Security
Brief items
Debconf5: Securing the Testing Distribution
This part of our Debconf5 coverage was inspired by a talk titled Securing the Testing Distribution given by Joey Hess.
Debian has several branches, including two currently supported stable branches, Woody and Sarge and the unstable branch, also known as sid. Though usually fairly stable, sid is in constant flux and provides a faster paced target for those who like run the latest and greatest software. The testing branch, on the other hand, provides a look at the next stable version still in development, in this case etch. Testing was first used when woody was in development. Once Woody was released as Debian 3.0 testing became synonymous with sarge. So now that Sarge has been released as Debian 3.1, testing has become etch which will someday to be the next stable version.
The supported stable version(s) (support for Woody will end before we will see an etch release) have a security team providing security updates. Often security fixes are backported to the stable packages. Packages in sid are usually upgraded to a new version of the package in which the problem has been fixed. Up to now there has been no mechanism to provide security updates for testing.
Some of the security issues in stable will have already been fixed in testing's newer packages, but for the most part security fixes have lagged behind stable and unstable. Packages fixed in unstable can automatically migrate to testing, if certain criteria are met, but that comes with a built-in delay. Unrelated release critical bugs in unstable packages could block the security updates from reaching testing. Ironically, those very users most interested in the shape of the next stable version are also those likely to be put off by the lack of security updates.
Those days have come to end. Now there is a security team for testing, with five to six team members and twice that on the mailing list. Some team members are Debian Developers (DDs), but that's not required. The team now proactively looks for holes, checking Debian testing packages against CVE entrys, bugs in the Bug Tracking System (BTS), and watching other security lists.
DDs and package maintainers were asked to document all security issues, including the CVE number in open bug reports. Change log entries and closed bugs should include a CVE number and indicate when security issues are fixed. Tracking and fixing security bugs in etch will make it far more appealing to potential testers, and may even help Debian achieve a more predictable release cycle.
New vulnerabilities
affix: two remote vulnerabilities
| Package(s): | affix | CVE #(s): | CAN-2005-2250 CAN-2005-2277 | ||||
| Created: | July 19, 2005 | Updated: | September 2, 2005 | ||||
| Description: | A buffer overflow in the Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share. Also remote attackers may execute arbitrary commands via shell metacharacters in the filename argument of a PUT command. | ||||||
| Alerts: |
| ||||||
bugzilla: information disclosure
| Package(s): | bugzilla | CVE #(s): | CAN-2005-2173 CAN-2005-2174 | ||||
| Created: | July 14, 2005 | Updated: | July 19, 2005 | ||||
| Description: | Bugzilla has a vulnerability that may allow a remote attacker to modify flags of arbitrary bugs, triggering a return email to the attacker as well as a race condition. | ||||||
| Alerts: |
| ||||||
ekg: multiple vulnerabilities
| Package(s): | ekg | CVE #(s): | CAN-2005-1850 CAN-2005-1851 CAN-2005-1916 | ||||||||
| Created: | July 18, 2005 | Updated: | August 8, 2005 | ||||||||
| Description: | Several vulnerabilities have been discovered in the ekg contributed scripts. These include an insecure temporary file creation problem, a potential shell command injection problem, and an arbitrary command execution problem. | ||||||||||
| Alerts: |
| ||||||||||
heartbeat: insecure temporary files
| Package(s): | heartbeat | CVE #(s): | CAN-2005-2231 | ||||||||||||||||||||
| Created: | July 19, 2005 | Updated: | August 15, 2005 | ||||||||||||||||||||
| Description: | Eric Romang discovered several insecure temporary file creations in the High Availability Linux Project Heartbeat 1.2.3. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
kdelibs: kate backup file permission leak
| Package(s): | kdelibs kate kwrite | CVE #(s): | CAN-2005-1920 | ||||||||||||||||||||||||||||
| Created: | July 19, 2005 | Updated: | September 21, 2010 | ||||||||||||||||||||||||||||
| Description: | Kate / Kwrite, as shipped with KDE 3.2.x up to including 3.4.0, creates a file backup before saving a modified file. These backup files are created with default permissions, even if the original file had more strict permissions set. See this advisory for more information. | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
mediawiki: JavaScript code injection
| Package(s): | mediawiki | CVE #(s): | |||||
| Created: | July 20, 2005 | Updated: | July 20, 2005 | ||||
| Description: | MediaWiki has a vulnerability caused by failing to correctly escape a parameter in the page move template. Remote attackers can use this to inject and execute JavaScript code with the permission of the user's browser session. | ||||||
| Alerts: |
| ||||||
mozilla-firefox: multiple vulnerabilities
| Package(s): | mozilla-firefox | CVE #(s): | |||||||||
| Created: | July 14, 2005 | Updated: | July 22, 2005 | ||||||||
| Description: | A dozen security vulnerabilities that have been fixed in Firefox 1.0.5 and Mozilla 1.7.9 have been back-ported to older versions. | ||||||||||
| Alerts: |
| ||||||||||
mysql: low-impact security fix
| Package(s): | mysql | CVE #(s): | CAN-2005-1636 | ||||||||||||||||
| Created: | July 20, 2005 | Updated: | February 22, 2006 | ||||||||||||||||
| Description: | An update to MySQL version 4.1.12 fixes a low-impact security problem (bz#158689). | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
pam_ldap: plain text authentication leak
| Package(s): | pam_ldap | CVE #(s): | CAN-2005-2069 | ||||||||||||||||||||||||
| Created: | July 14, 2005 | Updated: | October 17, 2005 | ||||||||||||||||||||||||
| Description: | pam_ldap and nss_ldap ignore the "ssl start_tls" ldap.conf setting, allowing an attacker to sniff unencrypted passwords and other information. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
phppgadmin: directory traversal vulnerability
| Package(s): | phppgadmin | CVE #(s): | CAN-2005-2256 | ||||
| Created: | July 18, 2005 | Updated: | July 19, 2005 | ||||
| Description: | A missing input sanitization vulnerability has been discovered in the phppgadmin PHP scripts, sensitive information may be disclosed. | ||||||
| Alerts: |
| ||||||
thunderbird mozilla firefox: multiple vulnerabilities
| Package(s): | thunderbird firefox mozilla | CVE #(s): | CAN-2005-0989 CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | July 20, 2005 | Updated: | September 1, 2005 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | Multiple vulnerabilities have been found in the Mozilla Thunderbird email client, as well as the Mozilla Suite and Firefox and Mozilla based other browsers. Bugs include an anonymous function handling bug, a JavaScript validation problem, privileged UI code handling DOM nodes, a JavaScript privilege escalation, a problem with Javascript in XBL controls, improper handling of child frames, a DOM name code execution vulnerability, and a base object clone problem. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated vulnerabilities
CUPS: multiple vulnerabilities
| Package(s): | CUPS | CVE #(s): | CAN-2004-2154 | ||||||||||||||||
| Created: | July 14, 2005 | Updated: | September 20, 2005 | ||||||||||||||||
| Description: | The CUPS printing system has a problem with queue name case-sensitivity matching that can cause a security policy override. An unauthorized user can use this to gain print to a protected queue. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
cvs: multiple vulnerabilities
| Package(s): | cvs | CVE #(s): | CAN-2004-1342 CAN-2004-1343 | ||||
| Created: | July 19, 2005 | Updated: | July 19, 2005 | ||||
| Description: | The cvs pserver access method in connection with the Debian repouid can allow an attacker to bypass the password authentication and gain unauthorized access to the repository. Also, a problem with the cvs-repouids file can allow a remote user to crash the cvs server and cause a denial of service. | ||||||
| Alerts: |
| ||||||
Page editor: Rebecca Sobol
Next page:
Kernel development>>
