Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try

A Selection of the Very Best Open Source Tutorials and Tools

Android Ice Cream Sandwich ported to x86 tablets, netbooks and notebooks

SECURITY: Google Chrome 17 Improves Security

How to read a CSV file in Perl?

Red Hat Brings Gluster to Amazon Cloud

New Linux kernel fixes power-saving issues



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
:Security Digest: December 2, 2004
Security Digest: December 2, 2004
Dec 3, 2004, 04 :45 UTC (0 Talkback[s]) (3803 reads)

Fedora Core


Fedora Update Notification
FEDORA-2004-487
2004-12-01

Product : Fedora Core 3
Name : cyrus-imapd
Version : 2.2.10
Release : 1.fc3
Summary : A high-performance mail server with IMAP, POP3, NNTP and SIEVE support.

Description :
The cyrus-imapd package contains the core of the Cyrus IMAP server. It is a scaleable enterprise mail system designed for use from small to large enterprise environments using standards-based internet mail technologies.

A full Cyrus IMAP implementation allows a seamless mail and bulletin board environment to be set up across multiple servers. It differs from other IMAP server implementations in that it is run on "sealed" servers, where users are not normally permitted to log in. The mailbox database is stored in parts of the filesystem that are private to the Cyrus IMAP server. All user access to mail is through software using the IMAP, POP3, or KPOP protocols. TLSv1 and SSL are supported for security.


Update Information:

Fix several buffer overflow problems that could be used as an exploit. Fixes the following security advisories: CAN-2004-1011 CAN-2004-1012 CAN-2004-1013 CAN-2004-1015


  • Tue Nov 30 2004 John Dennis <jdennis@redhat.com> 2.2.10-1.fc3
    • update to Simon Matter's 2.2.10 RPM, fixes bug #139382, security advisories: CAN-2004-1011 CAN-2004-1012 CAN-2004-1013 CAN-2004-1015
  • Wed Nov 24 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.10
  • Tue Nov 23 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.9
  • Fri Nov 19 2004 Simon Matter <simon.matter@invoca.ch>
    • changed scripts to use runuser instead of su if available
  • Thu Nov 18 2004 Simon Matter <simon.matter@invoca.ch>
    • changed requirement for file >= 3.35-1 from BuildPrereq to Requires, fixes RedHat's bug #124991
    • added acceptinvalidfrom patch to fix RedHat's bug #137705

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

3046ae0d6ae91d5a320a61d63d7cd758 SRPMS/cyrus-imapd-2.2.10-1.fc3.src.rpm
b96d8b8f7e004f15ea33e20d62487220 x86_64/cyrus-imapd-2.2.10-1.fc3.x86_64.rpm
cbd49b9ba05c908062ec9bbb870b96c9 x86_64/cyrus-imapd-murder-2.2.10-1.fc3.x86_64.rpm
dd901f900d3c5f35d5c1f5ba1ec04c2b x86_64/cyrus-imapd-nntp-2.2.10-1.fc3.x86_64.rpm
d20dbbc2a240d6b9a379e5628481a7a2 x86_64/cyrus-imapd-devel-2.2.10-1.fc3.x86_64.rpm
b13216f4a919d8cad9356e9f43d77f75 x86_64/perl-Cyrus-2.2.10-1.fc3.x86_64.rpm
5a21ed43e2ea56cdd7593ebaae2a8d9f x86_64/cyrus-imapd-utils-2.2.10-1.fc3.x86_64.rpm
8f2e20bdcda98aface6e953cb2fb7816 i386/cyrus-imapd-2.2.10-1.fc3.i386.rpm
1a7762f45b251d4305a68501d8160f0f i386/cyrus-imapd-murder-2.2.10-1.fc3.i386.rpm
50d7db7c3122324988eb3aa526c443ac i386/cyrus-imapd-nntp-2.2.10-1.fc3.i386.rpm
1e7f3b53af6f208d89d1825395530d77 i386/cyrus-imapd-devel-2.2.10-1.fc3.i386.rpm
ab9fefae62a9b7c342f5f662fcdc2748 i386/perl-Cyrus-2.2.10-1.fc3.i386.rpm
f7455698af9604eb8d7dcd371de5895f i386/cyrus-imapd-utils-2.2.10-1.fc3.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2004-489
2004-12-01

Product : Fedora Core 2
Name : cyrus-imapd
Version : 2.2.10
Release : 1.fc2
Summary : A high-performance mail server with IMAP, POP3, NNTP and SIEVE support.

Description :
The cyrus-imapd package contains the core of the Cyrus IMAP server. It is a scaleable enterprise mail system designed for use from small to large enterprise environments using standards-based internet mail technologies.

A full Cyrus IMAP implementation allows a seamless mail and bulletin board environment to be set up across multiple servers. It differs from other IMAP server implementations in that it is run on "sealed" servers, where users are not normally permitted to log in. The mailbox database is stored in parts of the filesystem that are private to the Cyrus IMAP server. All user access to mail is through software using the IMAP, POP3, or KPOP protocols. TLSv1 and SSL are supported for security.


Update Information:

Fix several buffer overflow problems that could be used as an exploit. Fixes the following security advisories: CAN-2004-1011 CAN-2004-1012 CAN-2004-1013 CAN-2004-1015


  • Tue Nov 30 2004 John Dennis <jdennis@redhat.com> 2.2.10-1.fc2
    • update to Simon Matter's 2.2.10 RPM, fixes bug #139382, security advisories: CAN-2004-1011 CAN-2004-1012 CAN-2004-1013 CAN-2004-1015
  • Wed Nov 24 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.10
  • Tue Nov 23 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.9
  • Fri Nov 19 2004 Simon Matter <simon.matter@invoca.ch>
    • changed scripts to use runuser instead of su if available
  • Thu Nov 18 2004 Simon Matter <simon.matter@invoca.ch>
    • changed requirement for file >= 3.35-1 from BuildPrereq to Requires, fixes RedHat's bug #124991
    • added acceptinvalidfrom patch to fix RedHat's bug #137705
  • Mon Oct 04 2004 Dan Walsh <dwalsh@redhat.com> 2.2.6-2.FC3.6
    • Change cyrus init scripts and cron job to use runuser instead of su
  • Fri Aug 06 2004 John Dennis <jdennis@redhat.com> 2.2.6-2.FC3.5
    • remove obsoletes tag, fixes bugs #127448, #129274
  • Wed Aug 04 2004 John Dennis <jdennis@redhat.com>
    • replace commas in release field with dots, bump build number
  • Tue Aug 03 2004 Simon Matter <simon.matter@invoca.ch>
    • fixed symlinks for x86_64, now uses the _libdir macro reported by John Dennis, fixes RedHat's bug #128964
    • removed obsoletes tag, fixes RedHat's bugs #127448, #129274
  • Mon Aug 02 2004 John Dennis <jdennis@redhat.com> 2.2.6-2,FC3,3
    • fix bug #128964, lib symlinks wrong on x86_64
  • Thu Jul 29 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.8
  • Thu Jul 29 2004 Simon Matter <simon.matter@invoca.ch>
    • updated autocreate and autosieve patches
    • made authorization a compile time option
    • added sieve-bc_eval patch
  • Tue Jul 27 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.7
    • modified autocreate patch or 2.2.7
    • removed snmpargs patch which was needed for RedHat 6.2
  • Tue Jul 13 2004 Simon Matter <simon.matter@invoca.ch>
    • added mboxlist / mboxname patches from CVS
  • Tue Jul 06 2004 Simon Matter <simon.matter@invoca.ch>
    • updated rmquota+deletemailbox patch
  • Sat Jul 03 2004 John Dennis <jdennis@redhat.com> - 2.2.6-2,FC3,1
    • bring up to date with Simon Matter's latest upstream rpm 2.2.6-2
    • comment out illegal tags Packager, Vendor, Distribution build for FC3
  • Wed Jun 30 2004 Simon Matter <simon.matter@invoca.ch>
    • added quota patches from CVS
  • Fri Jun 25 2004 Simon Matter <simon.matter@invoca.ch>
    • updated autocreate patch
  • Fri Jun 18 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.6
  • Fri Jun 11 2004 Simon Matter <simon.matter@invoca.ch>
    • updated autocreate and autosieve patches
  • Tue Jun 01 2004 Simon Matter <simon.matter@invoca.ch>
    • updated autocreate, autosieve and rmquota patches
    • fixed rmquota patch to build on gcc v3.3.x
    • added lmtp_sieve patch
  • Sat May 29 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.5
  • Fri May 28 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.5 pre-release
  • Mon May 24 2004 Simon Matter <simon.matter@invoca.ch>
    • added hash patch to fix a sig11 problem
    • added noncritical typo patch
  • Fri May 21 2004 Simon Matter <simon.matter@invoca.ch>
    • include OutlookExpress seenstate patch
    • fixed allnumeric patch
  • Thu May 20 2004 Simon Matter <simon.matter@invoca.ch>
    • don't enable cyrus-imapd per default
    • rename fetchnews to cyrfetchnews to avoid namespace conflicts with leafnode
    • replace fetchnews with cyrfetchnews in man pages
    • replace master with cyrus-master in man pages
  • Tue May 18 2004 Simon Matter <simon.matter@invoca.ch>
    • updated to 2.2.4

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

282783d2fff47052ce9af7943439b831 SRPMS/cyrus-imapd-2.2.10-1.fc2.src.rpm
084cd190d2e698d59a9ed03f45151f42 x86_64/cyrus-imapd-2.2.10-1.fc2.x86_64.rpm
e7a68608d3c73f9f013b28702566c2c9 x86_64/cyrus-imapd-murder-2.2.10-1.fc2.x86_64.rpm
7c0d7fe1769923f59f06414145b87fa0 x86_64/cyrus-imapd-nntp-2.2.10-1.fc2.x86_64.rpm
50fcbdfe08e215597afa16a3ca04f83a x86_64/cyrus-imapd-devel-2.2.10-1.fc2.x86_64.rpm
bbe82aeb7ada7220ce0b162b433e6c03 x86_64/perl-Cyrus-2.2.10-1.fc2.x86_64.rpm
2ebeb131a6eb52ccdb0706700f7e4d60 x86_64/cyrus-imapd-utils-2.2.10-1.fc2.x86_64.rpm
f0790e11402477fdc507a11ddc8a75d8 i386/cyrus-imapd-2.2.10-1.fc2.i386.rpm
d75e163a9659ed0a352c1e9753bbf93f i386/cyrus-imapd-murder-2.2.10-1.fc2.i386.rpm
43fc9f5476305e8a9b4b86f66236eba8 i386/cyrus-imapd-nntp-2.2.10-1.fc2.i386.rpm
d8c5813b05ab337aa419af14a9d5e470 i386/cyrus-imapd-devel-2.2.10-1.fc2.i386.rpm
1c638111d73229546980b9419fddda18 i386/perl-Cyrus-2.2.10-1.fc2.i386.rpm
c686870df1f217d40b0f288b78a07bd3 i386/cyrus-imapd-utils-2.2.10-1.fc2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Conectiva Linux


CONECTIVA LINUX SECURITY ANNOUNCEMENT

PACKAGE : cyrus-imapd
SUMMARY : Multiple vulnerabilities in cyrus-imapd
DATE : 2004-12-01 18:21:00
ID : CLA-2004:904
RELEVANT RELEASES : 9, 10


DESCRIPTION
cyrus-imapd[1] is an IMAP and POP3 mail server with several advanced features such as SASL authentication, server-side mail filtering, mailbox ACLs and others.

Stefan Esser from e-matters security recently published[2] several vulnerabilities in cyrus-imapd:

(if not mentioned otherwise, all vulnerabilities affect both Conectiva Linux 9 and 10)

1. "imapmagicplus" buffer overflow (CAN-2004-1011)[3] If the "imapmagicplus" option is enabled in the server's configuration file, then the LOGIN and PROXY commands can be abused to cause a buffer overflow, allowing remote unauthenticated attackers to execute arbitrary code as the "cyrus" user.

Later on it has been found that the proxyd service also suffered[6] (CAN-2004-1015) from the same problem.

Conectiva Linux 9 is not affected by these vulnerabilities.

2. PARTIAL command vulnerability (CAN-2004-1012)[4] The PARTIAL command parser has a vulnerability which would allow authenticated users to cause a memory corruption and possibly execute arbitrary code as the "cyrus" user.

3. FETCH command vulnerability (CAN-2004-1013)[5] The FETCH command parser has a vulnerability which would allow authenticated users to cause a memory corruption and possibly execute arbitrary code as the "cyrus" user.

All these vulnerabilities have been fixed upstream with new versions of cyrus-imapd: 2.2.10 for the 2.2.x branch and 2.1.17 for the 2.1.x branch.

Below are additional changes in our RPM packages:

  • for CL10: SNMP support has been removed. It needs a newer net-snmp library than the one that is currently being shipped;
  • for CL10: the script which attempts to convert the imapd.conf configuration file from 2.1.x to the 2.2.x format has been fixed. Previously it would mangle TLS directives;
  • for CL9: the init script has been fixed to allow GSSAPI authentication and also to restart the server if it was already running;
  • for CL9: the cyrus-imapd package now explicitly conflicts with uw-imap-server and uw-pop-server.

SOLUTION
It is recommended that all cyrus-imapd users upgrade their packages. The service will be automatically restarted after the upgrade if needed.

REFERENCES

  1. http://asg.web.cmu.edu/cyrus/imapd/
  2. http://security.e-matters.de/advisories/152004.html
  3. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1011
  4. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1012
  5. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1013
  6. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1015
  7. http://asg.web.cmu.edu/cyrus/download/imapd/changes.html

UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/10/SRPMS/cyrus-imapd-2.2.10-62338U10_2cl.src.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/cyrus-imapd-2.2.10-62338U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/cyrus-imapd-devel-2.2.10-62338U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/cyrus-imapd-devel-static-2.2.10-62338U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/cyrus-imapd-doc-2.2.10-62338U10_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/SRPMS/cyrus-imapd-2.1.17-28805U90_5cl.src.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/cyrus-imapd-2.1.17-28805U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/cyrus-imapd-devel-2.1.17-28805U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/cyrus-imapd-devel-static-2.1.17-28805U90_5cl.i386.rpm

ADDITIONAL INSTRUCTIONS
The apt tool can be used to perform RPM packages upgrades:

  • run: apt-get update
  • after that, execute: apt-get upgrade

Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en


All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en
Copyright (c) 2004 Conectiva Inc.
http://www.conectiva.com
CONECTIVA LINUX SECURITY ANNOUNCEMENT

PACKAGE : abiword
SUMMARY : Fix for buffer overflow vulnerability
DATE : 2004-12-01 13:28:00
ID : CLA-2004:902
RELEVANT RELEASES : 9, 10


DESCRIPTION
AbiWord[1] is a free word processing program similar to Microsoft(R) Word.
Wv[2] is a library which allows access to Microsoft Word files.

iDefense[3] discovered[4] a buffer overflow vulnerability[5] in the wv library which could allow an attacker to execute arbitrary code with the privileges of the user running the vulnerable application.

This announcement fixes the wv library which is included in AbiWord packages.

SOLUTION
It is recommended that all AbiWord users in Conectiva Linux upgrade their
packages.

REFERENCES

  1. http://www.abiword.org/
  2. http://wvware.sourceforge.net/
  3. http://www.idefense.com/
  4. http://www.idefense.com/application/poi/display?id=115&type=vulnerabilities&flashstatus=true
  5. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0645

UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/10/SRPMS/abiword-2.0.6-62012U10_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/abiword-2.0.6-62012U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/abiword-clipart-2.0.6-62012U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/abiword-plugins-impexp-2.0.6-62012U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/abiword-plugins-tools-2.0.6-62012U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/SRPMS/abiword-1.0.4-25186U90_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/abiword-1.0.4-25186U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/abiword-fonts-1.0.4-25186U90_1cl.i386.rpm

ADDITIONAL INSTRUCTIONS
The apt tool can be used to perform RPM packages upgrades:

  • run: apt-get update
  • after that, execute: apt-get upgrade

Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en


All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en
Copyright (c) 2004 Conectiva Inc.
http://www.conectiva.com


No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP