Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-107-20-129-212.compute-1.amazonaws.com [107.20.129.212]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 12 / 2005

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in imap and xpdf
Links: SGI-20051201-01
ID: ae-200512-062

SGI has released the Security Update #52 for SGI Advanced Linux Environment 3. These updates fix security related problems in imap and xpdf. So it's recommended to install these updates.

System: Mandriva Linux
Topic: Vulnerability in printer-filters-utils
Links: MDKSA-2005:239
ID: ae-200512-061

A local root vulnerability has been found in the mtink binary. It has a buffer overflow in its handling of the HOME environment variable, allowing the possibility for a local user to gain root privileges. Mandriva encourages all users to upgrade immediately to the updated packages.

System: Research in Motion (RIM)
Topic: Vulnerabilities in BlackBerry
Links: RIM KB-04758, VU#392920,
RIM KB-04757, VU#570768, Q-087
ID: ae-200512-060

The Research in Motion (RIM) BlackBerry Router contains a vulnerability in the way the router handles Server Routing Protocol (SRP) packets. By sending specially crafted SRP packets to the router, an attacker might cause a Denial-of-Service, disrupting communication between BES components and BlackBerry Handheld devices.
The Research in Motion (RIM) BlackBerry Attachment Service contains a vulnerability in the way the service handles TIFF files. By supplying a specially crafted TIFF image as an email attachment and convincing a user to view the image on a BlackBerry Handheld, a remote, unauthenticated attacker could cause a Denial-of-Service and maybe execute arbitrary code on the system.
These issue have been escalated internally, so a patches will follow.

System: Microsoft Windows XP, Microsoft Windows Server 2003
Topic: Vulnerability caused by WMF files
Links: VU#181038, Secunia #18255, Q-085, ISS Alert #211, AL-2005.0043, AU-2005-0023, Symantec
ID: ae-200512-059

Microsoft Windows Metafile format images are graphical files and Microsoft Windows contains routines for displaying these files. Due to a lack of input validation in one of these routines may allow a buffer overflow to occur, and in turn may allow remote arbitrary code execution with the rights of the Windows user. Current public exploits use the Windows Picture and Fax Viewer (SHIMGVW.DLL) as an attack vector affecting users of any Windows-based application that can handle Windows Metafiles. Until now, no patch is available.

System: Mandriva Linux
Topic: Vulnerability in php/php-mbstring
Links: MDKSA-2005:238, CVE-2005-3883
ID: ae-200512-058

A CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary E-Mail headers via line feeds (LF) in the "To" address argument, when using sendmail as the MTA (mail transfer agent). An updated package solves this problem.

System: Some
Topic: Vulnerability in VMWare
Links: VU#856689, ESB-2005.1013
ID: ae-200512-057

The VMware NAT Service used in multiple VMware products contains a buffer overflow in the way it handles FTP PORT and EPRT commands. An attacker might execute arbitrary code with the privileges of the NAT service or cause a Denial-of-Service (DoS). It's recommended to upgrade to a fixed version.

System: Sun Solaris
Topic: Vulnerability in PC Netlink 2.0
Links: Sun Alert 102117, Sun Alert 102122, ESB-2005.1010
ID: ae-200512-056

A security vulnerability in the "/etc/init.d/slsadmin" script in PC NetLink 2.0 may allow files to be opened insecurely, which could allow an unprivileged local user the ability to write to the filesystem with the permissions of the user running "slsadmin." If "slsadmin" is run as "root," it may allow a local unprivileged user to gain elevated privileges on the system and run arbitrary commands.
A patch is available now.

System: Debian GNU/Linux
Topic: Vulnerability in dhis-tools-dns
Links: DSA-928, CVE-2005-3341, ESB-2005.1012
ID: ae-200512-055

The dhis-tools-dns package contains DNS configuration utilities for a dynamic host information System. It's usually executed by root and it creates temporary files in an insecure manner. An updated package solves this problem.

System: Debian GNU/Linux
Topic: Vulnerability in tkdiff
Links: DSA-927, CVE-2005-3343, ESB-2005.1011
ID: ae-200512-054

Tkdiff is a graphical side by side "diff" utility. It creates temporary files in an insecure fashion. An updated package solves this problem.

System: Turbolinux
Topic: Vulnerabilities in gdk-pixbuf, gtk2, openssh, and squid
Links: TLSA-2005-98, TLSA-2005-99, CAN-2005-2976, CAN-2005-3186,
TLSA-2005-100, CAN-2005-2798,
TLSA-2005-101, CAN-2005-2917, CAN-2005-3258
ID: ae-200512-053

The GdkPixBuf library provides a number of features. Multiple vulnerabilities have been discovered in the handling of libXpm for gdk-pixbuf. Additionally, the gtk+ package contains the GIMP ToolKit (GTK+), a library for creating graphical user interfaces for the X Window System. Two vulnerabilities have been discovered in the handling of libXpm for gtk2. Both vulnerabilities may allow remote attackers to execute arbitrary code via malformed XPM image files.
OpenSSH is a free version of the SSH protocol suite of network connectivity tools. The sshd in OpenSSH, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts. So access controls can be bypassed.
Squid is a high-performance proxy caching server for web clients. It allows remote attackers to cause a Denial-of-Service (crash) via certain crafted requests.
Updated packages solve these problems.

System: Mandriva Linux
Topic: Vulnerabilities in fetchmail and cpio
Links: MDKSA-2005:236, CVE-2005-4348,
MDKSA-2005:237, CVE-2005-4268
ID: ae-200512-052

Fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a Denial-of-Service (DoS) because the application crashes if an attacker sends messages without headers from upstream mail servers.
A buffer overflow in cpio 2.6 on 64-bit platforms could also allow a local user to create a DoS and possibly execute arbitrary code when creating a cpio archive with a file whose size is represented by more than 8 digits.
Updated packages solve these problems.

System: Debian GNU/Linux
Topic: Vulnerability in ketm
Links: DSA-926, CVE-2005-3535
ID: ae-200512-051

Ketm is an old school 2D-scrolling shooter game. Du to a buffer overflow it's possible to execute arbitrary code with group games privileges. An updated package solves this problem.

System: Microsoft Windows
Topic: Vulnerability in McAfee Security Center
Links: iDEFENSE #358, CVE-2005-3657, ESB-2005.1009
ID: ae-200512-050

McAfee VirusScan is an anti-virus software. Remote exploitation of an access control vulnerability in McAfee Security Center allows attackers to create or overwrite arbitrary files. The vulnerability is due to a registered ActiveX control failing to restrict which domains may load the control for execution. MCINSCTL.DLL as included with McAfee Security Center exports an object for logging called MCINSTALL.McLog. The McLog object is designed to allow Security Center to log to a file through the StartLog and AddLog methods. McAfee fails to restrict the ActiveX control from being loaded in arbitrary domains. As such, attackers can create a specially crafted web page utilizing the McLog object to create arbitrary files. This attack can lead to arbitrary code execution by a remote attacker. McAfee previously released updates to SecurityCenter that resolve this issue.

System: Symantec
Topic: Vulnerability in RAR File Parser
Links: rem0te, VU#305272, ISS Alert #210
ID: ae-200512-049

The Symantec RAR decompression library Dec2RAR.dll contains multiple heap buffer overflows. Using a specially crafted RAR archive, a remote attacker could execute arbitrary code or cause a Denial-of-Service. A patch isn't available yet, so the scanning of RAR archives could be disabled.

System: SCO OpenServer
Topic: Vulnerabilities in Xloadimage, wu-ftp, and by TCP
Links: SCOSA-2005.62, CVE-2005-3178,
SCOSA-2005.63, CVE-2005-0256,
SCOSA-2005.65, CVE-2005-0356
ID: ae-200512-048

A buffer overflow in xloadimage might allow attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during zoom, reduce, or rotate operations.
The wu_fnmatch function in wu_fnmatch.c of the wu-ftpd allows remote attackers to cause a Denial-of-Service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, which can e.g. provided with the dir command.
TCP doesn't adequately validate segments before updating timestamp value, allowing a remote attacker to arbitrarily modify host timestamp values that will in turn cause TCP connections to abort/drop segments, leading to a Denial-of-Service condition.
Updated packages solve these problems.

System: Mandriva Linux
Topic: Vulnerabilities in sudo and kernel
Links: MDKSA-2005:234, CVE-2005-4158,
MDKSA-2005:235, CVE-2005-2490, CVE-2005-2492, CVE-2005-2873, CVE-2005-3044, CVE-2005-3055, CVE-2005-3179, CVE-2005-3181, CVE-2005-3257, CVE-2005-3274
ID: ae-200512-047

A vulnerability in sudo versions prior to 1.6.8p12 has been found. When the perl taint flag is off, sudo doesn't clear the PERLLIB, PERL5LIB, and PERL5OPT environment variables, which could allow limited local users to cause a perl script to include and execute arbitrary library files that have the same name as library files that included by the script. In addition, other environment variables have been included in the patch that remove similar environment variables that could be used in python and ruby, scripts, among others. Updated packages have been patched to correct this problem.
Additionally, a new kernel package has been published, fixing several vulnerabilities in the kernel.

System: Debian GNU/Linux
Topic: Vulnerabilities in nbd and phpbb2
Links: DSA-924, CVE-2005-3534, ESB-2005.1004,
DSA-925, CVE-2005-3310, CVE-2005-3415, CVE-2005-3416, CVE-2005-3417, CVE-2005-3418, CVE-2005-3419, CVE-2005-3420, CVE-2005-3536, CVE-2005-3537
ID: ae-200512-046

It has been found out, that nbd, the network block device client and server could potentially allow arbitrary code on the NBD server.
PhpBB is a fully featured and skinnable flat webforum. It shows several vulnerabilities which might lead to script injection, bypass protection and security mechanisms, Cross-Site Scripting, modification of global variables, SQL injection and more.
Updated packages solve these problems.

System: Cisco
Topic: Vulnerability in Cisco Clean Access / Perfigo CleanMachines
Links: BugTraq, Cisco, Q-084
ID: ae-200512-045

Cisco Clean Access is a Network Admission Control solution that can automatically detect, isolate, and clean infected or vulnerable devices that attempt to access the network. A method has been published to create a Denial-of-Service on a few layers. One, a user without a username or password can use the vulnerability to upload files to a web visable folder, leading to a DoS when the drive is filled. To carry out this attack, jsp files are used. Cisco recommends to remove obsolete jsp files and has published a patch for customers.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in netpbm, udev, curl, and cups
Links: RHSA-2005-843, CVE-2005-3632, CVE-2005-3662, Q-081, ESB-2005.0998,
RHSA-2005-864, CVE-2005-3631, Q-080, ESB-2005.0999,
RHSA-2005-875, CVE-2005-4077, Q-078, ESB-2005.1008,
RHSA-2005-878, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193, ESB-2005.1002
ID: ae-200512-044

Several buffer overflows were discovered in pnmtopng which is also included in netpbm, a collection of graphic conversion utilities, that can lead to the execution of arbitrary code via a specially crafted PNM file.
A flaw was discovered in the way udev sets permissions on various files in /dev/input. It may be possible for an authenticated attacker to gather sensitive data entered by a user at the console, such as passwords.
An off-by-one bug was discovered in curl. It may be possible to execute arbitrary code on a user's machine if the user can be tricked into executing curl with a carefully crafted URL.
Several flaws were discovered in the way CUPS processes PDF files. An attacker could construct a carefully crafted PDF file that could cause CUPS to crash or possibly execute arbitrary code when opened.
Fixed packages are available now.

System: Various
Topic: Vulnerability in Perl
Links: CVE-2005-3962, RHSA-2005-880, RHSA-2005-881, ESB-2005.1005, ESB-2005.1006, Q-082, Q-083, SUSE-SA:2005:071
ID: ae-200512-043

Integer overflows in the format string functionality in Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap. Fixed software is available now.

System: HP-UX
Topic: Vulnerability in WBEM Services
Links: HPSBUX02088, SSRT051026, ESB-2005.0997
ID: ae-200512-042

A vulnerability has been identified with HP-UX systems running WBEM Services. The vulnerability could be exploited remotely to create a Denial of Service (DoS). HP has made software updates available to resolve the issue.

System: Mandriva Linux
Topic: Vulnerability in apache2
Links: MDKSA-2005:233, CVE-2005-2970
ID: ae-200512-041

A memory leak in the worker MPM in Apache 2 could allow remote attackers to cause a Denial of Service (memory consumption) via aborted commands in certain circumstances, which prevents the memory for the transaction pool from being reused for other connections. Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in dropbear
Links: DSA-923, CVE-2005-4178, ESB-2005.0996
ID: ae-200512-040

A buffer overflow has been discovered in dropbear, a lightweight SSH2 server and client, that may allow authenticated users to execute arbitrary code as the server user (usually root). Fixed packages are available now.

System: SCO OpenServer
Topic: Vulnerabilities in gzip and tcpdmp
Links: SCOSA-2005.59, CVE-2005-0758, CVE-2005-0988, CVE-2005-1228,
SCOSA-2005.61, CVE-2005-1278, CVE-2005-1279, CVE-2005-1280
ID: ae-200512-039

Zgrep in gzip doesn't properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. A race condition in gzip, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. A directory traversal vulnerability in gunzip -N allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
Various flaws in tcpdump can allow remote attackers to cause Denial-of-Service (DoS).
Updated packages solve these problems.

System: Microsoft Windows
Topic: Vulnerability in Citrix Program Neighborhood client
Links: iDEFENSE #357, CVE-2005-3652, CTX108354, Q-077
ID: ae-200512-038

The Citrix Program Neighborhood client supports a UDP based application enumeration mechanism. If this functionality is used to present the client in version 9.1 and earlier for 32-bit and 64-bit Windows with a very long application name then an implementation flaw in the client could result in an internal buffer being overflowed. It's possible that this buffer overflow could be used to execute malicious code within the client process. This issue has been fixed in version 9.150, which is ready for download now.

System: IBM AIX 5.x
Topic: Vulnerabilities in muxatmd, diagela, and slocal
Links: ESB-2005.0989, ESB-2005.0990, ESB-2005.0991
ID: ae-200512-037

Buffer overflow vulnerabilities in muxatmd and slocal may allow any local user to gain root privileges. A vulnerability was discovered in the diagela script that allows a local user that is in the system group and that has the RunDiagnostics role to execute arbitrary code. Exploits for this vulnerability may be publicly available. Fixes solve these problems.

System: SuSE Linux
Topic: Several vulnerabilities in php4/php5 and in kernel
Links: SuSE_2005_69, SuSE_2005_68
ID: ae-200512-036

Updated PHP packages fix the some security issues, which might also lead to remote code execution. Several vulnerabilities have been discovered in the kernel, the core of a linux system. A fixed package solves these vulnerabilities, too.

System: Some
Topic: Vulnerabilities in Macromedia ColdFusion MX 7
Links: mpsb05-14, ESB-2005.0992
ID: ae-200512-035

A new cumulative security rollup contains security patches potential vulnerabilities. ColdFusion Sandbox security relies on the Java SecurityManager. When ColdFusion is running on a JRun 4 cluster member and the SecurityManager is disabled, Sandbox security silently fails without throwing an exception. With Sandbox security disabled a remote attacker using an application setup to use Sandbox security could potentially bypass security controls. Additionally, an application written to use the CFMAIL tag could be used to attach arbitrary files and send mail with any content. This is due to weak input validation in the "Subject" field. Setting CFOBJECT /CreateObject(Java) to be disabled in Sandbox security has no effect, still allowing a local attacker to create an object. Finally, the password hash used to authenticate the ColdFusion Administrator is exposed via an API call, allowing a local developer to obtain the hash and authenticate as Administrator.

System: Some
Topic: Vulnerabilities in Macromedia JRun 4.0 server
Links: mpsb05-13, ESB-2005.0992
ID: ae-200512-034

A new updater solves some problems in the JRun 4.0 server. A remote attacker could enter a malformed URL causing JRun to return web application source code. The JRun Web Server improperly handles long URLs and headers allowing a remote attacker to cause a Denial-of-Service. Macromedia doesn't recommend the JWS be used as a production web server.

System: Some
Topic: Vulnerabilities in Macromedia ColdFusion MX 6.X
Links: mpsb05-12, ESB-2005.0992
ID: ae-200512-033

A new cumulative security rollup contains security patches for two potential vulnerabilities. ColdFusion Sandbox security relies on the Java SecurityManager. When ColdFusion is running on a JRun 4 cluster member and the SecurityManager is disabled, Sandbox security silently fails without throwing an exception. With Sandbox security disabled a remote attacker using an application setup to use Sandbox security could potentially bypass security controls. Additionally, an application written to use the CFMAIL tag could be used to attach arbitrary files and send mail with any content. This is due to weak input validation in the "Subject" field.

System: Some
Topic: Vulnerability in Macromedia Flash Media Server
Links: mpsb05-11, ESB-2005.0992
ID: ae-200512-032

Flash Media Server remote administrator interface connects using TCP to port 1111. An error exists in the way that the server handles malformed data allowing a remote attacker to crash the administrator service. Workarounds to limit the exposure to attacks is described in the advisory.

System: Some
Topic: Vulnerability in FFmpeg libavcodec
Links: MDKSA-2005:228, MDKSA-2005:229, MDKSA-2005:230, MDKSA-2005:231, MDKSA-2005:232, CVE-2005-4048
ID: ae-200512-031

A vulnerability in FFmpeg libavcodec has been found. It can be exploited by malicious people to cause a DoS (Denial-of-Service) and potentially to compromise a user's system. This code is used by xine-lib, xmovie, mplayer, ffmpeg, and gstreamer-ffmpeg, so these programs are vulnerable. Updated packages fix this problem.

System: Some
Topic: Vulnerabilities in curl and Apache 1.3x
Links: OpenPKG-SA-2005.028, CVE-2005-4077,
OpenPKG-SA-2005.029, CVE-2005-3352
ID: ae-200512-030

A Denial-of-Service (DoS) vulnerability exists in "libcurl", the underlying library of the cURL networking tool. The reason are two off-by-one errors in libcurl's URL parser which a buffer overflow.
A Cross-Site Scripting (XSS) vulnerability exists in the Apache HTTP server. The flaw exists in the "mod_imap" extension module and occurs when using the "Referer" directive with image maps. In certain configurations a remote attacker could perform an XSS attack if a victim can be forced to visit a malicious URL using certain web browsers.
Updated packages are available now.

System: SCO UnixWare
Topic: Vulnerabilities in lynx, Xloadimage, and libXpm
Links: SCOSA-2005.55, CVE-2005-2929,
SCOSA-2005.56,
SCOSA-2005.57, CVE-2005-0605
ID: ae-200512-029

Remote exploitation of a command injection vulnerability in Lynx might allow attackers to execute arbitrary commands with the privileges of the underlying user. The reason is the URI handler "lynxcgi:".
In Xloadimage the titles of NIFF Images aren't handled correctly, so a buffer overflow is possible.
An integer overflow vulnerability in libXpm can be exploited by a remote user to cause arbitrary code to be executed.
Updated packages solve these problems.

System: Debian GNU/Linux
Topic: Several vulnerabilities in the kernel
Links: DSA-921, DSA-922, ESB-2005.0982, ESB-2005.0988
ID: ae-200512-028

Several vulnerabilities in the kernel have been fixed now. It's recommended to use kernel 2.4.27 or 2.6.8 only and to upgrade immediately, because some vulnerabilities are critical.

System: Microsoft Windows
Topic: Several vulnerabilities in Trend Micro Server Protect
Links: iDEFENSE #352, CVE-2005-1930, ESB-2005.0984,
iDEFENSE #353, iDEFENSE #354, CVE-2005-1929, ESB-2005.0985, ESB-2005.0986,
iDEFENSE #356, CVE-2005-1928, ESB-2005.0987
ID: ae-200512-027

Trend Micro Server Protect is a centrally managed solution for Anti-Virus. Three vulnerabilities have been detected in the Management Console 5.58 running with Trend Micro Control Manager 2.5/3.0 and Trend Micro damage Cleanup Server 1.1. The first is reasoned by the handling of the IMAGE parameter in the script rptserver.asp. When supplying special data, an attacker is able to have a remote view on all files on the system. Two other vulnerabilities give remote attackers the chance to execute arbitrary code on the system with the rights of the web server. Providing relay.dll or isaNVWRequest.dll with special content, the heap will be damaged and the supplied code will be executed. Finally, a remote Denial-of-Service against the EarthAgent Daemon is possible by sending specially crafted packets to port 5005/tcp.
For the fourth vulnerability, a patch is available. The others can be fixed by workarounds described in the concerning advisory.

System: Microsoft Windows
Topic: Vulnerability in Trend Micro PC-cilin
Links: iDEFENSE #351, CVE-2005-3360, ESB-2005.0983
ID: ae-200512-026

Trend Micro PC-Cillin Internet Security is antivirus protection software for home and business use. During the installation the default Access Control List (ACL) settings aren't save, so a local user can modify the installed files. Due to the fact that some of the programs run as system services, a user could replace an installed Trend Micro product file with their own malicious code, and the code would be executed with system privileges. An updated version solves this problem.

System: Microsoft Windows 2000
Topic: Vulnerability in Windows Kernel
Links: MS05-055, CAN-2005-2587, Q-075, ESB-2005.0981
ID: ae-200512-025

No further comment due to legal reasons.

System: Microsoft Windows
Topic: Cumulative update for Microsoft Internet Explorer
Links: MS05-054, CAN-2005-1790, CAN-2005-2829, CAN-2005-2830, CAN-2005-2831, Secunia 2005-7, Secunia 2005-12, VU#887861, Q-074, AL-2005.0042, Symantec
ID: ae-200512-024

No further comment due to legal reasons.

System: SCO UnixWare
Topic: Vulnerabilities in OpenSSH and uidadmin
Links: SCOSA-2005.53, CVE-2005-2797, CVE-2005-2798,
SCOSA-2005.54, iDEFENSE #350, CVE-2005-3903, ESB-2005.0979
ID: ae-200512-023

SCO has released updated packages to address two vulnerabilities identified in OpenSSH. These flaws might be exploited by attackers to disclose sensitive information or bypass security restrictions.
Local exploitation of a buffer overflow vulnerability in the uidadmin binary included in multiple versions of UnixWare allows attackers to gain root privileges. The main reason is because uidadmin is setuid root. An updated package solves this proble, too.

System: Some
Topic: Vulnerability in Mozilla MailNews und Mozilla Thunderbird
Links: MDKSA-2005:226, CVE-2005-3256
ID: ae-200512-022

A bug in enigmail, the GPG support extension for Mozilla MailNews and Mozilla Thunderbird was discovered that could lead to the encryption of an E-Mail with the wrong public key. This could potentially disclose confidential data to unintended recipients. An updated packages have been patched to prevent this problem.

System: Debian GNU/Linux
Topic: Vulnerability in curl
Links: DSA-919, CVE-2005-4077, CVE-2005-3185, ESB-2005.0978
ID: ae-200512-021

A vulnerability has been discovered a buffer overflow in libcurl that could allow the execution of arbitrary code. Several off-by-one errors allow local users to trigger a buffer overflow and cause a Denial-of-Service or bypass PHP security restrictions via certain URLs. An updated package remedies these problems.

System: Mandriva Linux
Topic: Vulnerabilities in curl and perl
Links: MDKSA-2005:224, CVE-2005-4077,
MDKSA-2005:225, CVE-2005-3962
ID: ae-200512-020

Libcurl's URL parser function can have a malloced buffer overflows in two ways if given a too long URL. It cannot be triggered by a redirect, which makes remote exploitation unlikely, but can be passed directly to libcurl (allowing for local exploitation) and could also be used to break out of PHP's safe_mode/ open_basedir. This vulnerability only exists in libcurl and curl 7.11.2 up to and including 7.15.0. An updated packages have been patched to correct the problem. As well, updated php-curl packages are available that provide a new curl PHP module compiled against the fixed code.
A new way to exploit format string errors in the Perl programming language might lead to the execution of arbitrary code. Updated packages are available now.

System: Various
Topic: Vulnerability in Ethereal
Links: iDEFENSE #349, CVE-2005-3651, ESB-2005.0976,
DSA-920, ESB-2005.0980, MDKSA-2005:227
ID: ae-200512-019

Ethereal is a full featured open source network protocol analyzer. Remote exploitation of an input validation vulnerability in the OSPF protocol dissectors within Ethereal, as included in various vendors operating system distributions, could allow attackers to crash the vulnerable process or potentially execute arbitrary code. It's recommended to disable the OSPF dissector or to install a patch.

System: Dell TrueMobile 2300
Topic: Authentication bypass vulnerability
Links: iDEFNSE #348, CVE-2005-3661, ESB-2005.0977
ID: ae-200512-018

The Dell TrueMobile 2300 Wireless Broadband Router is an 802.11b/g wireless access point, wired ethernet switch and internet router. By requesting a special url from the router, it's possible to obtain a page containing a form which allows you to reset the authentication credentials. Exploitation could allow remote attackers to associate with the internal side of the router to change any configuration settings, including uploading of new firmware. Dell is no longer selling this product and has replaced it with newer models that do not exhibit the defect. Therefore, a patch will not be released to address this issue.

System: Sun Solaris
Topic: Vulnerability in IBM Tivoli Directory Server
Links: IBM, VU#194753, Q-073
ID: ae-200512-017

A potential security vulnerability has been identified by IBM for the IBM Tivoli Directory Server (ITDS). Exploiting this vulnerability may allow unauthorized access to change, modify and/or delete directory data stored in IBM Tivoli Directory Server. Patches are available now.

System: Sun Solaris
Topic: Vulnerability in Sun Update Connection Services
Links: Sun Alert 102090, ESB-2005.0972, Q-072
ID: ae-200512-016

Solaris 10 with Sun Update Connection Services, a web proxy password may be visible to unauthorized local users on the affected system and also in the web proxy log files at the web proxy server. In addition, this issue prevents Sun Update Connection from authenticating to the web proxy server. Patches are available now.

System: Various
Topic: Vulnerability in phpMyAdmin
Links: Hardened-PHP, ESB-2005.0973
ID: ae-200512-015

phpMyAdmin comes with a register_globals emulation layer within grab_globals.php, to ensure compatibility with hosts where this feature is turned off. A bug in this feature opens phpMyAdmin to a number of XSS, local and remote file inclusion vulnerabilities. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in courier and osh
Links: DSA-917, CVE-2005-3532, ESB-2005.0971,
DSA-918, CVE-2005-3347, CVE-2005-3533, ESB-2005.0975
ID: ae-200512-014

It was discovered that courier-authdaemon, the authentication daemon of the Courier Mail Server, grants access to accounts that are already deactivated.
Two security related problems have been discovered in osh, the operator's shell for executing defined programs in a privileged environment. A bug in the substitution of variables allows a local attacker to open a root shell. A buffer overflow caused by the current working directory plus a filename could be used to execute arbitrary code and e.g. open a root shell.
Fixed packages are available now.

System: SuSE Linux
Topic: Several vulnerabilities in kernel
Links: SuSE_2005_67, CVE-2005-2973, CVE-2005-3044, CVE-2005-3055, CVE-2005-3180, CVE-2005-3181, CVE-2005-3271, CVE-2005-3527, CVE-2005-3783, CVE-2005-3784, CVE-2005-3805, CVE-2005-3806, CVE-2005-3807
ID: ae-200512-013

Several vulnerabilities have been discovered in the kernel, the core of a linux system. A fixed package solves these vulnerabilities.

System: Various
Topic: Vulnerabilities in xpdf/kpdf/gpdf
Links: KDE, CAN-2005-3191, CAN-2005-3192, CAN-2005-3193, ESB-2005.0970, RHSA-2005-840, RHSA-2005-867, RHSA-2005-868, ESB-2005.1003, ESB-2005.1000, ESB-2005.1001
ID: ae-200512-012

Kpdf and gpdf, the pdf viewers for KDE and Gnome, shares code with xpdf. Xpdf contains multiple integer overflow vulnerabilities that allow specially crafted pdf files, when opened, to overflow a heap allocated buffer and execute arbitrary code. Source code patches have been made available which fix these vulnerabilities.

System: HP-UX
Topic: Vulnerability in IPSec
Links: HPSBUX02082, SSRT051037, Q-071, ESB-2005.0968
ID: ae-200512-011

A potential security vulnerability has been discovered with HP-UX running IPSec. The vulnerability could be exploited to allow remote unauthorized access. HP has made software updates available to resolve the issue.

System: Debian GNU/Linux
Topic: Vulnerabilities in inkscape
Links: DSA-916, CVE-2005-3737, CVE-2005-3885, ESB-2005.0969
ID: ae-200512-010

Inkscape is a vector-based drawing program. A buffer overflow in the SVG parsing routines might lead to the execution of arbitrary code. Additionally, the ps2epsi extension shell script uses a hardcoded temporary file making it vulnerable to symlink attacks. An updated package remedies these problems.

System: Various
Topic: Vulnerabilities in Sun Java Runtime Environment
Links: Sun Alert 102068, Q-069, ESB-2005.0966,
Sun Alert 102012, Q-070, ESB-2005.0967
ID: ae-200512-009

A Security Vulnerability in Communications Services Delegated Administrator 2005Q1 may allow a remote unauthorized user the ability to gain access to the Top-Level Administrator (TLA) default password.
A security vulnerability exists in the Proxy Plug-in for certain Sun ONE and Java System Application Server products when the plug-in is used with a supported web server, such as Sun Java System Web Server, Apache Web Server or Microsoft Internet Information Server (IIS). This vulnerability may allow a "Man-in-the-Middle" condition to be exploited and possibly compromise data privacy between the client and the server.
Patches solve these problems.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in xpdf, imap, and libc-client
Links: RHSA-2005-840, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193, Q-068, ESB-2005.0963,
RHSA-2005-848, RHSA-2005-850, CVE-2005-2933, ESB-2005.0964, ESB-2005.0965
ID: ae-200512-008

The xpdf package is an X Window System-based viewer for Portable Document Format (PDF) files. Several flaws were discovered in Xpdf. An attacker could construct a carefully crafted PDF file that could cause Xpdf to crash or possibly execute arbitrary code when opened.
A buffer overflow flaw was discovered in the way the c-client library parses user supplied mailboxes. If an authenticated user requests a specially crafted mailbox name, it may be possible to execute arbitrary code on a server that uses the library.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Sun Java Runtime Environment
Links: Sun Alert 102003, ESB-2005.0962
ID: ae-200512-007

Three security vulnerabilities with the use of "reflection" APIs in the Java Runtime Environment (JRE) may (independently) allow an untrusted applet to elevate its privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. Patches are available now.

System: Mandriva Linux
Topic: Vulnerabilities in spamassassin, mailman, and webmin
Links: MDKSA-2005:221, CVE-2005-3351,
MDKSA-2005:222, CVE-2005-3573,
MDKSA-2005:223, CAN-2005-3912
ID: ae-200512-006

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an E-Mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
Scrubber.py in Mailman 2.1.4 - 2.1.6 doesn't properly handle UTF8 character encodings in filenames of E-Mail attachments, which allows remote attackers to cause a Denial-of-Service. In addition, these versions of mailman have an issue where the server will fail with an Overflow on bad date data in a processed message. The version of mailman in Corporate Server 2.1 doesn't contain the above vulnerable code.
A format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180 has been discovered. If syslog logging is enabled, remote attackers might to cause a Denial-of-Service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call.
Updated packages have been patched to address these issues.

System: Various
Topic: Vulnerability in Sun Java Runtime Environment
Links: Sun Alert 102050, VU#355284, Secunia #17748
ID: ae-200512-005

The Sun Java Runtime Environment provides the libraries and components necessary to run Java-based applications. There is an unspecified vulnerability in the Java Runtime Environment that may allow an untrusted Java applet to bypass the Java security settings. Once the security restrictions are bypassed, the applet may be able to access and manipulate system resources. Sun has addressed this issue in the Java Development Kit and Java Runtime Environment 5.0 Update 4 and later.

System: Many
Topic: Vulnerability in Real Player
Links: CAN-2005-2629, ESB-2005.0959, Q-067
ID: ae-200512-004

eEye Digital Security has discovered a critical vulnerability in RealPlayer. The vulnerability allows a remote attacker to reliably overwrite stack memory with arbitrary data and execute arbitrary code in the context of the user who executed the player. RealNetworks has released a patch for this vulnerability.

System: Cisco IOS
Topic: Vulnerability in Cisco IOS HTTP Server
Links: Cisco, ESB-2005.0958, Q-066
ID: ae-200512-003

A vulnerability exists in the IOS HTTP server. Exploiting this vulnerability may result in an attacker executing commands on the device, including the possibility of gaining full administrative privileges on the device which is dependent on the privilege level of the authenticated user. A proof of concept exploit exists for this vulnerability. Cisco has made free software available to address this vulnerability.

System: Microsoft Windows
Topic: Vulnerability in Cisco Security Agent
Links: Cisco, ESB-2005.0947, Q-063
ID: ae-200512-002

A vulnerability was discovered in Cisco Security Agent (CSA). CSA is a security software agent that provides threat protection for server and desktop computing systems. Exploiting this vulnerability may allow privilege escalation and allow an attacker with local system level privileges on a Windows workstation or server running managed or standalone CSA 4.5.0 or 4.5.1 agents. Cisco has made free software available to address this vulnerability.

System: Debian GNU/Linux
Topic: Vulnerabilities in horde2 and helix-player
Links: DSA-914, CVE-2005-3570, ESB-2005.0956,
DSA-915, CVE-2005-2629, ESB-2005.0960
ID: ae-200512-001

A vulnerability has been discovered in horde2, a web application suite, that allows attackers to insert arbitary script code into the error web page.
An integer overflow has been discovered in helix-player, the helix audio and video player. This flaw could allow a remote attacker to run arbitrary code on a victims computer by supplying a specially crafted network resource.
Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH