Security
Brief items
Fixing spam with the legal code
As the spam situation continues to worsen, more people are looking farther afield for potential solutions. Recently there has been a new surge in interest in legal solutions. When all else fails, pass a law.One of the current approaches is the Lofgren law (backed by Lawrence Lessig) which would require all spam to carry an "ADV:" tag in the subject line. Recipients of untagged spam could report it to the U.S. Federal Trade Commission, and, perhaps, receive a portion of any fines collected from the spammer. The bill has numerous problems, including an overbroad definition of "spam" and the fact that the FTC already is unable to do anything about the vast number of complaints it receives.
The state of Virginia has taken things further with a law that makes spamming with forged headers into a felony. Spammers could find themselves spending the next five years contemplating the benefits of anatomical enlargement in a prison cell. To qualify for this penalty, a spammer would have to send out at least 10,000 messages with forged headers in a single day.
Creating legal tools to shut down spammers may be helpful in a few cases, but it is hard to see much long-term benefit coming from the legislative approach. What reason is there to believe that the legal system will be any more effective at shutting down spam than it is, say, at stopping the distribution of DeCSS? Even after an international campaign making even linking to DeCSS a crime, the DVD decryption software remains readily accessible. When all a spammer needs is a dialup connection and an open relay anywhere in the world, the effectiveness of any country's laws will be limited.
New vulnerabilities
balsa: imap code buffer overflow
| Package(s): | balsa | CVE #(s): | CAN-2003-0140 CAN-2003-0167 | ||||||||||||
| Created: | April 30, 2003 | Updated: | May 7, 2003 | ||||||||||||
| Description: | Balsa, it turns out, suffers from the same buffer overflow found in mutt; see the mutt vulnerability information for details. | ||||||||||||||
| Alerts: |
| ||||||||||||||
Bugzilla: several vulnerabilities.
| Package(s): | bugzilla | CVE #(s): | |||||
| Created: | April 30, 2003 | Updated: | May 21, 2003 | ||||
| Description: | The Bugzilla bug tracking system has a new set of vulnerabilities which can lead to cross-site scripting and symlink attacks. Versions 2.16.3 and 2.17.4 contain the necessary fixes; see this advisory for the details. | ||||||
| Alerts: |
| ||||||
Monkey HTTPd Remote Buffer Overflow
| Package(s): | monkeyd | CVE #(s): | |||||
| Created: | April 28, 2003 | Updated: | April 30, 2003 | ||||
| Description: | A buffer overflow vulnerability exists in Monkey's handling of forms submitted with the POST request method. The unchecked buffer lies in the PostMethod() procedure. The advisory contains more information. | ||||||
| Alerts: |
| ||||||
PoPTop: remotely exploitable buffer overflow
| Package(s): | pptpd | CVE #(s): | CAN-2003-0213 | ||||||||||||
| Created: | April 28, 2003 | Updated: | June 6, 2003 | ||||||||||||
| Description: | The PoPToP PPTP server contains a remotely exploitable buffer overflow; read the full advisory for more information. | ||||||||||||||
| Alerts: |
| ||||||||||||||
squirrelmail: more cross-site scripting vulnerabilities
| Package(s): | squirrelmail | CVE #(s): | CAN-2003-0160 | ||||||||
| Created: | April 24, 2003 | Updated: | June 4, 2003 | ||||||||
| Description: | SquirrelMail is a webmail package written in PHP. Multiple vulnerabilities
have been found which affect versions of SquirrelMail shipped with Red Hat
Linux 8.0 and Red Hat Linux 9.
Cross-site scripting vulnerabilities in SquirrelMail version 1.2.10 and earlier allow remote attackers to execute script as other Web users via mailbox displays, message displays, or search results displays. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0160 to these issues. All users are advised to upgrade to these errata packages containing SquirrelMail version 1.2.11, which is not vulnerable to these issues. | ||||||||||
| Alerts: |
| ||||||||||
Events
Call for Papers: Chaos Communication Club Camp 2003
The Chaos Communication Club Camp is happening near Berlin on August 7 through 10. The call for papers has gone out, with papers due by July 1. "Lectures are expected to be highly relevant in practice or better be darn funny. Sales droids have been known to disappear without traces on past events."
Page editor: Jonathan Corbet
Next page:
Kernel development>>
