|
|
Log in / Subscribe / Register

Security

Brief items

Infrastructural attacks on free software

The recent compromise of several Debian servers has been well publicized. It appears that the Debian archive was unaffected, and Debian users need not be worried about malware entering their systems by that path. Certainly this event, like the recent kernel backdoor attempt, has raised awareness of the vulnerability of our software repositories. An attacker who is able to slip a bit of evil code into the wrong place could compromise many thousands of systems.

Less attention has been paid to the cost of having the Debian servers be unavailable for the better part of a week. Your editor, waiting for a working version of psycopg to be uploaded to unstable, was merely inconvenienced. Other users, who may have planned significant installations or upgrades, or who were trying to discuss problems with Debian developers will have been rather more inconvenienced. Debian developers, trying to get 3.0r2 out the door, were stopped dead for a while. These consequences are costly enough by themselves, but consider what could happen. Had a major security incident broken out while the Debian servers were unavailable, it would have been difficult or impossible for the project to respond quickly.

Linux systems are living things; even the most stable systems need occasional updates to stay secure. Linux users depend on the availability of their distributions' supporting infrastructure to keep their systems up to date. This sort of attack, by making that infrastructure unavailable, hurts users worldwide, and could leave them unable to respond quickly to serious security problems. Once again, we have been warned that our infrastructure is too fragile and insufficiently secure.

Comments (17 posted)

New vulnerabilities

iproute: local denial of service

Package(s):iproute net-tools CVE #(s):CAN-2003-0856
Created:November 25, 2003 Updated:December 14, 2004
Description: The iproute utility is susceptible to spoofed netlink messages sent by local users, with the result that denial of service attacks are possible.
Alerts:
Mandrake MDKSA-2004:148 iproute2 2004-12-13
Fedora FEDORA-2004-154 net-tools 2004-06-03
Fedora FEDORA-2004-115 iproute 2004-05-11
Debian DSA-492-1 iproute 2004-04-18
Gentoo 200404-10 # 2004-04-09
Red Hat RHSA-2003:316-01 iproute 2003-11-24

Comments (none posted)

opera buffer overflows

Package(s):opera CVE #(s):CAN-2003-0870
Created:November 20, 2003 Updated:November 24, 2003
Description: The Opera browser can cause a buffer allocated on the heap to overflow under certain HREFs when rendering HTML. The mail system is also deemed vulnerable and an attacker can send an email containing a malformed HREF, or plant the malicious HREF on a web site. Please see this advisory for further details. These vulnerabilities are fixed in Opera 7.22.
Alerts:
Gentoo 200311-02 net-www/opera 2003-11-19

Comments (1 posted)

Pan: denial of service

Package(s):Pan CVE #(s):CAN-2003-0855
Created:November 25, 2003 Updated:December 10, 2003
Description: Pan is a Gnome/GTK+ newsreader. A bug in Pan versions prior to 0.13.4 can cause Pan to crash when parsing an article header containing a very long author email address. This bug causes a crash (denial of service) but is not further exploitable.
Alerts:
Red Hat RHSA-2003:312-01 pan 2003-12-10
Red Hat RHSA-2003:311-01 Pan 2003-11-24

Comments (none posted)

phpSysInfo directory traversal

Package(s):phpsysinfo CVE #(s):CAN-2003-0536
Created:November 25, 2003 Updated:November 25, 2003
Description: phpSysInfo contains two vulnerabilities which could allow local files to be read or arbitrary PHP code to be executed, under the privileges of the web server process.
Alerts:
Gentoo 200311-06 dev-php/phpsysinfo 2003-11-22

Comments (none posted)

Resources

Quarterly CERT Summary

The quarterly CERT Summary - which describes the security issues being most actively exploited - is out. Of the nine vulnerabilities, six affect only Windows systems. The summary does, however, point out ongoing problems with OpenSSL, OpenSSH, and sendmail.

Full Story (comments: none)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds