Security
82% of email is spam
According to this eSecurity Planet article, 82% of all email which was sent in April was spam. That is the highest level ever measured - so far. Informal measurements here at LWN suggest that the 82% figure could even be a little low; some of our accounts here are receiving well over 1200 spams per day.The cost of this endless stream of garbage is eventually going to push some part of the system to the breaking point. And the results may not be good. As the spam problem gets worse, most email users will be willing to accept almost anything from their ISPs or legislators which promises to improve things. It would not be surprising to see power grabs coming from several directions as the usual cynical forces try to take advantage of the situation. Are we ready for a world of centralized email systems, proprietary protocols which limit bulk mailing to "authorized" merchants, and new laws giving governments power to monitor and restrict email content?
If we're not ready for those things, we're going to have to think again about how to fight this problem. Filtering can be highly effective, but it does little for many of the costs of spam, including bandwidth usage and compromised servers. Filtering also does not work for all users. Somehow, a way must be found to keep spammers and their output off the net. If we can't come up with a way to do that which preserves the freedoms that have made the net what it is, we're likely to see rather less palatable attempted solutions imposed by others.
New vulnerabilities
eterm: command execution
| Package(s): | eterm | CVE #(s): | CAN-2003-0068 | ||||
| Created: | April 29, 2004 | Updated: | May 5, 2004 | ||||
| Description: | eterm has a vulnerability in which escape codes can be inserted by an attacker to cause the user to execute malicious commands. | ||||||
| Alerts: |
| ||||||
flim: insecure file creation
| Package(s): | flim | CVE #(s): | CAN-2004-0422 | ||||||||||||
| Created: | May 5, 2004 | Updated: | December 16, 2004 | ||||||||||||
| Description: | The emacs "flim" mode creates temporary files in an insecure fashion, possibly allowing a local attacker to overwrite files. | ||||||||||||||
| Alerts: |
| ||||||||||||||
kolab: password disclosure
| Package(s): | kolab | CVE #(s): | |||||||||
| Created: | May 5, 2004 | Updated: | May 27, 2004 | ||||||||
| Description: | Kolab stores passwords in plain text format, and these passwords can read from the underlying LDAP database. See this advisory for more information. | ||||||||||
| Alerts: |
| ||||||||||
LHA: stack buffer overflows and directory traversal flaws
| Package(s): | LHA | CVE #(s): | CAN-2004-0234 CAN-2004-0235 | ||||||||||||||||||||||||||||||||
| Created: | April 30, 2004 | Updated: | June 11, 2004 | ||||||||||||||||||||||||||||||||
| Description: | LHA is an archiving and compression utility for LHarc format archives. Ulf
Harnhammar discovered two stack buffer overflows and two directory
traversal flaws in LHA. See this advisory+patch for more details.
CAN-2004-0234: An attacker could exploit the buffer overflows by creating a carefully crafted LHA archive in such a way that arbitrary code would be executed when the archive is tested or extracted by a victim. CAN-2004-0235: An attacker could exploit the directory traversal issues to create files as the victim outside of the expected directory. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
libpng: denial of service vulnerability.
| Package(s): | libpng | CVE #(s): | CAN-2004-0421 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | April 29, 2004 | Updated: | June 11, 2004 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | The PNG library can accesses memory that is out of bounds when creating an error message, this can be exploited by a malformed PNG image file. | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
mc: multiple vulnerabilities
| Package(s): | mc | CVE #(s): | CAN-2004-0226 CAN-2004-0231 CAN-2004-0232 | ||||||||||||||||||||||||||||
| Created: | April 29, 2004 | Updated: | May 26, 2004 | ||||||||||||||||||||||||||||
| Description: | Midnight Commander has multiple vulnerabilities including buffer overflows, insecure temp files, and format string problems. | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
proftpd privilege escalation
| Package(s): | proftpd | CVE #(s): | |||||||||||||
| Created: | April 30, 2004 | Updated: | May 19, 2004 | ||||||||||||
| Description: | A portability workaround was applied in version 1.2.9 of the FTP server ProFTPD. As a side-effect, CIDR based (aaa.bbb.ccc.ddd/NN) ACL entries in "Allow" and "Deny" directives act like an "AllowAll" directive and so FTP clients are granted access to files and directories although the server configuration might explicitly deny this. See this bug report. | ||||||||||||||
| Alerts: |
| ||||||||||||||
rsync remote file write attack
| Package(s): | rsync | CVE #(s): | CAN-2004-0426 | ||||||||||||||||||||||||||||||||||||||||
| Created: | April 30, 2004 | Updated: | July 12, 2004 | ||||||||||||||||||||||||||||||||||||||||
| Description: | See the rsync homepage for the
April 2004
advisory: "There is a security problem in all versions prior to 2.6.1 that affects only people running a read/write daemon WITHOUT using chroot. If the user privs that such an rsync daemon is using is anything above "nobody", you are at risk of someone crafting an attack that could write a file outside of the module's "path" setting (where all its files should be stored). Please either enable chroot or upgrade to 2.6.1. People not running a daemon, running a read-only daemon, or running a chrooted daemon are totally unaffected." | ||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||
samba: local root and symlink vulnerabilities
| Package(s): | samba | CVE #(s): | |||||||||
| Created: | April 29, 2004 | Updated: | May 5, 2004 | ||||||||
| Description: | Two vulnerabilities in Samba have been found. Smbfs has a setuid root exploit problem, and smbprint has a tempfile symlink vulnerability. | ||||||||||
| Alerts: |
| ||||||||||
sysklogd: heap overflow
| Package(s): | sysklogd | CVE #(s): | |||||||||
| Created: | April 29, 2004 | Updated: | May 5, 2004 | ||||||||
| Description: | Sysklogd has a memory allocation vulnerability that can allow a malicious attacker to write to unallocated memory and crash sysklogd. | ||||||||||
| Alerts: |
| ||||||||||
xine-lib: malicious code execution
| Package(s): | xine-lib | CVE #(s): | CAN-2004-0433 | ||||||||
| Created: | May 3, 2004 | Updated: | May 28, 2004 | ||||||||
| Description: | A vulnerability exists in xine-lib where playing a specially crafted Real RTSP stream could run malicious code as the user playing the stream. More details can be found in this advisory. The problem has been fixed in xine-lib 1-rc4. | ||||||||||
| Alerts: |
| ||||||||||
Events
SummerCon 2004 - Official Announcement
SummerCon 2004 is happening June 11 to 13 in Pittsburgh, PA. The call for papers is out; submissions are due by May 15.
Page editor: Jonathan Corbet
Next page:
Kernel development>>
