LWN.net Logo

Trustix alert TSLSA-2005-0064 (kernel spamassassin)

From:  Trustix Security Advisor <tsl@trustix.org>
To:  tsl-announce@lists.trustix.org
Subject:  TSLSA-2005-0064 - multi
Date:  Tue, 22 Nov 2005 11:52:56 +0100

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Trustix Secure Linux Security Advisory #2005-0064 Package names: kernel, spamassassin Summary: Multiple vulnerabilities Date: 2005-11-11 Affected versions: Trustix Secure Linux 2.2 Trustix Secure Linux 3.0 - -------------------------------------------------------------------------- Package description: kernel The kernel package contains the Linux kernel (vmlinuz), the core of your Trustix Secure Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. spamassassin SpamAssassin provides you with a way to reduce, if not completely eliminate, Unsolicited Bulk Email (or "spam") from your incoming email. It can be invoked by a MDA such as sendmail or postfix, or can be called from a procmail script, .forward file, etc. It uses a genetic-algorithm-evolved scoring system to identify messages which look spammy, then adds headers to the message so they can be filtered by the user's mail reading software. This distribution includes the spamd/spamc components which considerably speeds processing of mail. Problem description: kernel < TSL 3.0 > - SECURITY Fix: sysctl unregistration oops. You could open the /proc/sys/net/ipv4/conf/<if>/<whatever> file, then wait for interface to go away, try to grab as much memory as possible in hope to hit the (kfreed) ctl_table. Then fill it with pointers to your function.Then do read from file you've opened and if you are lucky, you'll get it called as ->proc_handler() in kernel mode. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2005-2709 spamassassin < TSL 3.0 > < TSL 2.2 > - SECURITY Fix: Fix DOS. This flaw is due to an input validation error in "Message.pm" when processing an email containing multiple recipients in the "To:" header field, which could be exploited by remote attackers to bypass the spam detection procedure by crashing a child process via a specially crafted email. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2005-3351 Action: We recommend that all systems with this package installed be upgraded. Please note that if you do not need the functionality provided by this package, you may want to remove it from your system. Location: All Trustix Secure Linux updates are available from <URI:http://http.trustix.org/pub/trustix/updates/>> <URI:ftp://ftp.trustix.org/pub/trustix/updates/>> About Trustix Secure Linux: Trustix Secure Linux is a small Linux distribution for servers. With focus on security and stability, the system is painlessly kept safe and up to date from day one using swup, the automated software updater. Automatic updates: Users of the SWUP tool can enjoy having updates automatically installed using 'swup --upgrade'. Questions? Check out our mailing lists: <URI:http://www.trustix.org/support/>> Verification: This advisory along with all Trustix packages are signed with the TSL sign key. This key is available from: <URI:http://www.trustix.org/TSL-SIGN-KEY>> The advisory itself is available from the errata pages at <URI:http://www.trustix.org/errata/trustix-2.2/>> and <URI:http://www.trustix.org/errata/trustix-3.0/>> or directly at <URI:http://www.trustix.org/errata/2005/0064/>> MD5sums of the packages: - -------------------------------------------------------------------------- a3977966035a3d8284b8a9f4055aeb82 2.2/rpms/perl-mail-spamassassin-3.0.4-3tr.i586.rpm 1ce0012f486b059a25dfafc2cfe0089a 2.2/rpms/spamassassin-3.0.4-3tr.i586.rpm 11d515339e779c991421dddb80d9efab 2.2/rpms/spamassassin-tools-3.0.4-3tr.i586.rpm e54469bcd2e9deaaaa0a1d9849715df5 3.0/rpms/kernel-2.6.14.2-2tr.i586.rpm 442ac995c5f47775e66c8357ebe18723 3.0/rpms/kernel-doc-2.6.14.2-2tr.i586.rpm b0e69677d239520d627d6bf5ad2e1ff0 3.0/rpms/kernel-headers-2.6.14.2-2tr.i586.rpm 1dd9e93670efeef9ed4051279fe6c700 3.0/rpms/kernel-smp-2.6.14.2-2tr.i586.rpm 71104e3dd274f4b4e9e192e92002dba6 3.0/rpms/kernel-smp-headers-2.6.14.2-2tr.i586.rpm f6184160a2a29eda3cf9e2e75ff85921 3.0/rpms/kernel-source-2.6.14.2-2tr.i586.rpm 0d8b55b3009b464f10f480ba4fd0875e 3.0/rpms/kernel-utils-2.6.14.2-2tr.i586.rpm 8e7e057b1f6b0e443b5b52174030cdd4 3.0/rpms/perl-mail-spamassassin-3.0.4-2tr.i586.rpm b76637383e79e9ac9ac5efbd6763f391 3.0/rpms/spamassassin-3.0.4-2tr.i586.rpm 7ac349ff344df75b913476a8a38d2e1c 3.0/rpms/spamassassin-tools-3.0.4-2tr.i586.rpm - -------------------------------------------------------------------------- Trustix Security Team -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQFDfcuwi8CEzsK9IksRArf9AJsHEdzSsb085Jeaow0EFlIUVRliSQCbB0h0 Iuc4KLsu9jcmZVIbJfojXE8= =PKIQ -----END PGP SIGNATURE----- _______________________________________________ tsl-announce mailing list tsl-announce@lists.trustix.org http://lists.trustix.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds