|
|
Log in / Subscribe / Register

Security

Brief items

Lobbying for insecurity (Register)

Here is an article in the Register on the U.S. National Security Agency's contribution to open-source security, Security-Enhanced Linux. "The most secure software in the world doesn't improve security if nobody runs it, or if it's incompatible with what the vast majority of people run. Standard is better than better. VINES networks might be more secure than TCP/IP but it does little to secure the Internet as a whole. MD5 password hashing was always more secure than old Unix crypt password hashes, but until vendors started shipping the code, and integrating it via Pluggable Authentication Modules, it made little difference."

Comments (none posted)

Website Security Flaw Costs ZD (Wired)

Brian McWilliams reports, in Wired, that a security oversight which allowed unauthorized web access to some customer's identifying information and credit card numbers has resulted in Ziff-Davis Media agreeing to pay $500 each to about 50 affected customers and an additional $100,000 to the state of New York.
An investigation led by New York with the assistance of Neohapsis revealed that Ziff-Davis failed to follow industry-standard security practices, such as encrypting and password-protecting the data, and keeping track of who accessed it.

According to the settlement agreement (PDF), the attorneys general concluded that Ziff-Davis was guilty of violating their states' business laws prohibiting deceptive business practices and false advertising.

Comments (none posted)

Security reports

SWS Web Server version 0.1.0 denial of service vulnerability

A proof of concept has been published for a denial of service attack on version 0.1.0 of the SWS Web Server.

Full Story (comments: none)

Cacti security issues

Knights of the Routing Table reports three low priority security issues in Cacti version 0.9.8, and possibily earlier versions. A valid username and password with administrator rights is required to exploit any of the vulnerabilities.

Cacti is a complete frondend to rrdtool, it stores all of the nessesary information to create graphs and populate them with data in a MySQL database. The frontend is completely PHP driven. Along with being able to maintain Graphs, Data Sources, and Round Robin Archives in a database, cacti handles the data gathering also. There is also SNMP support for those used to creating traffic graphs with MRTG.

Full Story (comments: none)

(Proprietary product) Aestiva's HTML/OS cross-site scripting vulnerability

A cross-site scripting vulnerability was reported in Aestiva's HTML/OS.

Full Story (comments: none)

New vulnerabilities

Ethereal 0.9.6 fixes potential remote code execution vulnerability

Package(s):ethereal CVE #(s):CAN-2002-0834 CAN-2002-0821 CAN-2002-0822
Created:September 4, 2002 Updated:September 11, 2002
Description: Ethereal 0.9.6 was released on August 20, 2002 fixing a serious buffer overflow vulnerability in the ISIS protocol dissector in Ethereal 0.9.5 and earlier versions.
It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.

Ethereal 0.9.4 has multiple buffer overflow and other vulnerabilities hat are best delt with by upgrading to 0.9.6. These vulnerabilities may allow remote attackers to cause a denial of service or execute arbitrary code.

Updating now, rather than later, is recommended.

Alerts:
Debian DSA-162-1 ethereal 2002-09-06
Eridani ERISA-2002:040 ethereal 2002-09-03
Gentoo ethereal-20020830 ethereal 2002-08-30
Red Hat RHSA-2002:169-13 ethereal 2002-08-28

Comments (none posted)

Scrollkeeper temporary file vulnerability

Package(s):scrollkeeper CVE #(s):CAN-2002-0662
Created:September 4, 2002 Updated:September 4, 2002
Description: There is a tempfile vulnerability in ScrollKeeper versions between 0.3 and 0.3.11.

The scrollkeeper-get-cl command generates temporary files with predictable names and follows symbolic links. "These files are created when a user logs in to a GNOME session and are created as the user who logged in. This means an attacker with local access can easily create and overwrite files as another user." For more information see this security advisory from Spybreak.

ScrollKeeper is a cataloging system for documentation on open systems. It manages documentation metadata (as specified by the Open Source Metadata Framework(OMF)) and provides a simple API to allow help browsers to find, sort, and search the document catalog.
Alerts:
Gentoo scrollkeeper-20020904 scrollkeeper 2002-09-04
Debian DSA-160-1 scrollkeeper 2002-09-03
Red Hat RHSA-2002:186-07 scrollkeeper 2002-08-28

Comments (none posted)

KDE 3.0.3 fixes X.509 certificate check vulnerability

Package(s):kde CVE #(s):
Created:September 4, 2002 Updated:September 11, 2002
Description: The SSL implementation used by previous version of KDE accepted, without alerting the user, any X.509 certificate signed by any entity under specific conditions. This bug allows "for undetected MITM attacks ("man in the mittle"), which could compromise an encrypted HTTPS session."
Alerts:
Mandrake MDKSA-2002:058 kdelibs 2002-09-09
Conectiva CLA-2002:519 kde 2002-08-29

Comments (none posted)

PXE server denial of service vulnerability

Package(s):pxe CVE #(s):CAN-2002-0835
Created:September 4, 2002 Updated:November 11, 2002
Description: The PXE server can be crashed using DHCP packets from some Voice Over IP (VOIP) phones. Maliciously formed DHCP packets could be used by a remote attacker to effect a denial of service attack.

The PXE package contains the PXE (Preboot eXecution Environment) server and code needed for Linux to boot from a boot disk image on a Linux PXE server.
Alerts:
SCO Group CSSA-2002-044.0 Preboot 2002-11-11
Eridani ERISA-2002:041 pxe 2002-09-03
Red Hat RHSA-2002:162-12 pxe 2002-08-30

Comments (none posted)

Resources

CERT Summary CS-2002-03

The latest CERT summary, dated August 30, 2002, is available.
Each quarter, the CERT Coordination Center (CERT/CC) issues the CERT summary to draw attention to the types of attacks reported to our incident response team, as well as other noteworthy incident and vulnerability information. The summary includes pointers to sources of information for dealing with the problems.

Full Story (comments: none)

Linux Security Week

The September 2nd Linux Security Week newsletter from LinuxSecurity.com is available.

Full Story (comments: none)

Metis 1.4.1 released

Sacha Faust announces the release of Metis 1.4.1 to fix a bug in last week's release of version 1.4.0. "This is a tool I wrote to collect information from web servers." Metis was written for the Open Source Security Testing Methodology (OSSTM).

Full Story (comments: none)

Events

Upcoming Security Events

Date Event Location
September 19 - 20, 2002SEcurity of Communications on the Internet 2002(SECI'02)Tunis, Tunisia
September 23 - 26, 2002New Security Paradigms Workshop 2002(The Chamberlain Hotel)Hampton, Virginia, USA
September 23 - 25, 2002University of Idaho Workshop on Computer Forensics(University of Idaho)Moscow, Idaho, USA
September 26 - 27, 2002HiverCon 2002(Hilton Hotel)Dublin, Ireland
September 27 - 29, 2002ToorCon 2002(San Diego Concourse)San Diego, CA, USA
October 16 - 18, 2002Recent Advances in Intrusion Detection 2002(RAID 2002)Zurich, Switzerland

For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.

Comments (none posted)

Page editor: Dennis Tenney
Next page: Kernel development>>


Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds