Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-72-44-48-122.compute-1.amazonaws.com [72.44.48.122]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 07 / 2003

System: Sun Solaris
Topic: Vulnerability in ld.so
Links: ESB-2003.0523, N-131
ID: ae-200307-087

An unprivileged local user may be able to gain unauthorized root privileges due to a buffer overflow in the runtime linker ld.so.1(1). Patches are available now.

System: Various
Topic: Vulnerability in konqueror
Links: RHSA-2003-235, RHSA-2003-236, ESB-2003.0559, TLSA-2003-45, MDKSA-2003:079, DSA-361, ESB-2003.0537
ID: ae-200307-086

Konqueror may inadvertently send authentication credentials to websites other than the intended website in clear text via the HTTP-referer header. This can occur when authentication credentials are passed as part of a URL in the form http://user:password@host/
Fixed KDE packages are available now.

System: Debian Linux
Topic: Vulnerabilities in xconq, gallery, and xtokkaetama
Links: DSA-354, DSA-355, DSA-356, OAR-2003.0961, OAR-2003.0961, OAR-2003:0970
ID: ae-200307-085

Buffer overflows were found in the games xconq and xtokkaetama.
A a cross site scripting vulnerability was discovered in gallery.
Fixed packages are available now.

System: SGI IRIX
Topic: Vulnerabilities in nsd
Links: SGI-20030704-01, ESB-2003.0522, N-130
ID: ae-200307-084

It's been reported that the IRIX name services daemon "nsd" can be exploited in various ways through the AUTH_UNIX gid list. This could result in an attacker gaining root access. Patches are available now.

System: Red Hat Linux
Topic: Vulnerability in OpenSSH
Links: RHSA-2003-222, ESB-2003.0521
ID: ae-200307-083

When configured to allow password-based or challenge-response authentication, sshd (the OpenSSH server) uses PAM (Pluggable Authentication Modules) to verify the user's password. Under certain conditions, OpenSSH rejects an invalid authentication attempt without first attempting authentication using PAM. The amount of time sshd takes to reject an invalid authentication request varies widely enough that the timing variations could be used to deduce whether or not an account with a specified name existed on the server. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerability in sup
Links: DSA-353, ESB-2003:0520
ID: ae-200307-082

sup, a package used to maintain collections of files in identical versions across machines, fails to take appropriate security precautions when creating temporary files. A local attacker could exploit this vulnerability to overwrite arbitrary files with the privileges of the user running sup. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in Samba
Links: Sun Alert ID 53581, ESB-2003.0524
ID: ae-200307-081

The Samba version that is shipped with Solaris 9 is vulnerable to buffer overflows that are known for some time (march, april) Patches are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-30
ID: ae-200307-080

Within the last the last week 57 new vulnerabilities have been reported:

- kerberos-incorrect-etype-info2 - mssql-lpc-bo - pafiledb-upload-command-execution
- php-multiple-safemode-bypass - messagefoundry-editprofile-change-password - macos-workgroup-gain-access
- netterm-ftp-dos - surfcontrol-rulesengine-bypass-filter - linux-serial-obtain-information
- fdclone-tmpdirectory-gain-access - atomicboard-dotdot-directory-traversal - mssql-named-pipe-dos
- atomicboard-error-path-disclosure - linux-stp-modify-topology - win-rpc-dcom-dos
- winnt-file-management-dos - operam2-bypass-external-embeds - vmware-environment-code-execution
- serverlock-physicalmemory-symlink - oracle-aolj-obtain-information - mediaplayer-asf-code-execution
- netware-enterprise-perl-bo - quicktime-hexadecimal-source-disclosure - quicktime-darwin-set-password
- quicktime-darwin-device-dos - drupal-xss - iis-admin-password-reset
- linux-forwarding-table-spoof - iis-admin-session-id - linux-execve-race-condition
- linux-reuse-gain-access - merge-display-gain-access - ms-directx-midi-bo
- gopherd-docommand-bo - pblang-message-xss - quicktime-darwin-source-disclosure
- messagefoundry-name-xss - xavi-get-bo - gästebuch pwd file password disclosure
- solaris-plaintext-proxy-password - guanxicrm-php-file-include - cftp-home-bo
- cgi-startform-xss - hp-laserjet-admin-xss - oracle-extrproc-bo
- apache-modproxy-mail-relay - winxp-odbc-password-plaintext - quicktime-darwin-dotdot-dos
- hp-laserjet-gain-access - oracle-fndwrr-bo - gnupg-setgid-overwrite-files
- exchange-owa-outlook-dos - quicktime-darwin-directory-traversal - messagefoundry-mf-plaintext-password
- ashnews-multiple-file-include - quicktime-darwin-viewbroadcast-dos - solaris-ipv6-packet-dos
System: HP-UX
Topic: Vulnerabilities in patches
Links: HPSBUX0307-270, OAR-2003.0951
ID: ae-200307-079

Two patches for HP-UX, PHNE_26413 and PHNE_27128, introduce the potential for local Denial-of-Service attacks. The solution is to remove these patches.

System: Conectiva Linux
Topic: Vulnerability in mnogosearch
Links: CLA-2003:711, OAR-2003.0955
ID: ae-200307-078

Buffer overflow vulnerabilities involving the variable "ul" and "q" were found in mnoGoSearch which can be exploited remotely to execute arbitrary commands with the privileges of the webserver. Patches are available now.

System: Cisco Aironet AP1x00 Series Wireless Devices
Topic: Vulnerability in Cisco IOS
Links: Cisco, ESB-2003.0519, WinITSec
ID: ae-200307-077

It is possible to cause Cisco Aironet Access Point to crash and reboot if the HTTP server feature is enabled. This can be accomplished by submitting a specially crafted request to the web server. There is no need to authenticate to perform this attack, only access to the web server is required. Only IOS based, not VxWorks based, Cisco Aironet Wireless Devices are affected. Fixed IOS software is available now.

System: SuSE Linux
Topic: Vulnerability in kopete
Links: SuSE 8.2
ID: ae-200307-076

The GnuPG plugin in kopete allows remote attackers to execute arbitrary commands in the client context by sending specially crafted messages to it. It's recommended to install this new patch.

System: Conectiva Linux
Topic: Vulnerability in Apache 1.3
Links: CLA-2003:704, OAR-2003.0947
ID: ae-200307-075

It is possible to make the apache httpd server enter infinite loops and crash under certain circumstances.
Leaks of several file descriptors to child processes, such as CGI scripts, were found in apache.
Patches are available now.

System: EnGarde Secure Linux
Topic: Vulnerabilities in kernel
Links: OAR-2003.0946
ID: ae-200307-074

Several security issues have been discovered affecting the Linux kernel that involve the execve() system call, the /proc Filesystem, the TTY layer, and the mxcsr code. Fixed kernel are available now.

System: Red Hat Linux
Topic: Vulnerability in stunnel
Links: RHSA-2003-221, RHSA-2003-223, OAR-2003.0948, OAR-2003.0949
ID: ae-200307-073

If Stunnel is configured to start a new child process to handle each connection, it will receive a SIGCHLD signal when that child exits. Stunnel would perform tasks in the SIGCHLD signal handler which, if interrupted by another SIGCHLD signal, could be unsafe. This could lead to a denial of service. Fixed packages are available now.

System: Oracle
Topic: Vulnerabilities in Database Server and E-Business Suite
Links: OracleAlert#55, OracleAlert#56, OracleAlert#57, N-127, N-128, N-129, ESB-2003.0515, ESB-2003.0516
ID: ae-200307-072

Potential security vulnerabilities have been discovered in the EXTPROC executable of the Oracle Database. An attacker might be able to execute arbitrary code against the Oracle database by exploiting buffer overflows in this executable. Affected are Oracle 8i and Oracle 9i as well.
Two vulnerabilities have been discovered in the Oracle E-Business Suite. The program FNDWRR CGI is vulnerable to malformed request, so potential attackers might cause the FNDWRR executable to crash. This doesn't lead to a Denial-of-Service, but it may grant a user unauthorized access to Oracle E-Business Suite. As another vulnerability, a set of JSPs allows users to view product configuration and host system diagnostic information without authentication. Affected are Oracle E-Business Suite 11i and all releases of Oracle Applications.
Patches are available and should be installed soon.

System: Red Hat Linux
Topic: Vulnerability in semi
Links: RHSA-2003-234, OAR-2003.0935
ID: ae-200307-071

Race conditions due to insecure temporary file creation were found in packages 'semi' (a MIME library for GNU Emacs). Fixed packages are available now.

System: Microsoft Windows NT, 2000, XP, Server 2003
Topic: Vulnerabilities in Microsoft SQL Server
Links: MS03-031, atstake, atstake, ESB-2003.0511, N-125, VU#584868, VU#556356, WinITSec
ID: ae-200307-070

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows
Topic: Vulnerability in DirectX
Links: MS03-030, CA-2003-18, ESB-2003.0509, N-126, VU#561284, WinITSec, ESB-2003.0585
ID: ae-200307-069

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows NT 4.0 Server, Terminal Server Edition
Topic: Vulnerability in file management function
Links: MS03-029, atstake, ESB-2003.0510 WinITSec, ESB-2003.0564
ID: ae-200307-068

No further comment due to Microsoft insisting on their copyright on advisories.

System: SuSE Linux
Topic: Vulnerabilities in wget and freeradius
Links: SuSE 8.2, SuSE 8.1
ID: ae-200307-067

A buffer overflow was found wget when handling long URLs.
A buffer overflow bug was found in the CHAP implementation of freeradius.
Patches are available now.

System: Mandrake Linux
Topic: Vulnerabilities in phpgroupware and mpg123
Links: MDKSA-2003:077, MDKSA-2003:078, OAR-2003.0936, OAR-2003.0944
ID: ae-200307-066

Several "cross-site-scripting" vulnerabilities were discovered in phpgroupware. By exploiting these vulnerabilities, a remote attacker can obtain sensitive information such as authentication cookies, or change the behavior of the browser by crafting a special URL with javascript in it and somehow having an user click on it.
A vulnerability in the way mpg123 handles mp3 files with a bitrate of zero may allow attackers to execute arbitrary code using a specially crafted mp3 file.
Fixed packages are available now.

System: SCO OpenServer, Open UNIX, UnixWare
Topic: Vulnerability in merge
Links: CSSA-2003-SCO.11, CSSA-2003-SCO.12, OAR-2003.0927
ID: ae-200307-065

Merge includes a security vulnerability in /usr/lib/merge/display that could be exploited to allow unauthorized root access to the UNIX system by an unprivileged user with a UNIX login. A patch is available now.

System: Sun Solaris
Topic: Vulnerabilities in IPv6, LDAP clients, and auditing ftpd
Links: Sun Alert ID 55301, Sun Alert ID 55380, Sun Alert ID 40521, N-124, VU#370060, ESB-2003.0504, ESB-2003.0507, ESB-2003.0508
ID: ae-200307-064

Solaris 8 systems configured to use Internet Protocol Version 6 (ip6(7P)) may panic when processing certain IPv6 packets.
Solaris 8 LDAP clients may log the proxy agent user's password as clear text.
Anonymous FTP sessions are not audited when the Basic Security Module (BSM) is used.
Patches or workarounds are available now.

System: Conectiva Linux
Topic: Vulnerabilities in nfs-utils, kernel, and cups
Links: CLA-2003:700, CLA-2003:701, CLA-2003:702, OAR-2003.0925, OAR-2003.0926, OAR-2003.0928
ID: ae-200307-063

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash).
Conectiva kernels are affected by several long known vulnerabilities.
Several long known vulnerabilties were fixed in cups.
Fixed packages are available now.

System: Debian Linux
Topic: Vulnerability in fdclone
Links: DSA-352, ESB-2003:0506
ID: ae-200307-062

fdclone creates a temporary directory in /tmp as a workspace. However, if this directory already exists, the existing directory is used instead, regardless of its ownership or permissions. Fixed packages are available now.

System: HP Tru64 UNIX
Topic: Vulnerability in Gigabit Ethernet Drivers
Links: OAR-2003:0914, OAR-2003:0915
ID: ae-200307-061

Certain Gigabit Ethernet LAN-on-Motherboard (LOM) and Network-Interface-Card (NIC) implementations may experience a DMA Write Engine loss of synchronization when transferring data from adapter/chip memory to host CPU memory. Patches are available now.

System: Conectiva Linux
Topic: Vulnerability in Apache 2
Links: CLA-2003:698, OAR-2003.0918
ID: ae-200307-060

Four vulnerabilities in Apache 2:
Certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one could result in the weak ciphersuite being used in place of the strong one.
Certain errors returned by accept() on rarely accessed ports could cause temporal denial of service, due to a bug in the prefork MPM.
Denial of service was caused when target host is IPv6 but ftp proxy server can't create IPv6 socket.
The server would crash when going into an infinite loop due to too many subsequent internal redirects and nested subrequests.
Apache 2.0.47 has been released to close these vulnerabilities.

System: Trustix Secure Linux
Topic: Vulnerability in nfs-utils
Links: OAR-2003.0916
ID: ae-200307-059

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). Fixed packages are available now.

System: Mandrake Linux
Topic: Vulnerabilities in apache2 and nfs-utils
Links: MDKSA-2003:075, MDKSA-2003:076, OAR-2003.0919, OAR-2003.0921
ID: ae-200307-058

Four vulnerabilities in Apache 2: Certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one could result in the weak ciphersuite being used in place of the strong one. Certain errors returned by accept() on rarely accessed ports could cause temporal denial of service, due to a bug in the prefork MPM. Denial of service was caused when target host is IPv6 but ftp proxy server can't create IPv6 socket. The server would crash when going into an infinite loop due to too many subsequent internal redirects and nested subrequests.
A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash).
Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerabilities in kernel
Links: RHSA-2003-238, ESB-2003:0502 N-122
ID: ae-200307-057

Several security issues have been discovered affecting the Linux kernel that involve the execve() system call, the /proc Filesystem, the RPC code, the STP protocoll and the forwarding table. Fixed kernel are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-29
ID: ae-200307-056

Within the last the last week 72 new vulnerabilities have been reported:

- invision-ipchat-sql-injection - wagora-index-obtain-information - auctionworks-sferror-xss
- blackbook-message-xss - invision-sminstall-gain-privileges - netscape-cdt-filename-bo
- simpnews-php-file-include - witangoapplicationserver-cookie-bo - imagemagick-format-string
- irc-daemon-raw-dos - wagora-profile-xss - exceed-xserver-font-bo
- blackbook-plaintext-password - irix-scheme-gain-privileges - universe-uvadmsh-bo
- webcalendar-dotdot-directory-traversal - mdaemon-imap4rev1-examine-bo - qmail-patch-open-relay
- gopherd-ftp-gateway-bo - diginews-digiads-cookie-access - citadel-profile-biography-bo
- ie-autoscan-xss - estore-login-sql-injection - nfs-utils-offbyone-bo
- asus-userdata-plaintext-password - storefront-login-sql-injection - citadel-ipgmexecute-code
- wagora-modules-path-disclosure - cisco-ios-ipv4-dos - synthigence-forum-obtain-information
- rav-scan-ravonline-bo - estore-settings-path-disclosure - netcart-settings-view-source
- universe-ccidir-root-access - serverlock-openprocess-load-module - mgc-25-dos
- blackbook-data-insecure-permissions - universe-uvadmsh-root-access - irix-nsd-minus-access
- truetype-font-xfstt-bo - irix-nsd-map-dos - irix-nsd-dns-callbacks
- isa-homepage-error-xss - elite-news-admin-access - citadel-ipgm-configuration-bo
- falcons-eye-s-bo - invision-flash-xss - aspdev-admin-obtain-information
- grub-plaintext-password - starsiegetribes-udp-dos - emailsystem-sql-injection
- universe-programs-abnormal-behavior - splatt-icon-html-injection - wagora-upload-command-execution
- netsuite-get-directory-traversal - omnithttpd-sample-pages-xss - apache-rotatelogs-dos
- bru-vsprintf-format-string - htmltonuke-htmltonuke-xss - win-rpc-dcom-bo
- ubb-cookie-unauthorized-access - gopherd-gsistext-bo - bru-vsprintf-bo
- mdaemon-imap4rev1-select-bo - twilight-get-bo - irix-nsd-portscan-dos
- directconnect-multiple-requests-dos - teledat-port-scan-dos - msn-image-bo
- emailsystem-message-obtain-information - cybershopasp-shopdbtest-obtain-information - webshield-attachment-filter-bypass
System: OpenBSD
Topic: Vulnerabilities in mpg123 and ucd-snmp
Links: OpenBSD
ID: ae-200307-055

Security fixex for mpg123, a player for MP3-files, and ucd-snmp have been published now.

System: Cisco IOS
Topic: Vulnerability in Cisco IOS
Links: CA-2003-17, ae-200307-045, Cisco, AU-2003.009
ID: ae-200307-054

Cisco routers and switches running Cisco IOS software and configured to process Internet Protocol version 4 (IPv4) packets are vulnerable to a Denial of Service attack. Working exploit code has now been made publicly available. This increases the threat posed to those sites which haven't yet taken the mitigation steps outlined in the Cisco Advisory. Fixed IOS software is available now.

System: HP-UX
Topic: Vulnerabilities in Java Runtime Environment
Links: HPSBUX0307-267, HPSBUX0307-268, ESB-2003.0497, ESB-2003.0498
ID: ae-200307-053

Two vulnerabilities were found in the Java(TM) Runtime Environment that may allow an untrusted applet to access restricted resources or trusted applets. Patches are available now.

System: SGI IRIX
Topic: Vulnerabilities in nsd and login
Links: SGI-20030701-01, SGI-20030702-01, ESB-2003.0494, ESB-2003.0495, N-123
ID: ae-200307-052

Several vulnerabilities were found in the IRIX Name Service Daemon (nsd).
Lgging into an IRIX 6.5 machine while particular environment variables are set can lead to /usr/lib/iaf/scheme (login) dumping core. Since "scheme" is suid root, this could potentially lead to a root compromise.
Patches are available now.

System: Immunix Secured OS
Topic: Vulnerability in nfs-utils
Links: OAR-2003.0911
ID: ae-200307-051

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). Fixed packages are available now.

System: Conectiva Linux
Topic: Vulnerability in phpgroupware
Links: CLA-2003:697, OAR-2003.0910, OAR-2003.0937
ID: ae-200307-050

Several "cross-site-scripting" vulnerabilities were discovered in phpgroupware. By exploiting these vulnerabilities, a remote attacker can obtain sensitive information such as authentication cookies, or change the behavior of the browser by crafting a special URL with javascript in it and somehow having an user click on it. Updated packages solve these problem.

System: Debian Linux
Topic: Vulnerability in PHP4
Links: DSA-351, ESB-2003:0500
ID: ae-200307-049

In PHP when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a cross-site scripting attack. Fixed packages are available now.

System: Microsoft ISA Server 2000
Topic: Vulnerability in ISA Server Error Pages
Links: MS03-028, ESB-2003.0492, N-119, WinITSec
ID: ae-200307-048

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows XP
Topic: Vulnerability in Windows Shell
Links: MS03-027, ESB-2003.0493, N-120, WinITSec
ID: ae-200307-047

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows NT, 2000, XP, Server 2003
Topic: Vulnerability in RPC Interface
Links: MS03-026, CA-2003-16, VU#568148, N-117, AL-2003.11, ISS Alerts, Symantec, WinITSec
ID: ae-200307-046

No further comment due to Microsoft insisting on their copyright on advisories.

System: Cisco IOS
Topic: Vulnerability in Cisco IOS
Links: Cisco, AL-2003.12, CA-2003-15, VU#411332, ISS Alerts, N-118, WinITSec, Symantec, CPAI-2003-26
ID: ae-200307-045

Cisco routers and switches running Cisco IOS software and configured to process Internet Protocol version 4 (IPv4) packets are vulnerable to a Denial of Service attack. A sequence of crafted IPv4 packets sent directly to the device may cause the input interface to stop processing traffic once the input queue is full. Fixed IOS software is available now.

System: Slackware
Topic: Vulnerability in nfs-utils
Links: OAR-2003.0900
ID: ae-200307-044

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). Fixed packages are available now.

System: Conectiva Linux
Topic: Vulnerabilities in mpg123 and ucd-snmp
Links: CLA-2003:695, OAR-2003.0898, CLA-2003:696, OAR-2003.0899
ID: ae-200307-043

A vulnerability in the way mpg123 handles mp3 files with a bitrate of zero may allow attackers to execute arbitrary code using a specially crafted mp3 file.
A remote heap overflow was found in snmpnetstat. When a list of interfaces is requested, a malicious server can return information in a way that will cause a heap overflow in snmpnetstat.
Updated packages solve these problem.

System: Mandrake Linux
Topic: Vulnerabilities in kernel
Links: MDKSA-2003:074, MDKSA-2003:066-2, OAR-2003.0901, OAR-2003.0920
ID: ae-200307-042

Mandrake kernels are affected by several long known vulnerabilities. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerability in falconseye
Links: DSA-350, ESB-2003:0490
ID: ae-200307-041

The falconseye package is vulnerable to a buffer overflow exploited via a long -s command line option. This vulnerability could be used by an attacker to gain gid 'games' on a system where falconseye is installed. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in mozilla
Links: RHSA-2003-162, ESB-2003:0491, N-121
ID: ae-200307-040

A heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL referencing a malformed .jar file, which overflows a buffer during decompression. Fixed packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-28
ID: ae-200307-039

Within the last the last week 61 new vulnerabilities have been reported:

- liece-tmp-file-symlink - gnuan-s-command-bo - zkfingerd-fprintf-format-string
- gattaca-view-xss - axis-printservers-webinterface-dos - bitboard2-datapassw-obtain-information
- weblogic-keyfile-password-disclosure - zkfingerd-syslog-format-string - apache-weak-encryption
- turboftp-response-bo - win-rundll32-routine-name-bo - coldfusion-rds-password-plaintext
- coda-rpc2-packet-dos - win2k-accessibility-gain-privileges - xbl-display-command-bo
- skkddskk-temporary-files-insecure - terminatorx-variables-gain-privileges - knoppix-qt-race-condition
- cpanel-multiple-xss - xfaceel-tmp-file-symlink - mdaemon-imap4rev1-examine-bo
- coldfusion-session-improper-validation - qshop-upload-obtain-information - billingexplorer-no-auth
- icq-auth-bypass - eztransserver-dotdot-directory-traversal - myserver-multiple-scripts-dos
- gattaca-view-directory-traversal - xchat-three-connections-dos - phpforum-mainfile-file-include
- mssql-createfile-gain-privileges - canon-gp300-get-dos - gattaca-llist-bo
- productcart-database-obtain-information - gnuchess-s-command-bo - productcart-msg-xss
- cisco-catalyst-tcp-dos - semi-tmp-file-symlink - 1st-security-settings-default
- billingexplorer-admin-password-plaintext - tomcat-plaintext-password - rockliffe-stats-obtain-information
- apache-type-map-dos - ccbill-whereami-execute-code - mdaemon-imap4rev1-select-bo
- apache-prefork-mpm-dos - iglooftppro-multiple-functions-bo - gattaca-slash-file-disclosure
- isdnrep-t-bo - xbox-dashboard-integer-underflow - laforgegroup-user-obtain-information
- coldfusion-rds-gain-access - weblogic-console-gain-access - weblogic-operator-gain-privileges
- trillian-typinguser-dos - mozart-insecure-mailcap-file - apache-redirects-subrequests-dos
- apache-ftp-proxy-dos - win-smb-bo - ie-aux-url-dos
- teapop-modules-sql-injection
System: SuSE Linux
Topic: Vulnerabilities in unzip, nfs-utils, and kernel
Links: SuSE-SA:2003:031, OAR-2003.0896
ID: ae-200307-038

A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence.
A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash).
SuSE kernels are affected by several long known vulnerabilities.
Patches are available now.

System: Conectiva Linux
Topic: Vulnerability in GnuPG
Links: CLA-2003:694, OAR-2003.0890
ID: ae-200307-037

When evaluating trust values for the UIDs assigned to a given key, GnuPG would incorrectly associate the trust value of the UID having the highest trust value with every UID assigned to this key. An updated package solves this problem.

System: Debian Linux
Topic: Vulnerability in nfs-utils
Links: DSA-349, ESB-2003:0486
ID: ae-200307-036

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in nfs-utils
Links: RHSA-2003-206, RHSA-2003-207, ESB-2003:0487, VU#258564
ID: ae-200307-035

A buffer overflow bug was found in nfs-utils. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). Fixed packages are available now.

System: Microsoft Windows XP
Topic: Vulnerability in rundll32.exe
Links: WinITSec
ID: ae-200307-034

A buffer-overflow vulnerability exists in Windows XP Service Pack 1's (SP1's) rundll32.exe file. Microsoft hasn't yet responded to this problem.

System: Debian GNU/Linux
Topic: Vulnerability in traceroute-nanog
Links: DSA-348, ESB-2003.0485
ID: ae-200307-033

traceroute-nanog contains an integer overflow bug which could be exploited to execute arbitrary code. traceroute-nanog is setuid root, but drops root privileges immediately after obtaining raw ICMP and raw IP sockets. Thus, exploitation of this bug provides only access to these sockets, and not root privileges. New packages are available now.

System: OpenPKG
Topic: Vulnerabilities in imagemagick and infozip
Links: OAR-2003.0885, OAR-2003.0886
ID: ae-200307-032

imagemagick's libmagick library creates temporary files without taking appropriate security precautions.
A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence.
Fixed packages are available now.

System: Several
Topic: Several vulnerabilities in BEA WebLogic Server and Express fixed
Links: BEA03-28 OAR-2003.0877, BEA03-32 OAR-2003.0878, BEA03-33 OAR-2003.0879, BEA03-34 OAR-2003.0880
ID: ae-200307-031

A vulnerability was found in an internal protocol used for copying data between servers. In some circumstances the protocol will allow non-privileged accounts to access application source code, modify applications, reconfigure the administrative settings of the server and in some installations, even alter the operating system files.
If the Console isn't protected by a firewall, under some circumstances it can be accessed through the managed server's listen port.
A vulnerability might occur, when there are users in the Operator role who are not also in the Admin role and the NodeManager is used to start servers. The users in the Operator role unintentionally have read and write access to the username and password used for remote starting each server, also for Admin users.
If the Node Manager is in use on a machine and users besides those in the WebLogic Server Admin and Operator roles have access to a process listing on that machine. So users who have access to the machine can, see the command lines of all machines running on the machine and acquire the password. So the Node Manager's account might be compromised.
Patches solve the problems mentioned.

System: Red Hat Linux ES/AS
Topic: New packages for Hangul Terminal, ethereal, and Netscape
Links: RHSA-2003-071, OAR-2003.0867, RHSA-2003-077, OAR-2003.0868, RHSA-2003-027, OAR-2003.0869
ID: ae-200307-030

Hangul Terminal is a terminal emulator for the X Window System, based on Xterm and showing a vulnerability when using escape-sequences. As for the "normal" Red Hat Linux also, updated Ethereal packages fix a number of remotely exploitable security issues. Netscape 4.8 has been published now, providing improvements in security and bug fixing.

System: Conectiva Linux
Topic: Vulnerabilities in Imp, PHP4, and pam
Links: CLA-2003:690, OAR-2003.0865, CLA-2003:691, OAR-2003.0866, CLA-2003:693, OAR-2003.0887,
ID: ae-200307-029

Imp is a webmail system which uses the Horde framework. It can optionally store user preferences, contacts list and session IDs in a SQL database. A remote attacker can exploit a SQL injection vulnerability to execute SQL commands and possibly get session IDs and steal another user's webmail session. Other consequences are possible and depend on the privileges Imp has in the database. An update solves this problem and makes Imp compatible with PHP 4.3.2.
PHP is a very popular scripting language used by web servers to offer dynamic content. Now, an update to version 4.3.2 is available, fixing some vulnerabilities.
PAM is the authentication system used in Linux. Pam_xauth is an authentication module which makes it possible to forward X credentials from one user to another in order to share an X display. It is particularly useful in applications such as "su". A vulnerability in the use of pam_xauth by the su utility has been found. If the attacker can make one user run su from an X session, he can steal the X credentials and execute programs in the X display of the user running su. An updated package solves this problem.

System: Several
Topic: Vulnerability in Apache 2
Links: Apache, ESB-2003.0482, ESB-2003.0496, N-146
ID: ae-200307-028

Four vulnerabilities in Apache 2:
Certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one could result in the weak ciphersuite being used in place of the strong one.
Certain errors returned by accept() on rarely accessed ports could cause temporal denial of service, due to a bug in the prefork MPM.
Denial of service was caused when target host is IPv6 but ftp proxy server can't create IPv6 socket.
The server would crash when going into an infinite loop due to too many subsequent internal redirects and nested subrequests.
Apache 2.0.47 has been released to close these vulnerabilities.

System: Microsoft Windows 2000
Topic: Vulnerability in Accessibility Utility Manager
Links: MS03-025, N-116, WinITSec, OAR-2003:0883
ID: ae-200307-027

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows NT, 2000, XP
Topic: Vulnerability in SMB implementation
Links: MS03-024, N-115, WinITSec, OAR-2003:0882
ID: ae-200307-026

No further comment due to Microsoft insisting on their copyright on advisories.

System: Cisco Catalyst
Topic: Vulnerability in CatOS
Links: Cisco, ESB-2003.0479
ID: ae-200307-025

After receiving eight TCP connection attempts using a non-standard TCP flags combination, a Catalyst switch will stop responding to further TCP connections to that particular service. In order to re-establish functionality of that service, the switch must be rebooted. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in skk, ddskk, unzip, xbl, phpsysinfo and teapop
Links: DSA-343, DSA-344, DSA-345, DSA-346, DSA-347, ESB-2003.0473, ESB-2003.0474, ESB-2003.0477, ESB-2003.0478
ID: ae-200307-024

'skk' (a simple Kana to Kanji conversion program) and its derivate 'ddskk' contain a race condition on use of temporary files.
'unzip' contain the already known directory traversal vulnerability.
'xbl' (a game) contains a buffer overflow which leads to permissions of group 'games'.
'phpsysinfo' (webbased program to display system status information) contains directory traversal vulnerabilities which can lead to allow local files via web or execute arbitrary PHP code with permissions of the web server process user.
'teapop' (a POP-3 server) is vulnerable against SQL injection, this can be used to execute any SQL with the permissions of the authenticated user.
New packages are available now.

System: Turbolinux
Topic: Vulnerability in unzip
Links: TLSA-2003-42, ae-200307-004
ID: ae-200307-023

For the already known vulnerabilty in 'unzip' an update is now available.

System: Macromedia
Topic: Vulnerability in ColdFusion MX and JRun 4.0
Links: MPSB03-04, ESB-2003.0476
ID: ae-200307-022

ColdFusion MX and JRun 4.0 will show source code while browsing .cfm, .cfc, .cfml (ColdFusion MX) or .jsp (JRun) pages if the user appends an encoded space to the end of a URL. This vulnerability only affects Apache 1.3.x and 2.x versions on Windows.
Patches are now available.

System: Several systems
Topic: New ISS Summary
Links: AS03-27
ID: ae-200307-021

Within the last the last week 34 new vulnerabilities have been reported:

- cyberstrongeshop-multiple-sql-injection - megabook-view-files - megabook-admin-login-xss
- solaris-dos - cache-insecure-permissions - megabook-gbook-xss
- imagemagick-libmagick-symlink - macos-auth-bypass - opera-multiple-dos
- sharemailpro-obtain-information - pinknetwebserver-dotdot-directory-traversal - sunone-ldap-auth-bypass
- ezbounce-sessions-format - openbsd-pf-obtain-information - netmeeting-dotdot-directory-traversal
- mantis-insecure-file-permissions - pabox-admin-password-reset - verityk2toolkit-querybuilder-xss
- greymatter-comment-command-execution - win2k-active-directory-bo - cutenews-html-element-xss
- rogerwilco-nickname-braodcast-bo - megabook-setup-weak-encryption - acrobatreader-wwwlaunchnetscape-bo
- pabox-bannedusers-file-include - phpgroupware-multiple-xss - win2k-shell32dll-shellexecute-bo
- abyss-http-get-bo - gtksee-png-bo - rogerwilco-recv-packet-dos
- ircd-format-string - abyss-http-header-injection - vpasp-shopexd-sql-injection
- visnetic-website-path-disclosure
System: Conectiva Linux
Topic: Vulnerability in openldap
Links: CLA-2003:685, OAR-2003.0864
ID: ae-200307-020

A failed password extended operation (password EXOP) can cause openldap to, if using the back-ldbm backend, attempt to free memory which was never allocated, resulting in a segfault. Package updates are now available.

System: Mandrake Linux
Topic: Vulnerability in unzip
Links: MDKSA-2003:073, OAR-2003:0870
ID: ae-200307-019

A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in liece and mozart
Links: DSA-341, DSA-342, ESB-2003.0469, ESB-2003.0470
ID: ae-200307-018

liece, an IRC client for Emacs, does not take appropriate security precautions when creating temporary files.
mozart, a development platform based on the Oz language, includes MIME configuration data which specifies that Oz applications should be passed to the Oz interpreter for execution. This means that file managers, web browsers, and other programs which honor the mailcap file could automatically execute Oz programs downloaded from untrusted sources.
New packages are available now.

System: Immunix Secured OS
Topic: Vulnerability in unzip
Links: OAR-2003.0855, ae-200307-004
ID: ae-200307-017

For the already known vulnerabilty in 'unzip' an update is now available.

System: Debian GNU/Linux
Topic: Vulnerabilities in semi, wemi and x-face-el
Links: DSA-339, DSA-340, ESB-2003.0467, ESB-2003.0468
ID: ae-200307-016

Race conditions due to insecure temporary file creation were found in packages 'semi', 'wemi' (MIME libraries for GNU Emacs) and 'x-face-el' (decoder for images included inline in X-Face).
New packages are available now.

System: Conectiva Linux
Topic: Vulnerabilities in xpdf, unzip and ml85p
Links: CLA-2003:672, OAR-2003.0856, ae-200306-050, CLA-2003:674, OAR-2003.0857, ae-200307-004, CLA-2003:675, OAR-2003.0858,
ID: ae-200307-015

The vulnerabilties in 'xpdf' and 'unzip' are already described.
Package 'ml85p' (printer driver for the Samsung ML-85G and QL85G printer models) contain also insecure temporary file creation.
For all 3 packages updates are now available.

System: Sun Linux
Topic: Vulnerabilities in xpdf and ypserv
Links: SunAlertID#55601, SunAlertID#55600, ae-200306-050, ae-200306-067
ID: ae-200307-014

For the already known vulnerabilties in 'xpdf' and 'ypserv' Sun now provides updated packages.

System: SuSE Linux
Topic: Vulnerabilities in mod_PHP
Links: SuSE 8.1
ID: ae-200307-013

A new fis for PHP corrects two possible vulnerabilities. The first is an internal error of the PHP interpreter, which will crash under some circumstances when session functions are used. Additionally, the handling of the session file is improved and corrected. It's recommended to install this new patch.

System: OpenBSD
Topic: Vulnerability in unzip
Links: OpenBSD
ID: ae-200307-012

A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence. Fixed packages are available now.

System: Conectiva Linux
Topic: Vulnerabilities in KDE
Links: CLA-2003:668, OAR-2003.0848
ID: ae-200307-011

In several cases, kde applications call the ghostview program to handle PS and PDF files in an insecure way (without the -DPARANOIDSAFER or -SAFER parameters), which may allow attackers to execute commands using crafted PS/PDF files. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in ethereal
Links: RHSA-2003-203, ESB-2003:0464
ID: ae-200307-010

Several vulnerabilities were found in a lot of the protocoll dissectors of ethereal. These vulnerabilities may lead to execution of arbitrary code. Affected are the dissectors for 802.11, AIM, BGP, CLNP, DCERPC, DNS, GIOP Gryphon, ISAKMP, ISIS, Mount, OSI, OSPF, PPP, PPTP, Quake, Quake2, Quake3, RMI, Rsync, SMB, SMPP, SPNEGO, TSP, WSP, WTP, BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI. Fixed packages are available now.

System: Microsoft Windows 2000 Server
Topic: Vulnerability in Active Directory
Links: CORE-2003-0305-03, ESB-2003.0463
ID: ae-200307-009

A vulnerability in Active Directory allows an attacker to crash and force a reboot of any Windows 2000 Server running the Active Directory service. The vulnerability can be triggered when an LDAP version 3 search request with more than 1000 "AND" statements is sent to the server, resulting in a stack overflow and subsequent crash of the Lsaas.exe service. This in turn, will force a domain controller to stop responding, thus making possible a denial of service attack against it. The LDAP request does not need to be authenticated. A fix for this issue is included in Windows 2000 SP4.

System: Microsoft Windows
Topic: Vulnerabilities in Opera
Links: WinITSec
ID: ae-200307-008

Several bugs were found in Opera 7 for Windows Web browser that can result in a Denial of Service (DoS) condition. A patch is not yet available.

System: Microsoft Windows
Topic: Vulnerability in Windows NetMeeting
Links: CORE-2003-0305-04, ESB-2003.0460
ID: ae-200307-007

A directory traversal vulnerability was found in NetMeeting when doing File Transfers. An attacker can use filenames containing "..\..\" when doing a file transfer, and in this manner, create a file in any place of the victim's filesystem, escaping the directory where NetMeeting usually stores incoming files (e.g. C:\Program Files\ Received\Received Files). A fix for this issue is included in Windows 2000 SP4 and Windows XP SP1.

System: Sun Solaris
Topic: Vulnerability in LDAP Name Service
Links: Sun Alert ID 52222, N-113, ESB-2003.0461
ID: ae-200307-006

On Solaris 8 and Solaris 9 systems with the LDAP name service enabled, an unprivileged local user may be able to gain unauthorized root access due to a buffer overflow in the "nss_ldap.so.1" library. Patches are not yet available.

System: Red Hat Linux
Topic: Vulnerability in PHP
Links: RHSA-2003-204, ESB-2003:0462, N-112
ID: ae-200307-005

In PHP when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a cross-site scripting attack. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in unzip
Links: RHSA-2003-199, RHSA-2003-200, ESB-2003:0458, N-111
ID: ae-200307-004

A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence. Fixed packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-26
ID: ae-200307-003

Within the last the last week 49 new vulnerabilities have been reported:

- moregroupware-multiple-xss - ftpserverx-wsprintf-bo - ikescan-filename-bo
- webweaver-error-page-xss - ie-html-bo - ncgactivemailserver-commands-bo
- xoops-tutorials-file-upload - tracesroute-nanog-integer-overflow - interforum-view-private-messages
- myserver-http-get-dos - phpnuke-mainfile-xss - moregroupware-multiple-file-include
- iweb-encoded-directory-traversal - tutos-php-file-upload - imp-dotdot-directory-traversal
- guestbookhost-multiple-fields-xss - symantec-security-activex-bo - xmb-buddy-xss
- wzdftpd-port-command-dos - compaq-webagent-ssi-dos - imp-index-path-disclosure
- xgalaga-home-bo - interforum-message-xss - interforum-gain-admin-privileges
- portmon-files-insecure - linux-proc-obtain-information - symantec-antivirus-improper-scans
- perledit-port1956-bo - gnats-multiple-functions-bo - iat-dotdot-directory-traversal
- vmware-insecure-files-symlink - gkrellm-daemon-bo - interforum-profile-editing-xss
- netscreen-screenos-auth-bypass - optiswitch-ctrl-root-access - armida-http-get-dos
- symantec-antivirus-updater-dos - hp-tftp-dos - linux-execve-gain-privileges
- sdfingerd-privilege-dropping - tutos-msg-xss - jnethack-groupid-bo
- webadmin-user-bo - sambar-search-dos - lbreakout2-snprintf-format-string
- visneticwebmail-php-source-disclosure - tcptraceroute-privilege-dropping - xmb-msn-mood-xss
- mediaplayer-activex-obtain-information
System: Sun Solaris
Topic: Vulnerabilities in dbmopen, dbminit, syslogd, Sun ONE Application Server, and VERITAS File System
Links: OAR-2003.0840, OAR-2003.0841, OAR-2003.0844, OAR-2003.0845
ID: ae-200307-002

A local unprivileged user may be able to gain unauthorized root privileges due to a buffer overflow vulnerability in the database function routines dbm_open(3C) and dbminit(3UCB).
A local or remote unprivileged user may be able to terminate the syslogd(1M) daemon on a Solaris system by sending large sized syslog(3C) packets.
The Sun ONE Application Server may incorrectly validate user authentication information with LDAP.
A local unprivileged user may be able to gain additional access privileges to VERITAS File System (VxFS) files due to incorrect permissions being set when Access Control Lists (ACLs) are being utilized.
Patches are available now.

System: Conectiva Linux
Topic: Vulnerabilities in radiusd-cistron and kopete
Links: CLA-2003:664, CLA-2003:665, OAR-2003.0827, OAR-2003.0828
ID: ae-200307-001

The package radiusd-cistron is an implementation of the RADIUS protocol. The RADIUS server does not handle large NAS numbers correctly. This leads to overwriting of internal memory of the server process and may be abused to gain remote access to the system the RADIUS server is running on.
The GnuPG plugin in kopete allows remote attackers to execute arbitrary commands in the client context by sending specially crafted messages to it.
Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH