|
|
Subscribe / Log in / New account

Security

Brief items

Email Virus Scanning for Linux: A review of alternatives to RAV Antivirus

[This article was contributed by tummy.com]

With the purchase of RAV by Microsoft, many Linux email providers and ISPs, are looking for an affordable, reliable replacement for RAV Antivirus.

Kevin Fenzi, Senior Member Technical Staff of tummy.com, ltd. and the co-author of the Linux Security HOWTO, has reviewed some of the currently available alternatives.

Kevin evaluated the alternatives on several different criteria, including Pricing policy (unlimited use is better than a per-domain or per-user price), broad support for Mail Transport Agents, and ease of installation and configuration.

Criteria Used:

  • Pricing policy: Unlimited use got the highest score. Per-domain pricing was next best, and per-user pricing was last. Those products that did not have pricing information on their website received no score in this category.

  • Support for MTAs: A point was awarded for each of the popular Mail Transport Agents supported (Qmail, Postfix, Exim, SuSE, Sendmail+Milters, Sendmail, Dmail).

  • Ease of Installation: Is the product easy to download and install?

  • Ease of Configuration: Is the product easy to configure with your local MTA?

  • Scores are on a 'bad, fair, good, excellent' scale.

Read the full article here.

Comments (10 posted)

New vulnerabilities

gtksee: buffer overflow

Package(s):gtksee CVE #(s):CAN-2003-0444
Created:June 30, 2003 Updated:July 11, 2003
Description: Viliam Holub discovered a bug in gtksee whereby, when loading PNG images of certain color depths, gtksee would overflow a heap-allocated buffer. This vulnerability could be exploited by an attacker using a carefully constructed PNG image to execute arbitrary code when the victim loads the file in gtksee.
Alerts:
Gentoo 200307-05 gtksee 2003-07-11
Debian DSA-337-1 gtksee 2003-06-29

Comments (none posted)

imagemagick: insecure temporary file

Package(s):imagemagick CVE #(s):CAN-2003-0455
Created:June 30, 2003 Updated:July 10, 2003
Description: There are circumstances in which imagemagick's libmagick library creates temporary files without taking appropriate security precautions. This vulnerability could be exploited by a local user to create or overwrite files with the privileges of another user who is invoking a program using this library.
Alerts:
OpenPKG OpenPKG-SA-2003.034 imagemagick 2003-07-10
Debian DSA-331-1 imagemagick 2003-06-27

Comments (none posted)

PHP: Cross site scripting vulnerability

Package(s):PHP CVE #(s):CAN-2003-0442
Created:July 2, 2003 Updated:August 13, 2003
Description: In PHP version 4.3.1 and earlier, when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a Cross Site Scripting attack.
Alerts:
Mandrake MDKSA-2003:082-1 php 2003-08-12
Mandrake MDKSA-2003:082 php 2003-08-04
Yellow Dog YDU-20030710-2 php 2003-07-10
Debian DSA-351-1 php4 2003-07-16
Conectiva CLA-2003:691 php4 2003-07-08
OpenPKG OpenPKG-SA-2003.032 php, apache 2003-07-07
Red Hat RHSA-2003:204-01 PHP 2003-07-02

Comments (none posted)

phpbb: sql injection

Package(s):phpbb CVE #(s):CAN-2003-0486
Created:June 28, 2003 Updated:July 2, 2003
Description: An SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.
Alerts:
Gentoo 200306-15 phpbb 2003-06-28

Comments (none posted)

proftpd: SQL injection

Package(s):proftpd CVE #(s):
Created:June 30, 2003 Updated:June 30, 2003
Description: runlevel [runlevel@raregazz.org] reported that ProFTPD's PostgreSQL authentication module is vulnerable to a SQL injection attack. This vulnerability could be exploited by a remote, unauthenticated attacker to execute arbitrary SQL statements, potentially exposing the passwords of other users, or to connect to ProFTPD as an arbitrary user without supplying the correct password.
Alerts:
Debian DSA-338-1 proftpd 2003-06-29

Comments (none posted)

tcptraceroute: problems dropping root privileges

Package(s):tcptraceroute CVE #(s):CAN-2003-0489
Created:June 28, 2003 Updated:July 10, 2003
Description: tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets. This may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.
Alerts:
Gentoo 200306-14 tcptraceroute 2003-06-28
Debian DSA-330-1 tcptraceroute 2003-06-23

Comments (none posted)

unzip: directory traversal vulnerability

Package(s):unzip CVE #(s):CAN-2003-0282
Created:July 1, 2003 Updated:November 13, 2003
Description: A vulnerabilitiy in unzip version 5.50 and earlier allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two "." characters. These non-printable characters are filtered, resulting in a ".." sequence. See the full advisory for further information.
Alerts:
SCO Group CSSA-2003-031.0 unzip 2003-11-07
Debian DSA-344-2 unzip 2003-08-26
Slackware SSA:2003-237-01 infozip 2003-08-25
Mandrake MDKSA-2003:073-1 unzip 2003-08-19
Conectiva CLA-2003:724 unzip 2003-08-18
Red Hat RHSA-2003:199-02 unzip 2003-08-15
Yellow Dog YDU-20030710-1 unzip 2003-07-10
Gentoo 200307-02 unzip 2003-07-11
OpenPKG OpenPKG-SA-2003.033 infozip 2003-07-10
Debian DSA-344-1 unzip 2003-07-08
Mandrake MDKSA-2003:073 unzip 2003-07-07
Conectiva CLA-2003:672 unzip 2003-07-02
Immunix IMNX-2003-7+-017-01 unzip 2003-07-02
Red Hat RHSA-2003:199-01 unzip 2003-07-01

Comments (none posted)

xgalaga: buffer overflows

Package(s):xgalaga CVE #(s):CAN-2003-0454
Created:June 30, 2003 Updated:July 2, 2003
Description: Steve Kemp discovered several buffer overflows in the game xgalaga, which can be triggered by a long HOME environment variable. This vulnerability could be exploited by a local attacker to gain gid 'games'.
Alerts:
Debian DSA-334-1 xgalaga 2003-06-28

Comments (none posted)

Resources

Linux Advisory Watch

The June 27 issue of the Linux Advisory Watch newsletter from LinuxSecurity.com is available.

Full Story (comments: none)

Linux Security Week

The June 30 issue of the Linux Security Week newsletter from LinuxSecurity.com is available.

Full Story (comments: none)

Events

NEbraskaCERT Conference

NEbraskaCERT is holding the 5th annual NEbraskaCERT conference, the leading Security Conference in the midwest. The conference will be held August 5 - 7, 2003 at the Peter Kiewit Institute, Scott Conference Center, Omaha, NE USA.

Comments (none posted)

Page editor: Rebecca Sobol
Next page: Kernel development>>


Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds