Security
Brief items
Lobbying for insecurity (Register)
Here is an article in the Register on the U.S. National Security Agency's contribution to open-source security, Security-Enhanced Linux. "The most secure software in the world doesn't improve security if nobody runs it, or if it's incompatible with what the vast majority of people run. Standard is better than better. VINES networks might be more secure than TCP/IP but it does little to secure the Internet as a whole. MD5 password hashing was always more secure than old Unix crypt password hashes, but until vendors started shipping the code, and integrating it via Pluggable Authentication Modules, it made little difference."
Website Security Flaw Costs ZD (Wired)
Brian McWilliams reports, in Wired, that a security oversight which allowed unauthorized web access to some customer's identifying information and credit card numbers has resulted in Ziff-Davis Media agreeing to pay $500 each to about 50 affected customers and an additional $100,000 to the state of New York.According to the settlement agreement (PDF), the attorneys general concluded that Ziff-Davis was guilty of violating their states' business laws prohibiting deceptive business practices and false advertising.
Security reports
SWS Web Server version 0.1.0 denial of service vulnerability
A proof of concept has been published for a denial of service attack on version 0.1.0 of the SWS Web Server.Cacti security issues
Knights of the Routing Table reports three low priority security issues in Cacti version 0.9.8, and possibily earlier versions. A valid username and password with administrator rights is required to exploit any of the vulnerabilities.
(Proprietary product) Aestiva's HTML/OS cross-site scripting vulnerability
A cross-site scripting vulnerability was reported in Aestiva's HTML/OS.
New vulnerabilities
Ethereal 0.9.6 fixes potential remote code execution vulnerability
| Package(s): | ethereal | CVE #(s): | CAN-2002-0834 CAN-2002-0821 CAN-2002-0822 | ||||||||||||||||
| Created: | September 4, 2002 | Updated: | September 11, 2002 | ||||||||||||||||
| Description: | Ethereal 0.9.6 was released
on August 20, 2002 fixing a serious
buffer overflow vulnerability in the ISIS protocol dissector in Ethereal 0.9.5 and earlier versions.
It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.
Ethereal 0.9.4 has multiple buffer overflow and other vulnerabilities hat are best delt with by upgrading to 0.9.6. These vulnerabilities may allow remote attackers to cause a denial of service or execute arbitrary code. Updating now, rather than later, is recommended. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
Scrollkeeper temporary file vulnerability
| Package(s): | scrollkeeper | CVE #(s): | CAN-2002-0662 | ||||||||||||
| Created: | September 4, 2002 | Updated: | September 4, 2002 | ||||||||||||
| Description: | There is
a tempfile vulnerability in ScrollKeeper versions between 0.3 and 0.3.11.
The scrollkeeper-get-cl command generates temporary files with predictable names and follows symbolic links. "These files are created when a user logs in to a GNOME session and are created as the user who logged in. This means an attacker with local access can easily create and overwrite files as another user." For more information see this security advisory from Spybreak.
ScrollKeeper is a cataloging system for documentation on open
systems. It manages documentation metadata (as specified
by the Open
Source Metadata Framework(OMF)) and provides a simple
API to allow help browsers to find, sort, and search
the document catalog.
| ||||||||||||||
| Alerts: |
| ||||||||||||||
KDE 3.0.3 fixes X.509 certificate check vulnerability
| Package(s): | kde | CVE #(s): | |||||||||
| Created: | September 4, 2002 | Updated: | September 11, 2002 | ||||||||
| Description: | The SSL implementation used by previous version of KDE accepted, without alerting the user, any X.509 certificate signed by any entity under specific conditions. This bug allows "for undetected MITM attacks ("man in the mittle"), which could compromise an encrypted HTTPS session." | ||||||||||
| Alerts: |
| ||||||||||
PXE server denial of service vulnerability
| Package(s): | pxe | CVE #(s): | CAN-2002-0835 | ||||||||||||
| Created: | September 4, 2002 | Updated: | November 11, 2002 | ||||||||||||
| Description: | The PXE server can be crashed using DHCP packets from
some Voice Over IP (VOIP) phones. Maliciously formed
DHCP packets could be used by a remote attacker to effect a
denial of service attack.
The PXE package contains the PXE (Preboot eXecution Environment)
server and code needed for Linux to boot from a boot disk image on a
Linux PXE server.
| ||||||||||||||
| Alerts: |
| ||||||||||||||
Resources
CERT Summary CS-2002-03
The latest CERT summary, dated August 30, 2002, is available.Linux Security Week
The September 2nd Linux Security Week newsletter from LinuxSecurity.com is available.Metis 1.4.1 released
Sacha Faust announces the release of Metis 1.4.1 to fix a bug in last week's release of version 1.4.0. "This is a tool I wrote to collect information from web servers." Metis was written for the Open Source Security Testing Methodology (OSSTM).
Events
Upcoming Security Events
| Date | Event | Location |
|---|---|---|
| September 19 - 20, 2002 | SEcurity of Communications on the Internet 2002(SECI'02) | Tunis, Tunisia |
| September 23 - 26, 2002 | New Security Paradigms Workshop 2002 | (The Chamberlain Hotel)Hampton, Virginia, USA |
| September 23 - 25, 2002 | University of Idaho Workshop on Computer Forensics | (University of Idaho)Moscow, Idaho, USA |
| September 26 - 27, 2002 | HiverCon 2002 | (Hilton Hotel)Dublin, Ireland |
| September 27 - 29, 2002 | ToorCon 2002 | (San Diego Concourse)San Diego, CA, USA |
| October 16 - 18, 2002 | Recent Advances in Intrusion Detection 2002(RAID 2002) | Zurich, Switzerland |
For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.
Page editor: Dennis Tenney
Next page:
Kernel development>>
