Security
Brief items
IBM Debuts First Self-Diagnostic Wireless Security Tool on Linux
A press release from IBM announces its "The Distributed Wireless Security Auditor" (DWSA) system. "The DWSA system, which runs on Linux on desktops and laptops, can accurately pinpoint the location of any rogue access points, enabling network personnel to quickly find and then fix or remove them, unlike other wireless auditors that require personnel to perform time consuming physical searches by walking around the site."
IBM shoots at 'drive-by hackers' (ZDNet)
Here's an article about IBM's recent press release, outlining their self-diagnostic wireless tool. "The IBM software sits on laptops and PCs, analyzing traffic on an internal 802.11 wireless network and sending data to a centralized server, said Dave Safford, manager of the global security analysis lab at IBM Research in Hawthorne, N.Y."
NSA pushes secure Linux (vnunet)
vnunet has posted an article about SELinux. "It may seem odd that the NSA has developed a security module. In the X-Files world of government agencies, the NSA is often associated with code breaking, but the other aspect of its role is code making, hence the interest in a secure Linux."
CRYPTO-GRAM, June 15, 2002
Bruce Schneier's CRYPTO-GRAM newsletter for June is out; the main topic this time around is making intelligence organizations work better to prevent attacks in the future. "My opinion has been that it is largely unnecessary to trade civil liberties for security, and that the best security measures -- reinforcing the airplane cockpit door, putting barricades and guards around important buildings, improving authentication for telephone and Internet banking -- have no effect on civil liberties. Broad surveillance is a mark of bad security."
Security reports
Remote denial of service vulnerability in Mozilla 1.0
A bug triggered by a huge font setting, from a CSS, results in a X windows crash or an unusable system. The problem is in Mozilla 1.0 and earlier. Also see the bugzilla entry.The problem is fixed in the Mozilla 1.0.1 branch.
IGMP local denial of service vulnerability in the 2.4.18 kernel
IGMPv2 is a protocol used by IP hosts to report their multicast group memberships to routers.Krishna N. Ramachandran has reported a IGMP related local denial of service vulnerability in the 2.4.18 kernel. It could be a problem for people using Linux as a high-end router. It won't affect most users, The full description is available here. The solution is to "drop All IGMP packets that are not multicast ethernet addresses."
Mandrake 8.2 security issue
It has been reported that the Mandrake Linux 8.2 "default security settings leave users' home directories world readable." The suggested solution is to "use the Mandrake Control Center, security settings section, and make sure the level is set to at least "High", or manually enter 'msec 3' via CLI"BasiliX multiple vulnerabilities
Ulf Harnhammar reports multiple vulnerabilities in the BasiliX webmail application based on PHP, IMAP and MySQL. The four vulnerabilities are: potential access to any file on the web server cross-site scripting issues, insecure storage of attachments and SQL Injection holes. Versions 1.1.0 and all previous versions are vulnerable.
ZenTrack System Information Disclosure Vulnerability
Ahmet Sabri Alper reported an information disclosure vulnerabilty in ZenTrack v2.0.3, v2.0.2beta and older. A maliciously crafted HTTP request may be used to reveal the path to the web root and "maybe some more sensitive information."PHP source injection vulnerability in PHPAddress 2.0e
Tim Vandermeersch reports that PHP Address 0.2e has a vulnerability which allows a crafted URL to include any php file on the server. The problem is fixed in PHP Address 0.2f (17.07.2002). PHP Address is a collection of PHP scripts for maintaing a small web-based address-database.(Proprietary product) Information disclosure vulnerability in webMathematica
A vulnerabilty was reported in "the webMathematica software which allows remote clients (web surfers) to read an arbitrary file on the server (assuming the httpd-user has permission)." A version of webMathematica which fixes the problem is available from the vendor, Wolfram Research.
New vulnerabilities
Apache 'chunk handling' vulnerability
| Package(s): | apache | CVE #(s): | CAN-2002-0392 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | June 19, 2002 | Updated: | July 3, 2002 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | It is past time to upgrade your Apache servers. A worm which takes advantage of the this vulnerability has been sighted, and its source has been publicly posted.
An apache httpd bug related to chunked encoding presents a denial of service vulnerability. For some platforms, including both 32-bit and 64-bit Linux, it is also a potential remote exploit vulnerability. A "carefully crafted invalid request" may be used to trigger the bug. The problem is fixed in Apache 2.0.39 and 1.3.26, which may be downloaded from here. For more information, see the advisories from CERT and the Apache Group. This vulnerability has been widely publicized. Applying a patch from your vendor or upgrading to the latest version from the Apache Software Foundation is strongly encouraged. Avoid patches from other sources; at least one patch that does not address the full scope of the problem has been circulated. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Cross-site scripting vulnerability in Horde/IMP 2.2.7 and 3.0
| Package(s): | imp horde/imp | CVE #(s): | |||||||||
| Created: | May 21, 2002 | Updated: | June 19, 2002 | ||||||||
| Description: | Version 2.2.8 of IMP has been released, it
fixes some vulnerabilities. "The Horde team announces the
availability of IMP 2.2.8, which prevents some potential cross-site
scripting (CSS) attacks." Upgrading
to IMP 3.1 or, at least, 2.2.8 is recommended
(First LWN
report: April 11, 2002).
Update: IMP 3.0, which was initially believed to be immune, is also vulnerable. The problem is fixed in IMP 3.1. | ||||||||||
| Alerts: |
| ||||||||||
Resources
VPN Implementation in Cluster Computing (Linux Journal)
This tutorial by Linux Journal offers ideas to negotiate security and scalability issues with clusters. "After we connected the two clusters through the the VPN, users were able to log in to the master machine on the first cluster and submit jobs on both of the clusters through the queue system."
Systrace - Interactive Policy Generation for System Calls
Niels Provos has released systrace for OpenBSD and NetBSD. "Some work has started on a GNU/Linux port.". Also see, this post regarding systrace and the recent apache vulnerabilities.
- confinement of complex or untrusted binary applications.
- interactive policy generation with graphical user interface.
- support for different emulations: GNU/Linux, BSDI, etc..
- non-interactive policy enforcement.
- remote monitoring and intrusion detection.
- automatic policy generation.
With a correctly configured policy the impact of programming errors in system daemons can be constrained significantly.
Linux Security Week and Advisory Watch
The June 17th Linux Security Week and June 14th Linux Advisory Watch newsletters from LinuxSecurity.com are available.
Events
ToorCon 2002 call for papers
ToorCon 2002, will be held the 27th-29th of September 2002 in San Diego, CA, USA. The call for papers closes the 16th of August, 2002.ICICS 2002 call for papers
The Fourth International Conference on Information and Communications Security (ICICS 2002) will be held in Singapore, December 9-12, 2002. The call for papers closes 1 July 2002.Upcoming Security Events
| Date | Event | Location |
|---|---|---|
| June 17 - 19, 2002 | NetSec 2002 | San Fransisco, California, USA |
| June 17 - 19, 2002 | 3rd Annual Information Assurance Workshop | (United States Military Academy)West Point, New York |
| June 24 - 28, 2002 | 14th Annual Computer Security Incident Handling Conference | (Hilton Waikoloa Village)Hawaii |
| June 24 - 26, 2002 | 15th IEEE Computer Security Foundations Workshop | (Keltic Lodge, Cape Breton)Nova Scotia, Canada |
| June 28 - 29, 2002 | Edinburgh Financial Cryptography Engineering 2002 | Edinburgh, Scotland |
| July 31 - August 1, 2002 | Black Hat Briefings 2002 | (Caesars Palace Hotel and Resort)Las Vegas, NV, USA |
| August 2 - 4, 2002 | Defcon | (Alexis Park Hotel and Resort)Las Vegas, Nevada |
| August 5 - 9, 2002 | 11th USENIX Security Symposium | San Francisco, CA, USA |
| August 6 - 9, 2002 | CERT Conference 2002 | Omaha, Nebraska, USA |
For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.
Page editor: Dennis Tenney
Next page:
Kernel development>>
