|
|
|
| Top White Papers
Current Newswire:
Advisories, February 13, 2007Feb 14, 2007, 04:45 (0 Talkback[s])Gentoo LinuxGentoo Linux Security Advisory [UPDATE] GLSA 200611-05:02 Severity: High UpdateThe original fix introduced a new vulnerability allowing the listing of any arbitrary directory with root group permissions due to a typo in the setgid() call. New fixed packages are available. Also, this update adds a second CVE reference which was not originally mentionned while it was covered by the original fix. Additionally, please note that the Netkit FTP Server package has been renamed from net-ftp/ftpd to net-ftp/netkit-ftpd. The updated sections appear below. Backgroundnet-ftp/netkit-ftpd is the Linux Netkit FTP server with optional SSL support. Affected packages
Package / Vulnerable / Unaffected
1 net-ftp/netkit-ftpd < 0.17-r5 >= 0.17-r5 ResolutionAll Netkit FTP Server users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-ftp/netkit-ftpd-0.17-r5"
References[ 1 ] CVE-2006-5778 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5778 [ 2 ] CVE-2006-6008 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6008 AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200611-05.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Gentoo Linux Security Advisory GLSA 200702-01 Severity: Normal SynopsisMultiple flaws exist in the Samba suite of programs, the most serious of which could result in the execution of arbitrary code. BackgroundSamba is a suite of SMB and CIFS client/server programs for UNIX. Affected packages
Package / Vulnerable / Unaffected
1 net-fs/samba < 3.0.24 >= 3.0.24 DescriptionA format string vulnerability exists in the VFS module when handling AFS file systems and an infinite loop has been discovered when handling file rename operations. ImpactA user with permission to write to a shared AFS file system may be able to compromise the smbd process and execute arbitrary code with the permissions of the daemon. The infinite loop could be abused to consume excessive resources on the smbd host, denying service to legitimate users. WorkaroundThere is no known workaround at this time. ResolutionAll Samba users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-fs/samba-3.0.24"
References[ 1 ] CVE-2007-0452 http://samba.org/samba/security/CVE-2007-0452.html [ 2 ] CVE-2007-0454 http://samba.org/samba/security/CVE-2007-0454.html AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200702-01.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Gentoo Linux Security Advisory GLSA 200702-02 Severity: High SynopsisA flaw in ProFTPD may allow a local attacker to obtain root privileges. BackgroundProFTPD is a powerful, configurable, and free FTP daemon. Affected packages
Package / Vulnerable / Unaffected
1 net-ftp/proftpd < 1.3.1_rc1 >= 1.3.1_rc1 DescriptionA flaw exists in the mod_ctrls module of ProFTPD, normally used to allow FTP server administrators to configure the daemon at runtime. ImpactAn FTP server administrator permitted to interact with mod_ctrls could potentially compromise the ProFTPD process and execute arbitrary code with the privileges of the FTP Daemon, which is normally the root user. WorkaroundDisable mod_ctrls, or ensure only trusted users can access this feature. ResolutionAll ProFTPD users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-ftp/proftpd-1.3.1_rc1"
References[ 1 ] CVE-2006-6563 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6563 AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200702-02.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Gentoo Linux Security Advisory GLSA 200702-03 Severity: Normal SynopsisSnort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service. BackgroundSnort is a widely deployed intrusion detection program. Affected packages
Package / Vulnerable / Unaffected
1 net-analyzer/snort < 2.6.1.2 >= 2.6.1.2 DescriptionRandy Smith, Christian Estan and Somesh Jha discovered that the rule matching algorithm of Snort can be exploited in a way known as a "backtracking attack" to perform numerous time-consuming operations. ImpactA remote attacker could send specially crafted network packets, which would result in the cessation of the detections and the consumption of the CPU resources. WorkaroundThere is no known workaround at this time. ResolutionAll Snort users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/snort-2.6.1.2"
References[ 1 ] CVE-2006-6931 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6931 AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200702-03.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Mandriva LinuxMandriva Linux Security Advisory MDKSA-2007:042 Package : smb4k Problem Description: Kees Cook performed an audit on the Smb4K program and discovered a number of vulnerabilities and security weaknesses that have been addressed and corrected in Smb4K 0.8.0 which is being provided with this update. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0472 Updated Packages: Mandriva Linux 2007.0: Mandriva Linux 2007.0/X86_64: To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com Type Bits/KeyID Date User ID Trustix Secure LinuxTrustix Secure Linux Security Advisory #2007-0007 Package names: fetchmail, gd, php, postgresql, samba Package description: fetchmail Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6,and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. gd php postgresql samba Problem description:
The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the names CVE-2006-5867 and CVE-2006-5974 to these issues. gd < TSL 3.0 > < TSL 2.2 >
The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CVE-2007-0455 to this issue. php < TSL 3.0 > < TSL 2.2 >
postgresql < TSL 3.0 > < TSL 2.2 > < TSEL 2 >
The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the names CVE-2007-0555 and CVE-2007-0556 to these issues. samba < TSL 3.0 > < TSL 2.2 > < TSEL 2 >
The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the names CVE-2007-0452, CVE-2007-0453 and CVE-2007-0454 to these issue. Action: Location: About Trustix Secure Linux: Automatic updates: Questions? Verification: The advisory itself is available from the errata pages at MD5sums of the packages: de6b10865bb6ad13a1a5934903d6cece 3.0/rpms/fetchmail-6.3.6-1tr.i586.rpm f04e1c33d8c11352a8115a178bce8806 3.0/rpms/gd-2.0.33-7tr.i586.rpm faff5121268f9cceb37d77e4c1fc2059 3.0/rpms/gd-devel-2.0.33-7tr.i586.rpm d65cb3c4798099bce8756d9d4d9fa7a0 3.0/rpms/gd-utils-2.0.33-7tr.i586.rpm 5bebb862eb223b3a0eedfe16c82b2dc6 3.0/rpms/php-5.2.1-1tr.i586.rpm a67665031b21953bebc51dba1aeba03c 3.0/rpms/php-calendar-5.2.1-1tr.i586.rpm f0fcbc3e69f4e96d646fec7bdbbcf554 3.0/rpms/php-cli-5.2.1-1tr.i586.rpm a939afe84d1671cce2bb7155f7ac0ab0 3.0/rpms/php-curl-5.2.1-1tr.i586.rpm 445da66088168ff3563b49a55397c745 3.0/rpms/php-dba-5.2.1-1tr.i586.rpm 9d5dd6d54688e2549206712d45d04c99 3.0/rpms/php-devel-5.2.1-1tr.i586.rpm b5e735b2210a098d985422eec4899118 3.0/rpms/php-exif-5.2.1-1tr.i586.rpm 8bf72a390e67d8c4d21394ca8d8a3cbd 3.0/rpms/php-fcgi-5.2.1-1tr.i586.rpm 609c6aa553a37f58e61a7c255d0dad23 3.0/rpms/php-gd-5.2.1-1tr.i586.rpm 82e8b36e32d265d28362c0a2235a3a10 3.0/rpms/php-imap-5.2.1-1tr.i586.rpm ec211999cb0359a7f17b82ea1d723777 3.0/rpms/php-ldap-5.2.1-1tr.i586.rpm 00274cb74e84ac30187acc473d64c862 3.0/rpms/php-mcrypt-5.2.1-1tr.i586.rpm 05d63a12841a4446990840d6ea85ab57 3.0/rpms/php-mhash-5.2.1-1tr.i586.rpm af196d861f6b48ba18d8af54178e9cbf 3.0/rpms/php-mssql-5.2.1-1tr.i586.rpm 55cfb9816587f3f4af66649c3d5cf50d 3.0/rpms/php-mysql-5.2.1-1tr.i586.rpm db96d6839bbac310d143240f0e355106 3.0/rpms/php-mysqli-5.2.1-1tr.i586.rpm 7e769d14d711d0da14c407a24030dc6e 3.0/rpms/php-openssl-5.2.1-1tr.i586.rpm a4848dad7454d6731585fc29697ce641 3.0/rpms/php-pdo-mysql-5.2.1-1tr.i586.rpm 044c453773907443c0583e6100280052 3.0/rpms/php-pdo-sqlite-5.2.1-1tr.i586.rpm a50c2f8aa1954845026f693c4f5dddd1 3.0/rpms/php-pgsql-5.2.1-1tr.i586.rpm dc4811e93101cf4f67785aded0604282 3.0/rpms/php-pspell-5.2.1-1tr.i586.rpm 656c60c889a7c24af9aa8279f99683bd 3.0/rpms/php-snmp-5.2.1-1tr.i586.rpm 985487ad22973ee213428eb05a9a4e71 3.0/rpms/php-sqlite-5.2.1-1tr.i586.rpm 974ebe419202aad9e71e0b904ad9a1a7 3.0/rpms/php-xslt-5.2.1-1tr.i586.rpm dccc24c6390eb5f08be54191a8759f90 3.0/rpms/php-zlib-5.2.1-1tr.i586.rpm 90b55a1dde7b503a6347ce898774df1b 3.0/rpms/postgresql-8.0.12-1tr.i586.rpm dc976150bccad1c875003fe92e8df406 3.0/rpms/postgresql-contrib-8.0.12-1tr.i586.rpm 373435a876d99504c422eb22e918110b 3.0/rpms/postgresql-devel-8.0.12-1tr.i586.rpm b28a5463590f707c2f2fbb4ec56c7968 3.0/rpms/postgresql-docs-8.0.12-1tr.i586.rpm 052899e6bf3d4dbf05b919ece3f78cc6 3.0/rpms/postgresql-libs-8.0.12-1tr.i586.rpm b917d3a7500d092b603596b9322e2e50 3.0/rpms/postgresql-plperl-8.0.12-1tr.i586.rpm 7b978664feff21df4de290d04849de25 3.0/rpms/postgresql-python-8.0.12-1tr.i586.rpm 57eba62e91beb1f756604ba0903a798d 3.0/rpms/postgresql-server-8.0.12-1tr.i586.rpm 4a78a579acc27be07c605b53757f409d 3.0/rpms/postgresql-test-8.0.12-1tr.i586.rpm 98cf0c288eb646d46e45ea3786d69460 3.0/rpms/samba-3.0.24-1tr.i586.rpm 3b8d03e1c657944697f27dfd94083b54 3.0/rpms/samba-client-3.0.24-1tr.i586.rpm 58bdd6118bddbbe9962f4eddb28ff7c8 3.0/rpms/samba-common-3.0.24-1tr.i586.rpm 97ba37f6f890e39a44474a575c8009d1 3.0/rpms/samba-devel-3.0.24-1tr.i586.rpm 4871243701dbd75a994eb14eefb88c6b 3.0/rpms/samba-mysql-3.0.24-1tr.i586.rpm 2c2dd71f917ff909e1f562af4984a46e
2.2/rpms/fetchmail-6.2.5.5-2tr.i586.rpm Trustix Security Team 0 Talkback[s]
(click to add your comment)
|