Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-54-234-231-49.compute-1.amazonaws.com [54.234.231.49]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 08 / 2003

System: Mandrake Linux
Topic: Vulnerability in gkrellm
Links: MDKSA-2003:087, OAR-2003:1082
ID: ae-200308-080

A buffer overflow was discovered in gkrellmd. This buffer overflow occurs while reading data from connected gkrellm clients and can lead to possible arbitrary code execution as the user running the gkrellmd server. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerabilities in node
Links: DSA-375, ESB-2003.0608
ID: ae-200308-079

Several buffer overflows and format string errors were found in node. Fixed packages are available now.

System: Turbolinux
Topic: Vulnerabilities in php, gdm, and perl
Links: TLSA-2003-47, TLSA-2003-48, TLSA-2003-49, OAR-2003.1058, OAR-2003.1078,
ID: ae-200308-078

In PHP when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a cross-site scripting attack.
A vulnerabilitiy in the Gnome Display Manager (GDM) allows local users to read any text file on the system, in addition, a denial of service issue exists, if X Display Manager Control Protocol (XDMCP) is enabled.
A cross-site scripting vulnerability exists in the start_form() function in CGI.pm.
Fixed packages are available now.

System: HP-UX
Topic: Vulnerabilities in shells
Links: HPSBUX0308-275, ESB-2003.0603, ESB-2003.0752
ID: ae-200308-077

Several shells create insecure temporary files with a name based on a process id. Patches are available now.

System: Slackware
Topic: Vulnerability in Gnome Display Manager (GDM)
Links: SSA:2003-236-01, OAR-2003.1075
ID: ae-200308-076

A vulnerabilitiy in the Gnome Display Manager (GDM) allows local users to read any text file on the system, in addition, a denial of service issue exists, if X Display Manager Control Protocol (XDMCP) is enabled.
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in glibc
Links: RHSA-2003-249, OAR-2003:1060
ID: ae-200308-075

A bug in the getgrouplist function can cause a buffer overflow if the size of the group list is too small to hold all the user's groups. This overflow can cause segmentation faults in user applications, which may have security implications, depending on the application in question. New packages are available now.

System: Various
Topic: Vulnerability in pam_smb
Links: VU#680260, RHSA-2003-261, N-137, DSA-364, ESB-2003.0598, TLSA-2003-50, Symantec, SuSE-SA:2003:036
ID: ae-200308-074

If a long password is supplied to the libpam-smb PAM authentication module, this can cause a buffer overflow which could be exploited to execute arbitrary code with the privileges of the process which invokes PAM services. Patches are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-34
ID: ae-200308-073

Within the last the last week 51 new vulnerabilities have been reported:

- widz-apmon-command-execution - avantbrowser-http-bo - gdm-xdmcp-continue-dos
- attilaphp-multiple-path-disclosure - emule-opserverident-heap-overflow - srcpd-conffile-bo
- best-buy-password-plaintext - ie-br549-activex-bo - netmail-weak-password-encryption
- horde-application-sessionid-disclosure - dropbear-login-format-string - attilaphp-index-xss
- helix-view-code-execution - best-buy-command-execution - ie-cache-script-injection
- gdm-xsessions-errors-symlink - matrikzgb-index-admin-privileges - eudora-search-xss
- webftp-accounts-plaintext-password - virobot-linux-cgi-bo - pabox-admin-plaintext-password
- sunone-dos - emule-packetssequence-execute-code - gdm-xdmcp-authorization-dos
- acmpop-weak-password-encryption - starfish-accountsdb-plaintext-password - omailwebmail-checklogin-code-execution
- ecartis-subscribe-password-disclosure - netserve-registrykey-plaintext-password - emule-servername-format-string
- antigen-test-filter-bypass - srcpd-multiple-functions-bo - mdac-broadcast-request-bo
- dwebpro-http-plaintext-password - openbsd-semget2-bo - php-dlopen-memory-disclosure
- piolet-dos - multipoint-commands-directory-traversal - bitkeeper-patch-execute-code
- unix-devrandom-keystroke-timing - openslp-slpd-symlink - ecartis-multiple-bo
- oracle-xml-bo - emule-opservermessage-format-string - ie-dbcs-object-bo
- solaris-cachefs-inetdconf-overwrite - ie-object-code-execution - srcpd-integer-overflow
- vonage-voip-callerid-spoof - checkmail-registrykey-plaintext-password - tru64-ee-driver-dos
System: Various
Topic: Vulnerability in sendmail
Links: Sendmail, VU#993452, ESB-2003.0594, MDKSA-2003:086, ESB-2003.0596, FreeBSD-SA-03:11, ESB-2003.0599, SuSE-SA:2003:035, RHSA-2003-265, ESB-2003.0606, N-138
ID: ae-200308-072

An attacker able to control DNS responses sent to affected sendmail servers using DNS maps may be able exploit an uninitialized data structure in servers running sendmail 8.12.x, where x < 9. This may lead to the sendmail daemon crashing, or possibly the execution of arbitrary code on the server. A patch is available now.

System: RealNetworks
Topic: Vulnerability in Helix Universal Server
Links: RealNetworks, N-152
ID: ae-200308-071

Helix Universal Server are vulnerable to a root exploit when certain types of character strings appear in large numbers within URLs destined for the server's protocol parsers. A patch is not available yet. As a workaround the "View Source" plug-in can be removed.

System: Mac OS X
Topic: Vulnerability in KisMAC
Links: @stake
ID: ae-200308-070

KisMAC is a popular wireless network identification and analysis tool. In the event that the "SUID Shell Scripts are enabled" checkbox (inside of the driver tab under preferences) is enabled, an attacker with local interactive access can become root through several different mechanisms. This feature is off by default. It's recommended to upgrade to version 0.05d4 and not to enable this functionality on a multi-user machine.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in kernel
Links: RHSA-2003-239, RHSA-2003-198, OAR-2003:1055, OAR-2003:1056
ID: ae-200308-069

Several vulnerabilities in the kernel should be fixed as soon as possible with the new packages, Red Hat has published now.

System: Microsoft Windows
Topic: W32/Sobig.F Second Phase Action
Links: ISS Alert 151, IN-2003-03
ID: ae-200308-068

Computers infected with the Sobig.F worm are programmed to automatically download an executable of unknown function from a hard-coded list of servers today at 19:00 UTC (3:00pm EDT) using port 8998/udp. Due to this ISS X-Force recommends to filter outbound connections to 67.73.21.6, 68.38.159.161, 67.9.241.67, 66.131.207.81, 65.177.240.194, 65.93.81.59, 65.95.193.138, 65.92.186.145, 63.250.82.87, 65.92.80.218, 61.38.187.59, 24.210.182.156, 24.202.91.43, 24.206.75.137, 24.197.143.132, 12.158.102.205, 24.33.66.38, 218.147.164.29, 12.232.104.221, 68.50.208.96 and to block port 8998/udp outgoing.

System: Mandrake Linux
Topic: Vulnerability in Gnome Display Manager (GDM)
Links: MDKSA-2003:085, ae-200308-066, OAR-2003:1057
ID: ae-200308-067

For the already known vulnerability in 'Gome Display Manager (GDM)' an update is now available.

System: Red Hat Linux
Topic: Vulnerability in Gnome Display Manager (GDM)
Links: RHSA-2003-258, ESB-2003.0593
ID: ae-200308-066

A vulnerabilitiy in the Gnome Display Manager (GDM) allows local users to read any text file on the system, in addition, a denial of service issue exists, if X Display Manager Control Protocol (XDMCP) is enabled.
Fixed packages are available now.

System: Oracle
Topic: Vulnerabilities in Oracle9i 9.2.0.1
Links: Symantec#8375, CPAI-2003-29
ID: ae-200308-065

Oracle XML Database (XDB) 9.2.0.1 has multible vulnerabilities, attacks can be done because of buffer oveflows in its FTP and HTTP services.
Currently there are no patches available so traffic filtering is required.

System: OpenBSD
Topic: Vulnerability in kernel
Links: OpenBSD, ESB-2003.0591
ID: ae-200308-064

An improper bounds check in the semget(2) system call can allow a local user to cause a kernel panic. A patch is available now.

System: Microsoft Windows
Topic: W32/Sobig.F worm
Links: S-03-059, AL-2003.14
ID: ae-200308-063

Since some time, the new worm W32/Sobig.F is in the wild. This wurm uses a since long time already known security hole: the user of Microsoft operating systems, who opens and execute attachements without any proper installed and up-to-date anti-virus software.

The worm starts then a program which searches for e-mail addresses in post boxes. Afterwards it sends itself by generating e-mails with random choosen sender and recipient addresses.
The new version was improved, the worm's SMTP client now is multi-threading enabled, means it can send multible e-mails at one time.
Improvements can be done e.g. by:
- teach users
- use up-to-date anti-virus software on all clients
- prohibit e-mail relaying from internal to external in case of usage of non internal sender addresses
In addition, the e-mail traffic can be reduced by disabling the sender notification on anti-virus gateway in general (recommended) or at least in case of detected worms, which choose random sender addresses (such notification is useless).

For incoming blocking on a SMTP gateway already extensions are published (without any warranty): Postfix, Sendmail/Exim.

System: Mandrake Linux
Topic: Vulnerability in perl-CGI module
Links: MDKSA-2003:084, ae-200308-033, OAR-2003:1053
ID: ae-200308-062

For the already known vulnerability in 'perl-CGI' module an update is now available.

System: Microsoft Windows ME, 2000, XP
Topic: Vulnerabilities in Microsoft Data Access Components 2.5 to 2.7
Links: MS03-033, VU#865940, N-136, ESB-2003.0587, WinITSec, S-03-061, M-105, Symantec
ID: ae-200308-061

No further comment due to Microsoft insisting on their copyright on advisories.

System: Microsoft Windows
Topic: Critical vulnerabilities in Internet Explorer
Links: MS03-032, CA-2003-22, ESB-2003.0601, VU#205148, VU#865940, VU#548964, VU#813208, VU#334928, N-135, ESB-2003.0588, S-03-060, WinITSec, CPAI-2003-30
ID: ae-200308-060

A new cumulative Patch for Internet Explorer was published.
No further comment due to Microsoft insisting on their copyright on advisories.

System: Mandrake Linux
Topic: Vulnerabilites in unzip and eroaster
Links: MDKSA-2003:073-1, MDKSA-2003:083, ae-200308-048, ae-200308-020, OAR-2003.1050, OAR-2003.1049
ID: ae-200308-059

For the already known vulnerabilities in 'unzip' and 'eroaster' updates are now available.

System: Macromedia
Topic: Vulnerabilites in Dreamweaver MX, DRK and UltraDev
Links: MPSB03-05, ESB-2003.0592
ID: ae-200308-058

A security issue was found with some of the server behaviors present in Dreamweaver MX, all versions of UltraDev, and two extensions that shipped as part of the Developer's Resource Kit (DRK), vol. 2 and vol. 4. If exploited, it is possible for an attacker to gain access to certain site-specific cookie and session information.
Patches are available now, see specific instructions on given URL.

System: Sun Solaris 2.6 & 7
Topic: Vulnerability in cachefs-Patch
Links: Sun Alert 56300, N-134, ESB-2003.0589
ID: ae-200308-057

Applying an earlier version of the cachefs patche on Solaris 2.6 and Solaris 7 systems can result in erroneously overwriting of the inetd.conf(4) file. This can lead to reenable previously disabled services.
A workaround is described on given URLs. Administrators should review also enabled service in current inetd.conf.

System: OpenBSD
Topic: Vulnerability in unzip
Links: OpenBSD, ae-200308-048
ID: ae-200308-056

For the already known vulnerabilty in 'unzip' an update is now available.

System: SCO UnixWare, Open UNIX
Topic: Vulnerability in metamail
Links: CSSA-2003-SCO.15, OAR-2003.1044
ID: ae-200308-055

Three vulnerabilities in metamail were fixed now. These vulnerabilities were publicly known since 1997 or 1999.

System: Apple Mac OS X
Topic: Vulnerability in realpath
Links: VU#743092, ESB-2003.0582
ID: ae-200308-054

An off-by-one error exists in a portion of realpath(3) that computes the length of the resolved pathname. Applications using realpath(3) MAY be vulnerable to denial of service attacks, remote code execution, and/or privilege escalation. A patch is available now.

System: HP HP-UX, Tru64, OpenVMS
Topic: Vulnerability with Distributed Computing Environment (DCE)
Links: HPSBUX0308-273, HPSBUX0308-274, ESB-2003.0572, ESB-2003.0580, ESB-2003.0604, ESB-2003.0659
ID: ae-200308-053

Potential security vulnerability with Distributed Computing Environment (DCE) where a remote user may cause the service to become unresponsive. Patches are available now.

System: Conectiva Linux
Topic: Vulnerability in openslp
Links: CLA-2003:723, OAR-2003.1045
ID: ae-200308-052

The initscript (/etc/rc.d/init.d/slpd) of the openslp daemon uses '/tmp/route.check' as a temporarily file in an unsafe manner. Patches are available now.

System: SuSE Linux
Topic: Vulnerability in exim
Links: SuSE 8.1, SuSE 8.2
ID: ae-200308-051

A buffer overflow was found in exim. Fixed packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-33
ID: ae-200308-050

Within the last the last week 65 new vulnerabilities have been reported:

- cisco-cmf-command-execution - sunone-viewlog-directory-traversal - phpwebsite-calendar-path-disclosure
- zorum-index-path-disclosure - ie-aboutblank-xss - pam-pgsql-format-string
- sunone-directory-gain-privileges - phpwebsite-calendar-sql-injection - invision-admin-xss
- warftp-waruser-plaintext-password - dsh-home-bo - xynph-bkonten-plaintext-password
- mdaemon-smtp-gain-access - webware-cookie-code-execution - poster-setup-add-accounts
- news-wizard-path-disclosure - webchatserver-xss - meteor-logonign-obtain-password
- bbpro-http-path-disclosure - postnuke-downloads-weblinks-xss - dcforum-subject-message-xss
- surgeldap-path-disclosure - xv-bo - surgeldap-users-plaintext-password
- xoops-bbcode-xss - stellar-fetch-path-disclosure - badblue-ext-plaintext-password
- jcsi-accesscontrol-unauthorized-access - freebsd-signal-dos - distcc-tmp-file-symlink
- eftp-userdata-eftp3server-password - mercury-mta-plaintext-password - meteorftp-user-bo
- skunk-handler-xss - imate-user-plaintext-password - xmule-format-string
- gnuftp-backdoor - weblogic-consoleapplication-xss - zorum-index-xss
- freebsd-ibcs2-kernel-memory - surgeldap-get-bo - urlscan-rsasecurid-filter-discovery
- netris-bo - lilhttp-lilhttp-plaintext-password - hostadmin-http-path-disclosure
- xitami-connections-not-logged - joe-bo - geeeekshop-multiple-path-disclosure
- fusion-login-add-accounts - irix-nfs-xdr-dos - phpwebsite-multiple-modules-xss
- surgeldap-cgi-scripts-xss - cisco-cmf-gain-privileges - autoresponder-bo
- webdeskpro-modify-role - hola-htmltags-admin-password - skunkweb-cache-directory-traversal
- chitchat-name-topictitle-xss - cdialog-bo - netsurf-get-bo
- phpwebsite-calendar-module-bo - ms-blast-worm - visual-studio-mcwndx-bo
- dameware-gain-privileges - irix-libcpr-overwrite-files
System: Debian Linux
Topic: Vulnerabilities in netris and autoresponer
Links: DSA-372, DSA-373, ESB-2003.0574
ID: ae-200308-049

A buffer overflow was found in the 'netris' clinet software.
A buffer overflow was found in 'autorespond'. This vulnerability could potentially be exploited by a remote attacker to gain the privileges of a user who has configured qmail to forward messages to autorespond.
Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in unzip
Links: RHSA-2003-199, RHSA-2003-200, ESB-2003:0576
ID: ae-200308-048

A vulnerabilitiy in unzip allows attackers to overwrite arbitrary files during archive extraction. The previous patches did not stop all cases. Fixed packages are available now.

System: OpenBSD
Topic: Vulnerability in netris
Links: OpenBSD
ID: ae-200308-047

OpenBSD has published a new version of netris to fix buffer overlows.

System: Cisco
Topic: Vulnerability caused by TFTP
Links: Cisco, ESB-2003.0568
ID: ae-200308-046

Last year, a vulnerability in the processing of filenames within a TFTP read request on IOS devices has been reported. Now, an update of this advisory points out, that also PXM-1 based MGX switches are affected products. A patch is available and should be installed soon.

System: Sun Linux, Qube3, RaQ4, RaQXTR, RaQ550
Topic: Vulnerabilities in unzip, ptrace, and Python
Links: Sun Alert 56120, Sun Alert 52081, Sun Alert 56122, OAR-2003:1042, OAR-2003:1043
ID: ae-200308-045

In Sun Linux 5.0, a directory traversal vulnerability in unzip 5.50 and earlier may allow local users to overwrite arbitrary files during archive extraction. It's recommended to make sure, the right permissions are set and a new patch is installed. A new patch should also installed for fixing an issue with the ptrace function. Due to a security hole an unauthorized local user may be able to gain root access rights on Linux systems, including Sun Linux and Sun Cobalt platforms. Addititionally unprivileged local users may be able to overwrite or create any file on the system if a root user runs Python.

System: Microsoft Windows
Topic: Vulnerability in Sun ONE/iPlanet Web Server
Links: Sun Alert 56180, OAR-2003:1041
ID: ae-200308-044

The Sun ONE/iPlanet Web Server is vulnerable to a Denial of Service (DoS) attack by a local or remote unprivileged user. It's recommended to install Sun ONE/iPlanet Web Server 6.0 Service Pack 6 or later.

System: Sun Solaris 9
Topic: Vulnerability in in.ftpd
Links: Sun Alert 56121, ESB-2003.0565, ae-200308-001
ID: ae-200308-043

The Solaris 9 FTP Server, in.ftpd, is based on WU-ftpd (Washington University ftpd) and is affected by a security vulnerability which may allow a local or remote unprivileged user to gain unauthorized root access. Sun describes some workarounds, a patch is pending.

System: Several
Topic: Compromise of GNU Project FTP Server
Links: CA-2003-21, ESB-2003.0563, S-03-058
ID: ae-200308-042

The CERT/CC has received a report that the system housing the primary FTP servers for the GNU software project was compromised. The compromise is reported to have occurred in March of 2003. Because this system serves as a centralized archive of popular software, the insertion of malicious code into the distributed software is a serious threat. As an announcement of FSF indicates, no source code distributions are believed to have been maliciously modified at this time. GNU software obtained from the compromised system should be verified to test the integrity of the downloaded distribution.

System: SGI IRIX
Topic: Vulnerability in nfsd and cpr
Links: SGI-20030801-01, SGI-20030802-01, ESB-2003.0570, ESB-2003.0569, VU#888459
ID: ae-200308-041

It's possible to create a Denial-of-Service attack on the IRIX nfsd by unsing carefully crafted packets which cause XDR decoding errors. This can lead to a kernel panic on the system. A vulnerability in the checkpoint/restart (cpr) system might allow local users to truncate or overwrite certain files without having the permission for it. Patches are available now.

System: Cisco
Topic: Vulnerability in CiscoWorks Common Management Foundation
Links: Cisco, ESB-2003.0566, WinITSec
ID: ae-200308-040

Two vulnerabilities exist in CiscoWorks CMF versions prior to and including 2.1. The first vulnerability is a privilege escalation vulnerability where a guest user may obtain administrative privileges within the application via a specially crafted URL. The second vulnerability is an ability to run arbitrary commands on the CiscoWorks server due to an error in processing user input. Patches are available now.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SuSE-SA:2003:034, OAR-2003.1028
ID: ae-200308-039

New kernel packages fix several local and denial of service vulnerabilities.

System: Microsoft Windows NT, 2000, XP, Server 2003
Topic: W32/Blaster worm
Links: CA-2003-20, MS03-026, ae-200308-005, ae-200307-046, AU-2003.011, ESB-2003.0561, ISS Alert, S-03-057, N-133, SVA-2003.0004, Cisco, ESB-2003.0567, ESB-2003.0590
ID: ae-200308-038

The W32/Blaster worm exploits a vulnerability in Microsoft's DCOM RPC interface as described in VU#568148 and CA-2003-16. Upon successful execution, the worm attempts to retrieve a copy of the file msblast.exe from the compromising host. Once this file is retrieved, the compromised system then runs it and begins scanning for other vulnerable systems to compromise in the same manner. In the course of propagation, a TCP session to port 135 is used to execute the attack. However, access to TCP ports 139 and 445 may also provide attack vectors and should be considered when applying mitigation strategies. Microsoft has published information about this vulnerability in Microsoft Security Bulletin MS03-026.

System: Several systems
Topic: New ISS Summary
Links: AS03-32
ID: ae-200308-037

Within the last the last week 47 new vulnerabilities have been reported:

- ichain-url-redirect - lotusinstantmessaging-obtain-information - userwerbenhack-newuser-sql-injection
- vqServer-irunini-plaintext-password - everybuddy-message-dos - ccart-multiple-path-disclosure
- eroaster-tmp-lockfile-insecure - device-driver-gain-privileges - aspboard-url-xss
- postfix-mailfrom-rcptto-dos - dlink-http-configuration-dos - crob-command-dos
- postfix-ddos - crob-login-dos - compaq-insightmanager-format-string
- pocket-pc-gain-access - tcpflow-format-string - mandb-define-execute-commands
- smallhttp-httpcfg-plaintext-password - netbsd-osi-packet-dos - truetype-offbyone-memory-leak
- mindi-tempfile-insecure - mollensoft-users-plaintext-password - crob-rename-file-dos
- dlink-long-http-dos - dce-rpc-dos - netfilter-connectiontracking-dos
- ichain-username-bruteforce - ideal-bb-error-xss - cisco-css-syn-dos
- xtokkaetama-nickname-bo - ibm-db2-gain-privileges - iisshield-packet-filter-bypass
- forumwebserver-admin-default-password - mandb-opencatstream-gain-privileges - ibm-db2job-insecure-permissions
- up2date-gpg-automatic-install - bajie-userproperties-plaintext-password - dreamweaver-php-login-xss
- netfilter-networkaddresstranslation-dos - mandb-command-bo - 121wamserver-dotdot-directory-traversal
- tightvnc-security-bypass - sunone-source-disclosure - vbulletin-register-xss
- ipnetmonitorx-ipnetsentryx-obtain-info - invision-ibf-html-injection
System: Conectiva Linux
Topic: Vulnerability in lynx
Links: CLA-2003:720, OAR-2003.1024, CAN-2002-1405
ID: ae-200308-036

When handling a URL supplied through the command line, lynx does not filter out characters such as spaces, CR, LF, etc, which allows an attacker to inject HTTP headers and cause program misbehavior[2] by using a specially crafted URL. Patches are available now.

System: Sun Solaris
Topic: Vulnerability in kcms_server
Links: Sun Alert 50104, ESB-2003.0562
ID: ae-200308-035

A local or remote unprivileged user may be able to view root privileged files due to a security vulnerability involving the Solaris kcms_server(1) daemon. Patches are available now.

System: Red Hat Linux
Topic: Vulnerability in GtkHTML
Links: RHSA-2003-241, RHSA-2003-242, ESB-2003.0575
ID: ae-200308-034

ddskk does not take appropriate security precautions when creating temporary files. This bug could potentially be exploited to overwrite arbitrary files with the privileges of the user running Emacs and skk. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerability in perl-CGI module
Links: DSA-371, ESB-2003.0560
ID: ae-200308-033

A cross-site scripting vulnerability exists in the start_form() function in CGI.pm. Fixed packages are available now.

System: FreeBSD
Topic: Vulnerabilities in kernel
Links: FreeBSD-SA-03:09, FreeBSD-SA-03:10, ESB-2003.0557, ESB-2003.0558
ID: ae-200308-032

The ptrace(2) system call and the `spigot' video capture device driver do not properly validate the signal numbers. The kernel then attempts to deliver a negative or out-of-range signal number. Thus may used to crash the machine or in dertain cases to complete system compromise.
If iBCS2 support were enabled, a malicious user could call the iBCS2 version of statfs(2) with an arbitrarily large length parameter, causing the kernel to return a large portion of kernel memory. Such memory might contain sensitive information, such as portions of the file cache or terminal buffers.
Source code patches are available now.

System: OpenBSD
Topic: Vulnerabilities in kdelibs and konqueror
Links: OpenBSD
ID: ae-200308-031

Due to vulnerabilities in kdelibs and konqueror, OpenBSD has published new versions of these programs.

System: Microsoft Windows
Topic: Vulnerability in Crob FTP Server
Links: WinITSec
ID: ae-200308-030

A Denial of Service (DoS) vulnerability exists in Crob FTP Server 2.60.1. If an attacker sends the FTP server a file whose name contains words such as CON, AUX, COM1, LPT1, the server might stop responding to legitimate requests. A patch isn't available until now.

System: Red Hat Linux 8/9
Topic: Vulnerability in up2date
Links: RHSA-2003-255, ESB-2003.0556
ID: ae-200308-029

The Red Hat Update Agent, up2date, automatically queries the Red Hat Network servers and determines which packages need to be updated on your machine. Up2date versions 3.0.7 and 3.1.23 incorrectly check RPM GPG signatures. This allows packages which have no GPG signature to be installed by up2date if they are provided by the Red Hat Network servers. The intended behaviour is that only packages signed with the Red Hat package signing key will be installed. This problem is fixed with new RPMs.

System: Debian GNU/Linux
Topic: Vulnerabilities in xtokkaetama, xpcd, zblast, and pam-pgsql
Links: DSA-367, DSA-368, DSA-369, DSA-370, ESB-2003.0553, ESB-2003.0554
ID: ae-200308-028

A buffer overflow was discovered in xtokkaetama, involving the "-nickname" command line option. This vulnerability might be exploited by a local attacker to gain gid 'games'. Another buffer overflow in xpcd-svga can be triggered by a long HOME environment variable. This vulnerability could be exploited by a local attacker to gain root privileges. Due to a buffer overflow in zblast-svgalib when saving the high score file, a local user is able to gain gid 'games' by achieving a high score. A vulnerability in pam-pgsql has been found. If the username to be used for authentication is used as a format string when writing a log message, an attacker might execute arbitrary code with the privileges of the program requesting PAM authentication. Patches to fix these vulnerabilities are available now.

System: Sun Linux, Qube3, RaQ4, RaQXTR, RaQ550
Topic: Vulnerabilities in file and fileutils
Links: Sun Alert 56040, Sun Alert 56041
ID: ae-200308-027

The Sun Linux 5.0 file utility version 3.39 and earlier contains a buffer overflow vulnerability in the Executable and Linking Format (ELF) parsing routines. This vulnerability may allow a local unprivileged user to execute arbitrary code with the privileges of the user running the file command. Additionally, a race condition in Sun Linux fileutils 4.1 and earlier versions may allow a local unprivileged user to delete files or directories owned by others.
In the advisories, workarounds are described. Patches will be published soon.

System: Unix
Topic: Vulnerability in tcpflow
Links: @stake, OpenBSD
ID: ae-200308-026

Tcpflow is a network monitoring tool that records TCP sessions in an easy to use and view manner. This tool contains a format string vulnerability that is typically unexploitable. However, there has been at least a couple of network management tools (IPNetMonitorX and IPNetSentryX) that allowed for this vulnerability to be successfully exploited. It's recommended to upgrade tcpflow and ensure that it is not setuid root.

System: Mac OS X
Topic: Vulnerability in Network Tools
Links: @stake
ID: ae-200308-025

IPNetSentryX and IPNetMonitorX are network tools that provide firewalling and general network monitoring. Both of these tools come with three helper tools that each have security issues associated with them. The first two tools: RunTCPDump and RunTCPFlow allow arbitrary users to monitor the network without requiring any form of authentication or privilege. The third tool, tcpflow (executed by RunTCPFlow), contains a format string vulnerability, allowing arbitrary commands to be run as the user calling the program. Since RunTCPFlow is setuid root and will pass arguments to tcpflow, we can execute arbitrary commands as root. These vulnerabilities are mitigated in the latest version of IPNetSentryX and IPNetMonitorX available from http://www.sustworks.com

System: Trustix Secure Linux
Topic: Vulnerability in stunnel
Links: OAR-2003.1009
ID: ae-200308-024

If Stunnel is configured to start a new child process to handle each connection, it will receive a SIGCHLD signal when that child exits. Stunnel would perform tasks in the SIGCHLD signal handler which, if interrupted by another SIGCHLD signal, could be unsafe. This could lead to a denial of service. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Sun ONE/iPlanet Web Server and Application Server
Links: Sun Alert 54147, Sun Alert 56020, ESB-2003.0548, ESB-2003.0549
ID: ae-200308-023

In Sun ONE Application Server or Sun ONE/iPlanet Web Server, it may be possible to gather information about the data transmitted over a Secure Sockets Layer (SSL) or a Transport Layer Security (TLS) channel.
In the Sun ONE Application Server it may be possible to view the source code of JavaServer Pages (JSP) applications.
Patches are available now.

System: EnGarde Secure Linux
Topic: Vulnerability in stunnel
Links: OAR-2003.1003
ID: ae-200308-022

If Stunnel is configured to start a new child process to handle each connection, it will receive a SIGCHLD signal when that child exits. Stunnel would perform tasks in the SIGCHLD signal handler which, if interrupted by another SIGCHLD signal, could be unsafe. This could lead to a denial of service. Fixed packages are available now.

System: Red Hat Linux
Topic: Vulnerability in GtkHTML
Links: RHSA-2003-126
ID: ae-200308-021

GtkHTML is the HTML rendering widget used by the Evolution mail reader. GtkHTML contains a bug when handling HTML messages that could cause the Evolution mail component to crash. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerabilities in phpgroupware and eroaster
Links: DSA-365, DSA-366, ESB-2003.0547
ID: ae-200308-020

Several "cross-site-scripting" and SQL injection vulnerabilties were discovered in phpgroupware.
eroaster does not take appropriate security precautions when creating a temporary file for use as a lockfile.
Fixed packages are available now.

System: Several systems
Topic: New ISS Summary
Links: AS03-31
ID: ae-200308-019

Within the last the last week 70 new vulnerabilities have been reported:

- hp-network-traffic-dos - atari800-bo - weblogic-gain-privileges
- netscreen-screenos-registry-dos - linux-lockdev-setup-bo - samba-reply-nttrans-bo
- xtokkaetama-display-bo - irix-authunix-nsd-bo - netscreen-screenos-transparent-dos
- hughes-config-htpasswd-access - xconq-user-display-bo - sup-tmpfile-insecure
- win-rpc-dcom-bo-detected - netscreen-screenos-tcp-dos - halflife-udp-packet-bo
- hassan-cart-information-disclosure - e107-post-obtain-information - gallery-search-xss
- linux-decodefh-packet-dos - halflife-mod-liblist-bo - mandb-command-line-bo
- cisco-leap-dictionary - mandb-multiple-functions-bo - gamespyarcade-gsapak-file-upload
- multiple-browsers-obtain-information - freeradius-chap-bo - cisco-ios-http-bo
- rav-ravonline-update-bo - ef-commander-banner-bo - cdrtools-rscsi-gain-privileges
- hp-phne-dos - dual-boot-bios-dos - robotftp-rftpsrvr-plaintext-passwords
- mandb-so-bo - xblast-home-bo - e107-class2-xss
- epolicy-long-post-bo - cisco-ios-info-leak - epolicy-msde-obtain-password
- symantec-antivirus-quarantine-dos - outpost-close-window-dos - cisco-ios-account-bruteforce
- macosx-screensaver-auth-bypass - qmailadmin-forward-execute-commands - kde-konqueror-plaintext-password
- mandb-addtodirlist-bo - guidescope-spam-relay - halflife-mod-code-execution
- liteserve-plaintext-passwords - modmylo-http-request-bo - epolicy-computerlist-format-string
- epolicy-http-directory-traversal - netware-accesslog-plaintext-password - solaris-code-dos
- halflife-client-connection-bo - msql-format-string - solaris-race-condition
- winnt-q823803i-rras-dos - xtokkaetama-xtokkaetamadir-bo - wuftp-fbrealpath-offbyone-bo
- mitel-voip-info-disclosure - mandb-bo - top-environment-variables-bo
- opera-protocolname-dos - sun-ldso1-ldpreload-bo - telnetxq-gain-access
- roundup-client-xss - cisco-aironet-http-dos - iis-asp-file-upload
- halflife-parameter-dos
System: HP-UX
Topic: Vulnerability in rpc.mountd
Links: HPSBUX0307-272, ESB-2003.0542 ESB-2003.0551
ID: ae-200308-018

The error messages returned by rpc.mountd can be used to determine whether a file exists. A patch is available now.

System: NetBSD
Topic: Vulnerability in OSI networking code
Links: NetBSD-SA2003-010, ESB-2003.0539
ID: ae-200308-017

It is possible to crash an OSI connected system remotely by sending it a carefully prepared OSI networking packet. A patch is available now.

System: Debian Linux
Topic: Vulnerabilities in man-db
Links: DSA-364, ESB-2003.0544, ESB-2003.0578
ID: ae-200308-016

Multiple buffer overflows in man-db, when installed setuid, allow local users to gain privileges via log values of environment variables. Additionally certain DEFINE directives in ~/.manpath, which contained commands to be executed, would be honored even when running setuid, allowing any user to execute commands as the "man" user. Updated packages fix these problems.

System: Conectiva Linux
Topic: Vulnerability in wget
Links: CLA-2003:716, OAR-2003.0996
ID: ae-200308-015

A buffer overflow was found wget when handling long URLs. Patches are available now.

System: FreeBSD, NetBSD, OpenBSD
Topic: Vulnerability in realpath
Links: VU#743092, FreeBSD-SA-03:08, ESB-2003.0535, NetBSD-SA2003-011, ESB-2003.0545, OpenBSD, ESB-2003.0540
ID: ae-200308-014

An off-by-one error exists in a portion of realpath(3) that computes the length of the resolved pathname. Applications using realpath(3) MAY be vulnerable to denial of service attacks, remote code execution, and/or privilege escalation. Source code patch is available now.

System: SuSE Linux
Topic: Vulnerability in imagemagick
Links: SuSE 8.1, SuSE 8.2
ID: ae-200308-013

imagemagick's libmagick library creates temporary files without taking appropriate security precautions. Fixed packages are available now.

System: Mandrake Linux
Topic: Vulnerability in PHP
Links: MDKSA-2003:082, MDKSA-2003:082-1, OAR-2003.0992
ID: ae-200308-012

In PHP when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a cross-site scripting attack. Fixed packages are available now.

System: Debian Linux
Topic: Vulnerabilities in xfstt and mindi
Links: DSA-360, DSA-362, ESB-2003.0534, ESB-2003.0537
ID: ae-200308-011

Several buffer overflows were found in xfstt, a TrueType font server for the X window system.
mindi does not take appropriate security precautions when creating temporary files. This bug could potentially be exploited to overwrite arbitrary files with the privileges of the user running mindi.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in postfix
Links: VU#895508, DSA-363, ESB-2003.0538, RHSA-2003-251, ESB-2003.0543, MDKSA-2003:081, SuSE-SA:2003:033
ID: ae-200308-010

A malformed envelope address can cause the queue manager to lock up until an entry is removed from the queue and also lock up the SMTP listener leading to a DoS. Postfix also allows an attacker to bounce- scan private networks or use the daemon as a DDoS (Distributed Denial of Service) tool by forcing the daemon to connect to an arbitrary service at an arbitrary IP address and receiving either a bounce message or by timing. Fixed packages are available now.

System: Microsoft Windows
Topic: Worm MIMAIL spreading in the Internet
Links: IN-2003-02, ESB-2003.0533
ID: ae-200308-009

The worm MIMAIL is spreading in the Internet. It exploits vulnerabilities reported in April this year (MS03-014). A typical mail from this worm looks like this:
Subject: your account <any string>
Body: Hello there, I would like to inform you about important
information regarding youremail address.
This email address will be expiring. Please read attachment for details.
Best regards,
Administrator
Attachment: "message.zip"
So please be sure to have the patch from Microsoft installed an to have your antivirus software up to date.

System: Some
Topic: Information leak in GroupWise (Wireless) WebAccess 6.5
Links: Novell, OAR-2003:0982
ID: ae-200308-008

When wireless phone users login to GroupWise WebAccess the userid and password are recorded in the webserver's access_log file below the directory of Apache. How to prevent wireless phone user's userid and password from being written to the access_log is described in the advisory.

System: Debian Linux
Topic: Vulnerabilities in xfstt
Links: DSA-360, OAR-2003:0980
ID: ae-200308-007

Xfstt is a TrueType font server for the X window system which is vulnerable to two classes of vulnerabilities. If a remote attacker sends requests several buffer overruns might be triggered, causing a Denial-of-Service or executing arbitrary code on the server with the privileges of the "nobody" user. Certain invalid data sent during the connection handshake might allow a remote attacker to read certain regions of memory belonging to the xfstt process. This information can be used for fingerprinting and might be an aid for exploiting different vulnerabilities. An updated package fixes these problems.

System: Cisco
Topic: Vulnerability in LEAP
Links: Cisco
ID: ae-200308-006

The Light Extensible Authentication Protocol (LEAP) authentication algorithm supports dynamic derivation of session keys in wireless networks. The authentication relies on a shared secret (the user's logon password) which is known by the client and the network and is used to respond to challenges between the user and the Remote Authentication Dial-In User Service (RADIUS) server. As with most password-based authentication algorithms, Cisco LEAP is vulnerable to dictionary attacks. Creating a strong password policy is the most effective way to mitigate against dictionary attacks. This includes using strong passwords and periodically expiring passwords. Cisco recommends to review and to use their latest security paper.

System: Microsoft Windows NT, 2000, XP, Server 2003
Topic: Exploitation of Vulnerabilities in Microsoft RPC Interface
Links: CA-2003-19, MS03-026, CPSA-2003-08, OAR-2003:0975
ID: ae-200308-005

Multiple exploits for this vulnerability have been publicly released, and there is active development of improved and automated exploit tools for this vulnerability. Known exploits target TCP port 135 and create a privileged backdoor command shell on successfully compromised hosts, but also other ports might be used. So it's strongly recommended to block the concerning ports using a firewall and to update vulnerable systems immediately!

System: Cisco IOS
Topic: Data leak in UDP Echo Service
Links: Cisco, ISS, OAR-2003:0976
ID: ae-200308-004

If the udp-small-servers command is enabled, a Cisco IOS software device may reply to malformed udp echo packets with some of the contents stored in a router's memory. By repeatedly sending malformed udp echo packets and capturing the replies, an attacker can obtain portions of the data that is stored in a router's memory. Cisco has published a paper now to use the command "no service udp-small-servers" to avoid this vulnerability.

System: HP OpenVMS
Topic: Vulnerability in OpenSSL
Links: SSRT3499, SSRT3518, OAR-2003:0972
ID: ae-200308-003

The well known vulnerability affects OpenVMS also. Local or remote users might obtain the server's private encryption key. An additional vulnerability in OpenSSL may allow remote users to perform an unauthorized RSA private key operation. The resolutions for these vulnerabilities are included in HP SSL for OpenVMS V1.1 kit.

System: Debian Linux
Topic: Vulnerabilities in kernel and atari800
Links: DSA-358, DSA-359, ESB-2003.0528, ESB-2003.0573
ID: ae-200308-002

Several security issues have been discovered affecting the Linux kernel that involve the execve() system call, the /proc Filesystem, the RPC code, the STP protocoll and the forwarding table.
Multiple buffer overflows were discovered in atari800, an Atari emulator.
Fixed packages are available now.

System: Various
Topic: Vulnerability in wu-ftpd
Links: AL-2003.13, VU#743092, DSA-357, ESB-2003.0527, RHSA-2003-245, RHSA-2003-246, N-132, ESB-2003.0526, MDKSA-2003:080, SuSE-SA:2003:032, TLSA-2003-46, Sun Alert 56220, ESB-2003.0605, CSSA-2003-024., CSSA-2003-SCO.20
ID: ae-200308-001

The Washington University FTP (File Transfer Protocol) server daemon, 'wu-ftpd', contains an off-by-one buffer overflow. On a vulnerable system, a remote attacker would be able to exploit this bug to gain root privileges. Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH