|
|
Log in / Subscribe / Register

Security

82% of email is spam

According to this eSecurity Planet article, 82% of all email which was sent in April was spam. That is the highest level ever measured - so far. Informal measurements here at LWN suggest that the 82% figure could even be a little low; some of our accounts here are receiving well over 1200 spams per day.

The cost of this endless stream of garbage is eventually going to push some part of the system to the breaking point. And the results may not be good. As the spam problem gets worse, most email users will be willing to accept almost anything from their ISPs or legislators which promises to improve things. It would not be surprising to see power grabs coming from several directions as the usual cynical forces try to take advantage of the situation. Are we ready for a world of centralized email systems, proprietary protocols which limit bulk mailing to "authorized" merchants, and new laws giving governments power to monitor and restrict email content?

If we're not ready for those things, we're going to have to think again about how to fight this problem. Filtering can be highly effective, but it does little for many of the costs of spam, including bandwidth usage and compromised servers. Filtering also does not work for all users. Somehow, a way must be found to keep spammers and their output off the net. If we can't come up with a way to do that which preserves the freedoms that have made the net what it is, we're likely to see rather less palatable attempted solutions imposed by others.

Comments (54 posted)

New vulnerabilities

eterm: command execution

Package(s):eterm CVE #(s):CAN-2003-0068
Created:April 29, 2004 Updated:May 5, 2004
Description: eterm has a vulnerability in which escape codes can be inserted by an attacker to cause the user to execute malicious commands.
Alerts:
Debian DSA-496-1 eterm 2004-04-29

Comments (none posted)

flim: insecure file creation

Package(s):flim CVE #(s):CAN-2004-0422
Created:May 5, 2004 Updated:December 16, 2004
Description: The emacs "flim" mode creates temporary files in an insecure fashion, possibly allowing a local attacker to overwrite files.
Alerts:
Fedora FEDORA-2004-546 flim 2004-12-15
Red Hat RHSA-2004:344-01 semi 2004-08-18
Debian DSA-500-1 flim 2004-05-01

Comments (none posted)

kolab: password disclosure

Package(s):kolab CVE #(s):
Created:May 5, 2004 Updated:May 27, 2004
Description: Kolab stores passwords in plain text format, and these passwords can read from the underlying LDAP database. See this advisory for more information.
Alerts:
Mandrake MDKSA-2004:052 kolab-server 2004-05-26
OpenPKG OpenPKG-SA-2004.019 kolab 2004-05-05

Comments (3 posted)

LHA: stack buffer overflows and directory traversal flaws

Package(s):LHA CVE #(s):CAN-2004-0234 CAN-2004-0235
Created:April 30, 2004 Updated:June 11, 2004
Description: LHA is an archiving and compression utility for LHarc format archives. Ulf Harnhammar discovered two stack buffer overflows and two directory traversal flaws in LHA. See this advisory+patch for more details.

CAN-2004-0234: An attacker could exploit the buffer overflows by creating a carefully crafted LHA archive in such a way that arbitrary code would be executed when the archive is tested or extracted by a victim.

CAN-2004-0235: An attacker could exploit the directory traversal issues to create files as the victim outside of the expected directory.

Alerts:
Whitebox WBSA-2004:178-01 LHA 2004-06-10
Debian DSA-515-1 lha 2004-06-05
Red Hat RHSA-2004:178-01 LHA 2004-05-26
Fedora FEDORA-2004-119 lha 2004-05-11
Gentoo 200405-02 LHa 2004-05-09
Conectiva CLA-2004:840 lha 2004-05-06
Slackware SSA:2004-125-01 lha 2004-05-04
Red Hat RHSA-2004:179-01 LHA 2004-04-30

Comments (2 posted)

libpng: denial of service vulnerability.

Package(s):libpng CVE #(s):CAN-2004-0421
Created:April 29, 2004 Updated:June 11, 2004
Description: The PNG library can accesses memory that is out of bounds when creating an error message, this can be exploited by a malformed PNG image file.
Alerts:
Whitebox WBSA-2004:180-01 libpng 2004-06-10
Red Hat RHSA-2004:180-01 libpng 2004-05-19
Gentoo 200405-06 libpng 2004-05-14
Fedora FEDORA-2004-106 libpng10 2004-05-05
Fedora FEDORA-2004-105 libpng 2004-05-05
Slackware SSA:2004-124-04 libpng 2004-05-02
Red Hat RHSA-2004:181-01 libpng 2004-04-30
Trustix TSLSA-2004-0025 libpng 2004-04-30
Debian DSA-498-1 libpng 2004-04-30
Mandrake MDKSA-2004:040 libpng 2004-04-29
OpenPKG OpenPKG-SA-2004.017 png 2004-04-29

Comments (none posted)

mc: multiple vulnerabilities

Package(s):mc CVE #(s):CAN-2004-0226 CAN-2004-0231 CAN-2004-0232
Created:April 29, 2004 Updated:May 26, 2004
Description: Midnight Commander has multiple vulnerabilities including buffer overflows, insecure temp files, and format string problems.
Alerts:
Gentoo 200405-21 mc 2004-05-26
Red Hat RHSA-2004:172-01 mc 2004-05-19
Slackware SSA:2004-136-01 mc 2004-05-14
SuSE SuSE-SA:2004:012 mc 2004-05-14
Red Hat RHSA-2004:173-01 mc 2004-04-30
Mandrake MDKSA-2004:039 mc 2004-04-29
Debian DSA-497-1 mc 2004-04-29

Comments (none posted)

proftpd privilege escalation

Package(s):proftpd CVE #(s):
Created:April 30, 2004 Updated:May 19, 2004
Description: A portability workaround was applied in version 1.2.9 of the FTP server ProFTPD. As a side-effect, CIDR based (aaa.bbb.ccc.ddd/NN) ACL entries in "Allow" and "Deny" directives act like an "AllowAll" directive and so FTP clients are granted access to files and directories although the server configuration might explicitly deny this. See this bug report.
Alerts:
Gentoo 200405-09 proftpd 2004-05-19
Mandrake MDKSA-2004:041 proftpd 2004-04-30
OpenPKG OpenPKG-SA-2004.018 proftpd 2004-04-30

Comments (none posted)

rsync remote file write attack

Package(s):rsync CVE #(s):CAN-2004-0426
Created:April 30, 2004 Updated:July 12, 2004
Description: See the rsync homepage for the April 2004 advisory: "There is a security problem in all versions prior to 2.6.1 that affects only people running a read/write daemon WITHOUT using chroot. If the user privs that such an rsync daemon is using is anything above "nobody", you are at risk of someone crafting an attack that could write a file outside of the module's "path" setting (where all its files should be stored). Please either enable chroot or upgrade to 2.6.1. People not running a daemon, running a read-only daemon, or running a chrooted daemon are totally unaffected."
Alerts:
Gentoo 200407-10 rsync 2004-07-12
Fedora FEDORA-2004-116 rsync 2004-07-01
Whitebox WBSA-2004:192-01 rsync 2004-06-10
Debian DSA-499-2 rsync 2004-06-02
OpenPKG OpenPKG-SA-2004.025 rsync 2004-05-21
Red Hat RHSA-2004:192-01 rsync 2004-05-19
Mandrake MDKSA-2004:042 rsync 2004-05-10
Slackware SSA:2004-124-01 rsync 2004-05-02
Debian DSA-499-1 rsync 2004-05-01
Trustix TSLSA-2004-0024 rsync 2004-04-29

Comments (none posted)

samba: local root and symlink vulnerabilities

Package(s):samba CVE #(s):
Created:April 29, 2004 Updated:May 5, 2004
Description: Two vulnerabilities in Samba have been found. Smbfs has a setuid root exploit problem, and smbprint has a tempfile symlink vulnerability.
Alerts:
Netwosix NW-2004-0013 samba 2004-05-01
Gentoo 200404-21 # 2004-04-29

Comments (none posted)

sysklogd: heap overflow

Package(s):sysklogd CVE #(s):
Created:April 29, 2004 Updated:May 5, 2004
Description: Sysklogd has a memory allocation vulnerability that can allow a malicious attacker to write to unallocated memory and crash sysklogd.
Alerts:
Slackware SSA:2004-124-02 sysklogd 2004-05-02
Mandrake MDKSA-2004:038 sysklogd 2004-04-28

Comments (none posted)

xine-lib: malicious code execution

Package(s):xine-lib CVE #(s):CAN-2004-0433
Created:May 3, 2004 Updated:May 28, 2004
Description: A vulnerability exists in xine-lib where playing a specially crafted Real RTSP stream could run malicious code as the user playing the stream. More details can be found in this advisory. The problem has been fixed in xine-lib 1-rc4.
Alerts:
Gentoo 200405-24 mplayer 2004-05-28
Slackware SSA:2004-124-03 xine 2004-05-02

Comments (none posted)

Events

SummerCon 2004 - Official Announcement

SummerCon 2004 is happening June 11 to 13 in Pittsburgh, PA. The call for papers is out; submissions are due by May 15.

Full Story (comments: none)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds