ACLs have been corrected, too.

System: OpenBSD
Topic: Vulnerabilities in w3m, fetchmail, and cyrus-sasl
Links: OpenBSD
ID: ae-200212-038

In the packets mentioned some security related problems have been found, including a buffer overflow. Source code patches have been published to solve these problems.

System: Red Hat Linux
Topic: Vulnerabilities in apache
Links: RHSA-2002-222, ESB-2002:696
ID: ae-200212-037

The permissions of the shared memory used for the scoreboard allows an attacker who can execute under the Apache UID to send a signal to any process as root or cause a local denial of service attack.
Cross-site scripting (XSS) vulnerability in the default error page, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header.
Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilties in perl, wget, and lynx
Links: DSA-208, DSA-209, DSA-210, ESB-2002.700, ESB-2002.701, ESB-2002.702
ID: ae-200212-036

The Safe extension module allows the creation of compartments in which perl code can be evaluated in a new namespace and the code evaluated in the compartment cannot refer to variables outside this namespace. However, when a Safe compartment has already been used, there's no guarantee that it is Safe any longer.
A buffer overrun was found in the url_filename function of wget. In addition wget does not verify the FTP server response to a NLST command.
lynx does not properly check for illegal characters in all places, including processing of command line options, which could be used to insert extra HTTP headers in a request.
Fixed packages are now available.

System: Sun Cobalt RaQ 4
Topic: Vulnerability in Security Hardening Package (SHP)
Links: Sun, ESB-2002:688, VU#810921, CA-2002-35, N-025, Symantec
ID: ae-200212-035

A remotely exploitable vulnerability has been discovered in Sun Cobalt RaQ 4 Server Appliances running Sun's Security Hardening Package (SHP). Exploitation of this vulnerability may allow remote attackers to execute arbitrary code with superuser privileges.
A fixed package is available now.

System: HP TruCluster Server
Topic: Vulnerability in Internode Communication System (ICS)
Links: OAR-2002:1099
ID: ae-200212-034

A potential security vulnerability has been discovered in the Internode Communication System (ICS) that may result in a denial of service (DoS) on HP TruCluster Server systems. This potential security vulnerability may be in the form of local and remote security domain risks.
Patches are available now.

System: HP-UX
Topic: Vulnerabilities in ntpd, Visualize Conference and Samba
Links: ESB-2002:691, ESB-2002:692, ESB-2002:693, N-023
ID: ae-200212-033

The ntpd of the xntpd software may hang or exhibit extremely poor performance, this can lead to a potential denial-of-service.
The already known potential remote root access in Samba exists also in the version of HP.
The installation of HP-UX Visualize Conference leaves certain directories with insecure permissions. This can lead to a potential increase in privileges or unauthorized access.
Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilty in tetex-bin
Links: DSA-207, OAR-2002:1104
ID: ae-200212-032

A vulnerability was discovered in kpathsea library (libkpathsea) which is used by xdvi and dvips. Both programs call the system() function insecurely, which allows a remote attacker to execute arbitrary commands via cleverly crafted DVI files.
Fixed packages are now available.

System: Macromedia
Topic: Problems with JRun and ColdFusion MX
Links: MPSB02-14, ESB-2002:694
ID: ae-200212-031

Web services in JRun 4.0 and ColdFusion MX products are vulnerable to a denial of service attack by passing incorrectly formed messages to the SOAP interfaces exposed by ColdFusion MX and JRun. Both products use an XML parser (either Crimson or Xerces) that can be made to run in an almost infinite loop with this specially formed message - exhausting CPU resources.
Patches are available now.

System: SCO Open UNIX, UnixWare
Topic: Vulnerability in uudecode
Links: CSSA-2002-SCO.44, ae-200204-033, OAR-2002:1105
ID: ae-200212-030

As longer known, older versions of uudecode didn't check whether output file is a link or a named pipe.
SCO now provides updated packages.

System: Cisco Catalyst 6500 & Router 7600
Topic: Vulnerability in OSM Line Card
Links: Cisco, ESB-2002:689, S-02-114
ID: ae-200212-029

The Optical Service Module (OSM) Line Cards installed in Catalyst 6500 or Cisco 7600 chassis, and running Cisco IOS® Software Version 12.1(8)E and higher are vulnerable to a Denial of Service upon receiving a specifically constructed or corrupted packet from the local network.
New software releases which fixes this issue are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Java VM, SMB Signing and WM_TIMER Message Handling
Links: MS02-069, MS02-070, MS02-071, S-02-113, ESB-2002.697, ESB-2002.698, ESB-2002.699, N-026, N-027, WinITSec, WinITSec, WinITSec
ID: ae-200212-028

No further comment due to Microsoft insisting on their copyright on advisories.

System: Mandrake Linux
Topic: Vulnerability in wget
Links: MDKSA-2002:086, ae-200212-023, OAR-2002:1108
ID: ae-200212-027

For the already known vulnerability of wget Mandrake now provides updated packages.

System: Debian GNU/Linux
Topic: Vulnerabilites in gtetrinet and tcpdump
Links: DSA-205, DSA-206, ESB-2002:685
ID: ae-200212-026

Several buffer overflows were found in the gtetrinet (a multiplayer tetris-like game) package which could be abused by a malicious server.
The BGP decoding routines for tcpdump used incorrect bounds checking when copying data. This could be abused by introducing malicious traffic on a sniffed network for a denial of service attack against tcpdump, or possibly even remote code execution.
Updated packages are available now.

System: HP-UX
Topic: Vulnerability in tomcat
Links: ESB-2002:686
ID: ae-200212-025

A security vulnerability in Tomcat 4.0.X versions prior to version 4.0.6 leads to potential unauthorized source code listing.
HP recommends upgrading to 4.0.6 or above or apply a workaround.

System: SCO OpenLinux
Topic: Vulnerability in nss_ldap
Links: CSSA-2002-058, OAR-2002:1098
ID: ae-200212-024

A buffer overflow in the DNS SRV code for nss_ldap allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Updated packages are available now.

System: Red Hat Linux
Topic: Vulnerabilities in wget and Canna
Links: RHSA-2002-229, RHSA-2002-246, VU#210148, ESB-2002:687, ESB-2002:695, N-022
ID: ae-200212-023

The wget packages shipped with Red Hat Linux 6.2 through 8.0 contain a security bug which, under certain circumstances, can cause local files to be written outside the download directory.
The Canna server, used for Japanese character input, has two security vulnerabilities including an exploitable buffer overrun allowing a local user to gain 'bin' user privileges.
New packages are now available.

System: Several systems
Topic: New ISS Summary
Links: AS02-49
ID: ae-200212-022

Within the last the last week, 45 new vulnerabilities have been found:

- aix-vmm-gain-privileges - openwindows-mailtool-dos - portailphp-modsearch-sql-injection
- portailphp-modsearch-index-xss - aldap-bind-manager-access - winxp-fus-processes-disclosure
- virusscan-webscanx-dll-execution - boozt-parameter-indexcgi-bo - etrust-inoculateit-protection-bypass
- pserv-data-stream-bo - yabb-xphp-xss - thatware-php-file-include
- 3com-nbx-cel-bo - lawson-financials-insecure-authentication - cyrus-sieve-header-bo
- cyrus-imap-preauth-bo - ipd-change-system-clock - shopfactory-price-modification
- squirrelmail-readbody-xss - thatware-authinc-sql-injection - etrust-inoculateit-exchange-bypass
- cyrus-sieve-imap-bo - cyrus-sieve-script-bo - airstation-wlarl11gl-httpget-dos
- linux-netfilter-obtain-information - im-impwagent-insecure-directory - im-immknmz-symlink
- solaris-null-pointer-dos - phpbb-search-username-xss - sendmail-check-relay-bypass
- hp-ied-information-disclosure - bigfun-irc-dcc-dos - exim-daemonc-format-string
- sap-db-lserversrv-symlink - outlook-email-header-dos - winxp-wireless-information-leak
- sygate-firewall-insecure-shutdown - smb2www-command-execution - tomcat-modjk-get-bo
- cobalt-shp-request-bo - webreflex-dotdot-directory-traversal - apboard-useraction-information-disclosure
- upb-viewtopic-xss - upb-viewtopic-path-disclosure - upb-add-path-disclosure
System: SCO Open UNIX, UnixWare
Topic: closed file descriptor race vulnerability
Links: CSSA-2002-SCO.43, OAR-2002:1091
ID: ae-200212-021

SCO implements now in UnixWare a fix to close file descriptors 0, 1 and/or 2 before executing a setuid program.

System: SCO OpenLinux
Topic: Vulnerability in groff pic
Links: CSSA-2002-057, OAR-2002:1089
ID: ae-200212-020

In handling arguments, groff pic has a buffer overrun. The problem could be remotely exploited depending on the lpd setup. A new package fixes this problem.

System: IBM AIX
Topic: Vulnerability in IPSec
Links: OAR-2002:1075, ae-200212-002
ID: ae-200212-019

Similar to FreeS/WAN the IPSec implementation of IBM does not properly handle certain very short packets. This may lead to Denial-of-Service attacks. Fixed packages are available now.

System: HP-UX
Topic: Vulnerabilities in ied and X Font Server
Links: ESB-2002:673, ESB-2002:674
ID: ae-200212-018

The command ied(1) has the capability for a potential unauthorized data access.
The X Font Server contains the already known remote exploitable buffer overflow.
Patches are available now.

System: SUN Solaris
Topic: Vulnerabilities in BIND & libresolv, Java/zlib, X Font Server, mailtool, priocntl System Call
Links: Sun Alert ID48818, Sun Alert ID48761, Sun Alert ID48879, Sun Alert ID48216, Sun Alert ID49131, Sun Alert ID48267, VU#683673
ID: ae-200212-017

SUN has published several new patches for Solaris. Details can be found in the advisories.

System: SCO OpenLinux
Topic: Vulnerabilities in ypserv, glibc, apache
Links: CSSA-2002-054, CSSA-2002-055, CSSA-2002-056, OAR-2002:1076, OAR-2002:1080, OAR-2002:1088
ID: ae-200212-016

For the already some time ago vulnerabilities found in
- Apache webserver (DoS by sending SIGUSR1, XSS and Buffer overflow in ApacheBench)
- exloitable memory leak in ypserv
- RPC XDR buffer overflow in glibc
SCO now provides updated packages.

System: SGI IRIX
Topic: Vulnerabilites in Samba, X Font Server, BIND
Links: SGI#20021201-01, SGI#20021202-01, SGI#20021203-01, SGI#20021204-01, ae-200211-031, ae-200211-057, ae-200211-076, ESB-2002:678, ESB-2002:679, ESB-2002:680, ESB-2002:681
ID: ae-200212-015

For already known vulnerabilities:
- in Samba SGI recommends to install version 2.2.7 from the original Samba site.
- in X Font Service (xfs) SGI recommends to upgrade to IRIX 6.5.14 or newer.
- in BIND SGI recommends to apply a patch or upgrade to IRIX 6.5.19 or newer.

Also SGI currently investigates the BIND Name Server DNS Spoofing Vulnerability.

System: Debian GNU/Linux
Topic: Vulnerability in kdelibs
Links: DSA-204, ae-200211-038, ESB-2002:682,
ID: ae-200212-014

For the already known security problems in KDE (KIO) Debian has now released updated packages.

System: Microsoft Windows
Topic: Vulnerability in Internet Explorer
Links: MS02-068, ESB-2002:677, WinITSec, N-021, VU#162097
ID: ae-200212-013

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Outlook 2002
Topic: Vulnerability in E-mail Header Processing
Links: MS02-067, ESB-2002:676, WinITSec
ID: ae-200212-012

No further comment due to Microsoft insisting on their copyright on advisories.

System: SuSE Linux
Topic: Vulnerabilities in OpenLDAP
Links: SuSE-2002:047, OAR-2002:1087
ID: ae-200212-011

OpenLDAP is the Open Source implementation of the Lightweight Directory Access Protocol (LDAP) and is used in network environments for distributing certain information such as X.509 certificates or login information. Some buffer overflows and other bugs were found in the openldap server and in the openldap client libraries, so remote attackers might get access to a vulnerable system. Because there is no workaround but shutting down the server, it's strongly recommended to install fixed packages which have been published now.

System: Debian GNU/Linux
Topic: Vulnerability in smb2www
Links: DSA-203, ESB-2002:670
ID: ae-200212-010

A security problem in smb2www could lead a remote attacker to execute arbitrary programs under the user id www-data on the host where smb2www is running. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerabilities in KDE
Links: RHSA-2002-220, ESB-2002:672, N-020
ID: ae-200212-009

A number of vulnerabilities have been found that affect various versions of KDE. New packages are now available.

System: Several Linux/Unix systems
Topic: Vulnerability in Sendmail on Relay-Check
Links: Sendmail
ID: ae-200212-008

Access restrictions imposed via check_relay for IP addresses can be circumvented using bogus DNS data, patches for 8.12 and 8.9 are available now. Upcoming version 8.12.7 will contain a patch for this. If you use FEATURE(`delay_checks') then you don't need a patch.

System: IBM AIX
Topic: Vulnerabilities in CDE DtSvc and DNS Resolver
Links: OAR-2002:1059, OAR-2002:1060, OAR-2002:1061, OAR-2002:1062
ID: ae-200212-007

Several updates are available now for:

Buffer Overflow Vulnerability in DNS Resolver Libraries (AIX 4.3.3)
(Malicious user may cause denial of service or could gain root privileges)

Buffer Overflow vulnerability in CDE DtSvc Library (AIX 4.3.3 and 5.1.0)
(Malicious user can obtain elevated privileges)

In addition some recalled Security APARs for AIX 4.3.3 are reinstated, fixing several vulnerabilities.

System: Several Linux/Unix systems
Topic: Vulnerability in Cyrus IMAP server
Links: VU#740169, Cyrus
ID: ae-200212-006

A buffer overflow vulnerability exists in versions of Cyrus IMAP Server up to and including 2.1.10. This vulnerability may allow a remote attacker to execute arbitrary code on the mail server with the privileges of the Cyrus IMAP Server.
Official Updates have not been released. This issue will be resolved in version 2.1.11 and 2.0.17.
Note that version 1.x are no longer supported and should be replaced with 2.0.17 (if available).

System: Debian GNU/Linux
Topic: Vulnerability in IM
Links: DSA-202, ESB-2002:669
ID: ae-200212-005

IM, containing interface commands and Perl libraries for E-Mail and NetNews, creates temporary files insecurely.
Fixed packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS02-47
ID: ae-200212-004

Within the last the last week, 40 new vulnerabilities have been found:

- iplanet-admin-log-xss - iplanet-perl-command-execution - bind-rr-dns-spoofing
- tcpdump-sizeof-memory-corruption - openbsd-syslogd-incorrect-reporting - symantec-jit-bypass-security
- java-bytecode-verifier-bypass - netscape-java-insecure-classes - vbulletin-member2-perpage-xss
- badblue-soinfo-odbc-passwords - badblue-extdll-library-xss - calisto-dos
- phpnuke-fetch-xss - pserv-post-request-dos - solaris-fsauto-execute-code
- webservercreator-php-file-include - phpbb-forum-msg-xss - netscreen-fragmented-url-bypass
- netscreen-h323-dos - immobilier-agentadmin-sql-injection - ssh-setsid-privilege-elevation
- ssh-client-url-bo - wsmp3-multiple-bo - netscape-applet-canconvert-bo
- bugzilla-quips-xss - freenews-php-file-include - newsevolution-php-file-include
- sybase-xpfreedll-dll-bo - libcgi-libcgih-changevalue-bo - solaris-priocntl-pcclname-modules
- imagefolio-imagefolio-nphbuild-xss - sybase-drop-database-bo - sybase-dbcc-checkverify-bo
- pwins-dotdot-directory-traversal - libcgi-cgilibc-parsefield-bo - netsuite-post-contentlength-bo
- bogofilter-bogopass-symlink - webster-url-bo - webster-dotdot-directory-traversal
- webster-path-name-xss
System: Mandrake Linux
Topic: Vulnerabilities in pine and windowmaker
Links: MDKSA-2002:084, MDKSA-2002:085
ID: ae-200212-003

A buffer overflow when parsing certain "From:" addresses was found in pine. A malicious user could send a message with a specially crafted "From:" address and cause a segmentation fault on the client.
The function RCreateImage from WindowMaker shows a buffer overflow. So remote attackers might execute arbitrary code with the rights of the user having startet WindowManager.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in FreeS/WAN
Links: DSA-201, ESB-2002:667
ID: ae-200212-002

FreeS/WAN does not properly handle certain very short packets. This may lead to Denial-of-Service attacks. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in xinetd
Links: RHSA-2002-196, ESB-2002:668
ID: ae-200212-001

A denial-of-service (DoS) vulnerability was found in xinetd. New packages are now available.



(c) 2000-2013 AERAsec Network Services and Security GmbH