Benchmark-Perl-Formance-Cargo
view release on metacpan or search on metacpan
share/SpamAssassin/easy_ham_2/01345.c40d5798193a4a060ec9f3d2321e37e4 view on Meta::CPAN
17:21:18 +0100
Received: from lists.securityfocus.com (lists.securityfocus.com
[66.38.151.19]) by outgoing.securityfocus.com (Postfix) with QMQP id
9D913A30D7; Tue, 6 Aug 2002 10:12:42 -0600 (MDT)
Mailing-List: contact linux-secnews-help@securityfocus.com; run by ezmlm
Precedence: bulk
List-Id: <linux-secnews.list-id.securityfocus.com>
List-Post: <mailto:linux-secnews@securityfocus.com>
List-Help: <mailto:linux-secnews-help@securityfocus.com>
List-Unsubscribe: <mailto:linux-secnews-unsubscribe@securityfocus.com>
List-Subscribe: <mailto:linux-secnews-subscribe@securityfocus.com>
Delivered-To: mailing list linux-secnews@securityfocus.com
Delivered-To: moderator for linux-secnews@securityfocus.com
Received: (qmail 14854 invoked from network); 6 Aug 2002 16:05:02 -0000
Date: Tue, 6 Aug 2002 10:03:52 -0600 (MDT)
From: John Boletta <jboletta@securityfocus.com>
To: linux-secnews@securityfocus.com
Subject: SecurityFocus Linux Newsletter #92
Message-Id: <Pine.LNX.4.43.0208061003200.9767-100000@mail.securityfocus.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
SecurityFocus Linux Newsletter #92
----------------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System
>>From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.
With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.
Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-lx.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Advanced Log Processing
2. Assessing Internet Security Risk, Part Three: an Internet...
3. Copyright, Security, and the Hollywood Hacking Bill
4. SecurityFocus DPP Program
II. LINUX VULNERABILITY SUMMARY
1. OpenSSL SSLv2 Malformed Client Key Remote Buffer Overflow...
2. Abyss Web Server HTTP GET Request Directory Contents Disclosure...
3. DotProject User Cookie Authentication Bypass Vulnerability
4. OpenSSL SSLv3 Session ID Buffer Overflow Vulnerability
5. phpBB2 Gender Mod Remote SQL Injection Vulnerability
6. ShoutBox Form Field HTML Injection Vulnerability
7. Sympoll File Disclosure Vulnerability
8. OpenSSL ASN.1 Parsing Error Denial Of Service Vulnerability
9. William Deich Super SysLog Format String Vulnerability
10. Frederic Tyndiuk Eupload Plain Text Password Storage...
11. Util-linux File Locking Race Condition Vulnerability
12. OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer...
13. OpenSSL ASCII Representation Of Integers Buffer Overflow...
14. ParaChat Phantom User Denial Of Service Vulnerability
15. OpenSSH Trojan Horse Vulnerability
16. Bharat Mediratta Gallery Remote File Include Vulnerability
17. John G. Myers MUnpack Malformed MIME Encoded Message Buffer...
18. Dispair Remote Command Execution Vulnerability
19. Mailreader Session Hijacking Vulnerability
20. John G. Myers MPack/MUnpack Malformed Filename Vulnerability
21. Fake Identd Client Query Remote Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. LDAP Auth? (Thread)
2. LDAP auth (Thread)
3. Administrivia: Gone Fishin' (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
1. Gateway Guardian
2. PakSecured Linux
3. Progressive Systems VPN
V. NEW TOOLS FOR LINUX PLATFORMS
1. Astaro Security Linux (Stable 3.x) v3.202
2. FCheck 2.07.59
3. The @stake Sleuth Kit (TASK) v1.50
VI. SPONSORSHIP INFORMATION
I. FRONT AND CENTER
-------------------
1. Advanced Log Processing
By Anton Chuvakin
Reading logs is a crucial part of incident detection and response.
However, it is easy for security personnel to be overwhelmed by the sheer
volume of logs. This article will offer a brief overview of log analysis,
particularly: log transmission, log collection and log analysis. It will
also briefly touch upon log storing and archival.
http://online.securityfocus.com/infocus/1613
2. Assessing Internet Security Risk, Part Three: an Internet Assessment
Methodology Continued
by Charl van der Walt
This article is the third in a series that is designed to help readers to
assess the risk that their Internet-connected systems are exposed to. In
the first installment, we established the reasons for doing a technical
risk assessment. In the second part, we started to discuss the methodology
that we follow in performing this kind of assessment. In this installment,
we will continue to discuss methodology, particularly visibility and
vulnerability scanning.
http://online.securityfocus.com/infocus/1612
3. Copyright, Security, and the Hollywood Hacking Bill
By Richard Forno
Proposed copyright enforcement legislation may allow the powerful
entertainment lobby to circumvent fundamental constitutional protections,
and may create chaos on the Internet.
share/SpamAssassin/easy_ham_2/01345.c40d5798193a4a060ec9f3d2321e37e4 view on Meta::CPAN
version 1.2.
Exploitation of this issue on Microsoft Windows operating systems may
potentially expose arbitrary system files since webservers typically run
in the SYSTEM context.
8. OpenSSL ASN.1 Parsing Error Denial Of Service Vulnerability
BugTraq ID: 5366
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5366
Summary:
OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.
A remotely exploitable denial of service condition has been reported in
the OpenSSL ASN.1 library.
This vulnerability is due to parsing errors and affects SSL, TLS, S/MIME,
PKCS#7 and certificate creation routines. In particular, malformed
certificate encodings could cause a denial of service to server and client
implementations which depend on OpenSSL.
Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.
** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.
9. William Deich Super SysLog Format String Vulnerability
BugTraq ID: 5367
Remote: No
Date Published: Jul 31 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5367
Summary:
super is an open source set-uid root utility that allows for a similar
functionality to that of the sudo utility. It is written for use on Linux
and Unix variant operating systems.
super is prone to a format string vulnerability. This problem is due to
incorrect use of the syslog() function to log error messages. It is
possible to corrupt memory by passing format strings through the
vulnerable logging function. This may potentially be exploited to
overwrite arbitrary locations in memory with attacker-specified values.
The vulnerability is a result of compiling super with syslog support. Due
to an error in the file, error.c, users that are not in the super
configuration file will still be able to execute code with root
privileges.
Successful exploitation of this issue may allow the attacker to execute
arbitrary instructions with root privileges.
10. Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
BugTraq ID: 5369
Remote: Yes
Date Published: Jul 31 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5369
Summary:
Frederic Tyndiuk Eupload is a small script designed to facilitate
uploading of files to a remote server. It is written in Perl and should
work with Microsoft Windows and Linux and Unix variant operating systems.
A problem with Eupload 1.0 may make it possible for remote attackers to
gain access to sensitive information.
Eupload does not cryptographically protect stored passwords. Passwords
contained in the configuration file, password.txt, are stored in plain
text. They may be read by simply viewing the file. The file, password.txt,
is stored in a web accessible location and is, itself, accessible for
retrieval. Thus it is trivial for an attacker to obtain user passwords and
abuse the Eupload service.
This problem could allow an attacker to gain access to the passwords to
protected resources.
11. Util-linux File Locking Race Condition Vulnerability
BugTraq ID: 5344
Remote: No
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5344
Summary:
The util-linux package is a set of commonly used system utilities such as
'chfn' and 'chsh'. It is included with many Linux distributions.
A race condition has been reported in code shared by the util-linux
utilities. The condition is related to file locking. Failure to check
for the existence of a lockfile prior to sensitive operations may, under
specific circumstances, open a window of opportunity for attack. The
util-linux utilities often write to sensitive files such as /etc/passwd/.
Attackers may exploit the condition to inject arbitrary data into these
files to elevate privileges.
The reported attacks are complex, time dependent and require specific
circumstances such as system administrator interaction and a large passwd
file.
Red Hat Linux is known to ship with util-linux as a core component.
Other distributions, those that are derived from Red Hat in particular,
may also be vulnerable.
It should be noted that the utilities included with the shadow-utils
package (shipped with SuSE Linux) are not vulnerable.
12. OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
BugTraq ID: 5361
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5361
Summary:
OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.
A vulnerability has been reported for OpenSSL 0.9.7 pre-release versions.
This vulnerability is present only when Kerberos is enabled for a system
using SSL version 3.
When initiatiating contact between a SSLv3 server, master keys are
exchanged between the client and the server. When an oversized master key
is supplied to a SSL version 3 server by a malicious client, it may cause
a buffer to overflow on the vulnerable system. As a result, stack memory
on the vulnerable server will become corrupted. This could enable the
attacker to take control of the SSLv3 server process and cause it to
execute malicious, attacker supplied code.
( run in 0.728 second using v1.01-cache-2.11-cpan-b16cb0d3907 )