|
|
Log in / Subscribe / Register

Security

Brief items

On the value of virus notifications

Many readers will, by now, be familiar with the results of "SoBig," this week's worm afflicting Microsoft systems. This worm, by some estimates, is accounting for some 70% of all email traffic on the net as this article is being written. Even those of us smugly running Linux, and who are thus not directly susceptible to this worm, have been affected by the flood of incoming email.

Interestingly, here at LWN we might have remained almost unaware of this worm. SpamAssassin does a perfectly fine job of filtering out SoBig mail; it never made it to our mailbox. The same cannot be said for the steady stream of "your email contained a virus" mail which continues to pour in. Finding our real mail among all of the virus notifications has become a bit of a challenge.

The thing is, of course, that we have not sent infected mail to anybody. Honest. Neither have many of the other people who have gotten these notifications. The software sending these notifications is working on the assumption that email containing virulent malware will also be so polite as to contain a correct return address. SoBig is far from the first infestation which forges return addresses, and it will certainly not be the last.

If virus notification email ever served a purpose, it has long since outlived it. Virus/worm scanning software has its place in organizations which are running vulnerable software, but as soon as it starts sending mail to addresses found in hostile mail, it becomes part of the problem. If you have anything to do with the development, deployment, or administration of such software, please consider turning the notification feature off.

Comments (21 posted)

New vulnerabilities

autorespond: buffer overflow

Package(s):autorespond CVE #(s):CAN-2003-0654
Created:August 18, 2003 Updated:October 1, 2003
Description: Christian Jaeger discovered a buffer overflow in autorespond, an email autoresponder used with qmail. This vulnerability could potentially be exploited by a remote attacker to gain the privileges of a user who has configured qmail to forward messages to autorespond. This vulnerability is currently not believed to be exploitable due to incidental limits on the length of the problematic input, but there may be situations in which these limits do not apply.

CAN-2003-0654

Alerts:
Debian DSA-373-1 autorespond 2003-08-16

Comments (none posted)

eroaster: insecure temporary file

Package(s):eroaster CVE #(s):CAN-2003-0656
Created:August 19, 2003 Updated:October 1, 2003
Description: A vulnerability was discovered in eroaster where it does not take any security precautions when creating a temporary file for the lockfile. This vulnerability could be exploited to overwrite arbitrary files with the privileges of the user running eroaster.

CAN-2003-0656

Alerts:
Gentoo 200309-04 eroaster 2003-09-02
Mandrake MDKSA-2003:083 eroaster 2003-08-19
Debian DSA-366-1 eroaster 2003-08-05

Comments (none posted)

netris: buffer overflow

Package(s):netris CVE #(s):CAN-2003-0685
Created:August 18, 2003 Updated:October 1, 2003
Description: Shaun Colley discovered a buffer overflow vulnerability in netris, a network version of a popular puzzle game. A netris client connecting to an untrusted netris server could be sent an unusually long data packet, which would be copied into a fixed-length buffer without bounds checking. This vulnerability could be exploited to gain the priviliges of the user running netris in client mode, if they connect to a hostile netris server.

CAN-2003-0685

Alerts:
Debian DSA-372-1 netris 2003-08-16

Comments (none posted)

openslp: temporary file creation vulnerability

Package(s):openslp CVE #(s):
Created:August 18, 2003 Updated:August 20, 2003
Description: According to this advisory there's a symbolic link vulnerability in one of the initscripts provided with openslp. The slpd.all_init file uses '/tmp/route.check' as a temporarily file in an unsafe manner.
Alerts:
Conectiva CLA-2003:723 openslp 2003-08-18

Comments (none posted)

Resources

August CRYPTO-GRAM newsletter

Bruce Schneier's CRYPTO-GRAM newsletter for August is out. It looks at airline security silliness, hidden text in documents, and Bruce's new book. "If I can name one overarching goal of the book, it's to explain how we all can make ourselves safer by thinking of security not in absolutes, but in terms of trade-offs -- the inevitable expenses, inconveniences, and diminished freedoms we accept (or have forced on us) in the name of enhanced security."

Full Story (comments: none)

CERT Advisory on GNU FTP server compromise

CERT has issued an advisory on the compromise of the GNU FTP server. "Because this system serves as a centralized archive of popular software, the insertion of malicious code into the distributed software is a serious threat. As the above announcement indicates, however, no source code distributions are believed to have been maliciously modified at this time"

Full Story (comments: none)

LinuxSecurity.com newsletters

The latest Linux Advisory Watch and Linux Security Week newsletters from LinuxSecurity.com are available.

Comments (none posted)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds