|
|
Log in / Subscribe / Register

Security

Brief items

Debconf5: Securing the Testing Distribution

This part of our Debconf5 coverage was inspired by a talk titled Securing the Testing Distribution given by Joey Hess. Debconf5 sign

Debian has several branches, including two currently supported stable branches, Woody and Sarge and the unstable branch, also known as sid. Though usually fairly stable, sid is in constant flux and provides a faster paced target for those who like run the latest and greatest software. The testing branch, on the other hand, provides a look at the next stable version still in development, in this case etch. Testing was first used when woody was in development. Once Woody was released as Debian 3.0 testing became synonymous with sarge. So now that Sarge has been released as Debian 3.1, testing has become etch which will someday to be the next stable version.

The supported stable version(s) (support for Woody will end before we will see an etch release) have a security team providing security updates. Often security fixes are backported to the stable packages. Packages in sid are usually upgraded to a new version of the package in which the problem has been fixed. Up to now there has been no mechanism to provide security updates for testing.

Some of the security issues in stable will have already been fixed in testing's newer packages, but for the most part security fixes have lagged behind stable and unstable. Packages fixed in unstable can automatically migrate to testing, if certain criteria are met, but that comes with a built-in delay. Unrelated release critical bugs in unstable packages could block the security updates from reaching testing. Ironically, those very users most interested in the shape of the next stable version are also those likely to be put off by the lack of security updates.

Those days have come to end. Now there is a security team for testing, with five to six team members and twice that on the mailing list. Some team members are Debian Developers (DDs), but that's not required. The team now proactively looks for holes, checking Debian testing packages against CVE entrys, bugs in the Bug Tracking System (BTS), and watching other security lists.

DDs and package maintainers were asked to document all security issues, including the CVE number in open bug reports. Change log entries and closed bugs should include a CVE number and indicate when security issues are fixed. Tracking and fixing security bugs in etch will make it far more appealing to potential testers, and may even help Debian achieve a more predictable release cycle.

Comments (2 posted)

New vulnerabilities

affix: two remote vulnerabilities

Package(s):affix CVE #(s):CAN-2005-2250 CAN-2005-2277
Created:July 19, 2005 Updated:September 2, 2005
Description: A buffer overflow in the Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share. Also remote attackers may execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
Alerts:
Debian DSA-762-1 affix 2005-07-19

Comments (none posted)

bugzilla: information disclosure

Package(s):bugzilla CVE #(s):CAN-2005-2173 CAN-2005-2174
Created:July 14, 2005 Updated:July 19, 2005
Description: Bugzilla has a vulnerability that may allow a remote attacker to modify flags of arbitrary bugs, triggering a return email to the attacker as well as a race condition.
Alerts:
Gentoo 200507-12 bugzilla 2005-07-13

Comments (none posted)

ekg: multiple vulnerabilities

Package(s):ekg CVE #(s):CAN-2005-1850 CAN-2005-1851 CAN-2005-1916
Created:July 18, 2005 Updated:August 8, 2005
Description: Several vulnerabilities have been discovered in the ekg contributed scripts. These include an insecure temporary file creation problem, a potential shell command injection problem, and an arbitrary command execution problem.
Alerts:
Ubuntu USN-162-1 ekg 2005-08-08
Debian DSA-760-1 ekg 2005-07-18

Comments (none posted)

heartbeat: insecure temporary files

Package(s):heartbeat CVE #(s):CAN-2005-2231
Created:July 19, 2005 Updated:August 15, 2005
Description: Eric Romang discovered several insecure temporary file creations in the High Availability Linux Project Heartbeat 1.2.3.
Alerts:
Debian DSA-761-2 heartbeat 2005-08-15
Ubuntu USN-165-1 heartbeat 2005-08-11
Mandriva MDKSA-2005:132 heartbeat 2005-08-09
Gentoo 200508-05 heartbeat 2005-08-07
Debian DSA-761-1 heartbeat 2005-07-19

Comments (none posted)

kdelibs: kate backup file permission leak

Package(s):kdelibs kate kwrite CVE #(s):CAN-2005-1920
Created:July 19, 2005 Updated:September 21, 2010
Description: Kate / Kwrite, as shipped with KDE 3.2.x up to including 3.4.0, creates a file backup before saving a modified file. These backup files are created with default permissions, even if the original file had more strict permissions set. See this advisory for more information.
Alerts:
Gentoo 200611-21 kile 2006-11-27
Debian DSA-804-2 kdelibs 2005-11-10
Debian DSA-804-1 kdelibs 2005-09-08
Red Hat RHSA-2005:612-01 kdelibs 2005-07-27
Ubuntu USN-150-1 kdelibs 2005-07-21
Mandriva MDKSA-2005:122 kdelibs 2005-07-20
Fedora FEDORA-2005-594 kdelibs 2005-07-19

Comments (1 posted)

mediawiki: JavaScript code injection

Package(s):mediawiki CVE #(s):
Created:July 20, 2005 Updated:July 20, 2005
Description: MediaWiki has a vulnerability caused by failing to correctly escape a parameter in the page move template. Remote attackers can use this to inject and execute JavaScript code with the permission of the user's browser session.
Alerts:
Gentoo 200507-18 mediawiki 2005-07-20

Comments (none posted)

mozilla-firefox: multiple vulnerabilities

Package(s):mozilla-firefox CVE #(s):
Created:July 14, 2005 Updated:July 22, 2005
Description: A dozen security vulnerabilities that have been fixed in Firefox 1.0.5 and Mozilla 1.7.9 have been back-ported to older versions.
Alerts:
Gentoo 200507-14 mozilla-firefox 2005-07-15
Mandriva MDKSA-2005:120 mozilla-firefox 2005-07-13

Comments (none posted)

mysql: low-impact security fix

Package(s):mysql CVE #(s):CAN-2005-1636
Created:July 20, 2005 Updated:February 22, 2006
Description: An update to MySQL version 4.1.12 fixes a low-impact security problem (bz#158689).
Alerts:
Mandriva MDKSA-2006:045 MySQL 2006-02-21
Red Hat RHSA-2005:685-01 mysql 2005-10-05
Debian DSA-783-1 mysql-dfsg-4.1 2005-08-24
Fedora FEDORA-2005-557 mysql 2005-07-20

Comments (1 posted)

pam_ldap: plain text authentication leak

Package(s):pam_ldap CVE #(s):CAN-2005-2069
Created:July 14, 2005 Updated:October 17, 2005
Description: pam_ldap and nss_ldap ignore the "ssl start_tls" ldap.conf setting, allowing an attacker to sniff unencrypted passwords and other information.
Alerts:
Red Hat RHSA-2005:767-01 openldap 2005-10-17
Red Hat RHSA-2005:751-01 openldap 2005-10-17
SuSE SUSE-SR:2005:020 multiple 2005-09-12
Ubuntu USN-152-1 openldap2, libpam-ldap, libnss-ldap 2005-07-21
Mandriva MDKSA-2005:121 nss_ldap 2005-07-18
Gentoo 200507-13 pam_ldap 2005-07-14

Comments (none posted)

phppgadmin: directory traversal vulnerability

Package(s):phppgadmin CVE #(s):CAN-2005-2256
Created:July 18, 2005 Updated:July 19, 2005
Description: A missing input sanitization vulnerability has been discovered in the phppgadmin PHP scripts, sensitive information may be disclosed.
Alerts:
Debian DSA-759-1 phppgadmin 2005-07-18

Comments (none posted)

thunderbird mozilla firefox: multiple vulnerabilities

Package(s):thunderbird firefox mozilla CVE #(s):CAN-2005-0989 CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270
Created:July 20, 2005 Updated:September 1, 2005
Description: Multiple vulnerabilities have been found in the Mozilla Thunderbird email client, as well as the Mozilla Suite and Firefox and Mozilla based other browsers. Bugs include an anonymous function handling bug, a JavaScript validation problem, privileged UI code handling DOM nodes, a JavaScript privilege escalation, a problem with Javascript in XBL controls, improper handling of child frames, a DOM name code execution vulnerability, and a base object clone problem.
Alerts:
Debian DSA-779-2 mozilla-firefox 2005-09-01
Mandriva MDKSA-2005:127-1 mozilla-thunderbird 2005-08-26
Debian DSA-781-1 mozilla-thunderbird 2005-08-23
Debian DSA-779-1 mozilla-firefox 2005-08-20
SuSE SUSE-SA:2005:045 mozilla,MozillaFirefox,epiphany,galeon 2005-08-11
Ubuntu USN-157-2 enigmail 2005-08-02
Ubuntu USN-157-1 mozilla-thunderbird 2005-08-01
Mandriva MDKSA-2005:127 mozilla-thunderbird 2005-07-28
Ubuntu USN-149-3 mozilla-firefox 2005-07-28
Ubuntu USN-155-1 mozilla 2005-07-26
Gentoo 200507-24 mozilla 2005-07-26
Ubuntu USN-149-2 mozilla-firefox 2005-07-25
Mandriva MDKSA-2005:120-1 mozilla-firefox 2005-07-22
Slackware SSA:2005-203-01 mozilla 2005-07-22
Red Hat RHSA-2005:587-01 mozilla 2005-07-22
Fedora FEDORA-2005-622 yelp 2005-07-22
Fedora FEDORA-2005-621 devhelp 2005-07-22
Fedora FEDORA-2005-618 devhelp 2005-07-22
Fedora FEDORA-2005-620 epiphany 2005-07-22
Fedora FEDORA-2005-617 epiphany 2005-07-22
Fedora FEDORA-2005-619 mozilla 2005-07-22
Fedora FEDORA-2005-616 mozilla 2005-07-22
Red Hat RHSA-2005:601-01 thunderbird 2005-07-21
Red Hat RHSA-2005:586-01 firefox 2005-07-21
Ubuntu USN-149-1 mozilla-firefox 2005-07-21
Fedora FEDORA-2005-606 thunderbird 2005-07-20
Fedora FEDORA-2005-604 thunderbird 2005-07-20
Fedora FEDORA-2005-605 firefox 2005-07-20
Fedora FEDORA-2005-603 firefox 2005-07-20

Comments (none posted)

Updated vulnerabilities

CUPS: multiple vulnerabilities

Package(s):CUPS CVE #(s):CAN-2004-2154
Created:July 14, 2005 Updated:September 20, 2005
Description: The CUPS printing system has a problem with queue name case-sensitivity matching that can cause a security policy override. An unauthorized user can use this to gain print to a protected queue.
Alerts:
Mandriva MDKSA-2005:165 cups 2005-09-15
Ubuntu USN-185-1 cupsys 2005-09-20
Fedora-Legacy FLSA:163274 CUPS 2005-09-14
Red Hat RHSA-2005:571-01 CUPS 2005-07-14

Comments (none posted)

cvs: multiple vulnerabilities

Package(s):cvs CVE #(s):CAN-2004-1342 CAN-2004-1343
Created:July 19, 2005 Updated:July 19, 2005
Description: The cvs pserver access method in connection with the Debian repouid can allow an attacker to bypass the password authentication and gain unauthorized access to the repository. Also, a problem with the cvs-repouids file can allow a remote user to crash the cvs server and cause a denial of service.
Alerts:
Debian DSA-715-1 cvs 2005-04-27

Comments (none posted)

Page editor: Rebecca Sobol
Next page: Kernel development>>


Copyright © 2005, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds