Security
That OpenSSL Worm
This worm has been referred to by at least four different names: Apache/mod_ssl worm, linux.slapper.worm, bugtraq.c worm and Modap worm.On Friday September 13th the first reports appeared on Bugtraq of an active worm exploiting the OpenSSL buffer overflow vulnerability reported at the end of July. The next day CERT issued Advisory CA-2002-27 Apache/mod_ssl Worm.
By Sunday
September 15th, at 17:00 GMT, F-Secure Corporation reported 13,000 infected servers
out of "over 1,000,000 active OpenSSL
installations in the public web.
"
Updates to fix the problem, including backports to earlier versions of OpenSSL, had been available for over a month
from the OpenSSL project, Caldera, Conectiva, Debian, EnGarde, Eridani, Gentoo, Mandrake, OpenPKG, Red Hat, SuSE, Trustix and Yellow Dog.
SecurityFocus has completed and released a full analysis (PDF format) of the worm in addition to their initial incident Alert (PDF format). F-Secure is maintaining a "Virus Description" of this worm with lots of interesting information.
The first reports in the press appeared Friday, the day the worm was first seen, in CNET and Network World Fusion. The next day CNET put up another story with additional information. By Monday evening both the Register and TechWeb had published their reports on events to date. On Tuesday Network World Fusion reported that the worm has infected at least 30,000 Linux Apache Web servers.
Also, see this other article from TechWeb on the worm:
RUS-CERT has made available a tool to remotely detect vulnerable servers. However, Eric Rescorla has observed behavior different from what that tool expects.
In the unlikely event that you haven't already, applying the appropriate OpenSSL update might be a very good thing to do before reading any further.
Brief items
Mozilla bug leaks Web surfing data (CNET)
CNET has a short article about a little privacy bug in Mozilla's handling of referers. "The bug reveals the URL of the page someone is viewing to the Web server of the site last visited. This allows a Web server to track where people go after they leave the site, even if the next Web address comes from a bookmark or is manually typed into the browser." If you are using a Gecko-based browser, you can see the bug in action on this page.
September CRYPTO-GRAM newsletter
Bruce Schneier's CRYPTO-GRAM newsletter for September is out. It looks at possible new attack strategies for algorithms like AES, the Word97 vulnerability, and more. "We're seeing more and more of this: vulnerabilities in products that are no longer supported. When the SNMP vulnerabilities were published earlier this year, many products with the vulnerability were no longer supported. Some were made by companies no longer in business."
Security reports
ht://Check cross-site scripting problems
Ulf Harnhammar reports potential cross-site scripting problems in ht://Check version 1.1, and possibly earlier versions as well. "It doesn't remove HTML tags before displaying the crawled web servers' "Server:" headers and other information."
xbreaky symlink vulnerability
Marco van Berkum reports a symlink vulnerability in the xbreaky breakout game for X. If xbreaky is installed as suid, the vulnerabilty can be abused by any user to overwrite any file on the filesystem. Distributions which include xbreaky may or may not install it suid root.MIMEDefang version 2.21 scans fragmented mail messages
The folks at Roaring Penguin Software have released, under the GPL, version 2.21 of MIMEDefang to deal with this Outlook Express based attack to bypass SMTP-based content filter engines.
A patched version of MIME-Tools that addresses the problem is also avilable as well as version 1.2-F17 of Roaring Penguin's commercial CanIt anti-spam solution based on MIMEDefang 2.21.
(Proprietary product) Race conditions in BRU Workstation 17.0
A race condition in TolisGroup's BRU Workstation 17.0 can be used to clobber any system file." According to this followup post, TolisGroup have responded with confirmation of an update for a race condition reported previously, and an estimated date for a new update for this one.(Proprietary product) File disclosure vulnerability in DB4Web application server
Stefan Bagdohn reports a file disclosure vulnerability in the DB4Web high-performance application server from Guardeonic Solutions AG. The DB4Web team has already provided an update which is available from here.
New vulnerabilities
Local privilege escalation vulnerability in XFree86
| Package(s): | xf86 xfree86 | CVE #(s): | |||||||||||||||||
| Created: | September 18, 2002 | Updated: | October 27, 2002 | ||||||||||||||||
| Description: | XFree86 version 4.2.1 fixes a problem in Xlib that made it possible to execute arbitrary code in privileged clients. Other libraries are dynamically loaded by libX11.so as needed. When linking against a setuid program, arbitrary code could be loaded and executed from a pathname controlled by the user. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
Cross-site scripting vulnerability in Konqueror for KDE 3.0.3
| Package(s): | kdelibs | CVE #(s): | |||||||||||||||||
| Created: | September 17, 2002 | Updated: | November 18, 2002 | ||||||||||||||||
| Description: | Konqueror for KDE 3.0.3, and earlier versions, is subject to this cross-site scripting vulnerability. Since the problem is in kdelibs, any other application which uses the KHTML renderer is also vulnerable. Javascript code running in one frame can access other frames which should be inaccessible. The problem is fixed in kdelibs 3.0.3a. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
Buffer overflow vulnerabilities in purity
| Package(s): | purity | CVE #(s): | |||||
| Created: | September 17, 2002 | Updated: | September 26, 2002 | ||||
| Description: | It seems that the "purity" game isn't entirely pure itself - a couple of buffer overflows have been found which could be exploited to gain access to the "games" group on Debian systems. Rather than face the prospect of people tampering with their nethack scores, the Debian Project released the first upgrade closing the vulnerability. | ||||||
| Alerts: |
| ||||||
Resources
Linux Security Week and Advisory Watch
The September 16th Linux Security Week and September 13th Linux Advisory Watch newsletters from LinuxSecurity.com are available.chkrootkit 0.37 is now available
Klaus Steding-Jessen announces the release of chkrootkit version 0.37. chkrootkit is a tool to locally check for signs of a rootkit.Well worth a look, especially if you arn't familiar with this useful tool.
Four final computer security guidelines availble from NIST
The US National Institute of Standards and Technology (NIST) announces the final publication of four computer security guidelines available from here.The four NIST Special Publications are:
- Security for Telecommuting and Broadband Communications
- Security Guide for Interconnecting Information Technology Systems
- Procedures for Handling Security Patches
- Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme.
Choosing passwords: random, mnemonic phrases and more
Folks at the Cambridge University Computer Laboratory have done a good study on different password selection approaches which is summarized in two papers:- The Memorability and Security of Passwords - Some Empirical Results by Jianxin Yan, Alan Blackwell, Ross Anderson and Alasdair Grant (PDF format)
- A Note on Proactive Password Checking by Jianxin Jeff Yan (PDF format)
Crispin Cowan also has some interesting comments on the conclutions reached by the study.
Events
Final Speakers Announced for HiverCon 2002
HiverCon 2002 is scheduled for November 26th and 27th, 2002 in Dublin Ireland.
Upcoming Security Events
| Date | Event | Location |
|---|---|---|
| September 19 - 20, 2002 | SEcurity of Communications on the Internet 2002(SECI'02) | Tunis, Tunisia |
| September 23 - 26, 2002 | New Security Paradigms Workshop 2002 | (The Chamberlain Hotel)Hampton, Virginia, USA |
| September 23 - 25, 2002 | University of Idaho Workshop on Computer Forensics | (University of Idaho)Moscow, Idaho, USA |
| September 27 - 29, 2002 | ToorCon 2002 | (San Diego Concourse)San Diego, CA, USA |
| October 16 - 18, 2002 | Recent Advances in Intrusion Detection 2002(RAID 2002) | Zurich, Switzerland |
| November 26 - 27, 2002 | HiverCon 2002 | (Burlington Hotel)Dublin, Ireland |
For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.
Page editor: Dennis Tenney
Next page:
Kernel development>>
