Skip to content

customize
National Cyber Alert System
Cyber Security Bulletin SB05-124archive

Summary of Security Items from April 27 through May 3, 2005

Information in the US-CERT Cyber Security Bulletin is a compilation and includes information published by outside sources, so the information should not be considered the result of US-CERT analysis. Software vulnerabilities are categorized in the appropriate section reflecting the operating system on which the vulnerability was reported; however, this does not mean that the vulnerability only affects the operating system reported since this information is obtained from open-source information.

This bulletin provides a summary of new or updated vulnerabilities, exploits, trends, viruses, and trojans. Updates to vulnerabilities that appeared in previous bulletins are listed in bold text. The text in the Risk column appears in red for vulnerabilities ranking High. The risks levels applied to vulnerabilities in the Cyber Security Bulletin are based on how the "system" may be impacted. The Recent Exploit/Technique table contains a "Workaround or Patch Available" column that indicates whether a workaround or patch has been published for the vulnerability which the script exploits.


Vulnerabilities

The table below summarizes vulnerabilities that have been identified, even if they are not being exploited. Complete details about patches or workarounds are available from the source of the information or from the URL provided in the section. CVE numbers are listed where applicable. Vulnerabilities that affect both Windows and Unix Operating Systems are included in the Multiple Operating Systems section.

Note: All the information included in the following tables has been discussed in newsgroups and on web sites.

The Risk levels defined below are based on how the system may be impacted:

  • High - A high-risk vulnerability is defined as one that will allow an intruder to immediately gain privileged access (e.g., sysadmin or root) to the system or allow an intruder to execute code or alter arbitrary system files. An example of a high-risk vulnerability is one that allows an unauthorized user to send a sequence of instructions to a machine and the machine responds with a command prompt with administrator privileges.
  • Medium - A medium-risk vulnerability is defined as one that will allow an intruder immediate access to a system with less than privileged access. Such vulnerability will allow the intruder the opportunity to continue the attempt to gain privileged access. An example of medium-risk vulnerability is a server configuration error that allows an intruder to capture the password file.
  • Low - A low-risk vulnerability is defined as one that will provide information to an intruder that could lead to further compromise attempts or a Denial of Service (DoS) attack. It should be noted that while the DoS attack is deemed low from a threat potential, the frequency of this type of attack is very high. DoS attacks against mission-critical nodes are not included in this rating and any attack of this nature should instead be considered to be a "High" threat.

Windows Operating Systems Only

Vendor & Software Name
Vulnerability - Impact
Patches - Workarounds
Attacks Scripts
Common Name /
CVE Reference
Risk
Source

Adobe

Adobe Reader 7.0 and earlier

Adobe Acrobat 7.0 and earlier

The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote malicious users to determine the existence of arbitrary files via the LoadFile ActiveX method.

This is a separate issue from CAN-2005-1347.

Updates available: http://www.adobe.com/support/
techdocs/331465.html

Currently we are not aware of any exploits for this vulnerability.

Adobe Acrobat and Reader File Discovery

CAN-2005-0035

Low
Adobe Advisory, Document 331465, April 1, 2005

Adobe

Acrobat Reader 6.0 and prior

A vulnerability has been reported that could let a remote malicious user execute arbitrary code. If a specially crafted PDF file is loaded by Acrobat Reader it will trigger an Invalid-ID-Handle-Error in 'AcroRd32.exe'.

No workaround or patch available at time of publishing.

The vendor has been unable to reproduce this vulnerability. The original vulnerability reporter has refused to provide sufficient details to confirm the issue to either Security Tracker or the vendor. This is a separate issue from CAN-2005-0035.

Currently we are not aware of any exploits for this vulnerability.

Adobe Acrobat Reader Invalid-ID-Handle-Error Remote Code Execution

CAN-2005-1347

High

Security Tracker Alert, 1013774, April 21, 2005, Updated May 2, 2005

Altiris

Altiris Client Service for Windows version 6.1.393

A vulnerability has been reported that could let local malicious users bypass certain security restrictions. This is due to an error in ACLIENT.EXE that lets a user bypass the password restriction and gain access to the "Altiris Client Service Properties" window without supplying a valid password.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

Altiris Deployment Solution AClient Security Bypass
Medium
Security Focus, Bugtraq ID 13409, April 29, 2005

BulletProof Software

BulletProof FTP 2.4.0.31

A vulnerability has been reported that could let local malicious users gain escalated privileges. This is due to the application invoking the help functionality with SYSTEM privileges when configured to run as a service.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

BulletProof FTP Server Privilege Escalation

CAN-2005-1371

Medium
Secunia Advisory, SA15152, April 28, 2005

Cybration

ICUII 7.0

A vulnerability has been reported that could let a local malicious user obtain passwords. This is because the application password and instant messenger application passwords are stored in plain text format. The file may contain MSN, Yahoo, AIM, and ICQ user passwords.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

Cybration ICUII Password Disclosure

CAN-2005-1411

Medium
Security Focus Bugtraq ID: 13441, April 29, 2005

Ecommerce-Carts.com

Ecomm Professional Guestbook 3.x

An input validation vulnerability has been reported that could let a remote malicious user conduct SQL injection attacks.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Ecomm Professional Guestbook "AdminPWD" SQL Injection

CAN-2005-1412

High
Secunia Advisory, SA15190, April 29, 2005

enVivo!soft

enVivo!CMS

A vulnerability has been reported that could let a remote malicious user inject SQL commands to gain access to the application. The 'admin_login.asp' script does not properly validate user-supplied input in the 'username' and 'password' parameters.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

enVivo!soft enVivo!CMS SQL Injection and Privilege Escalation

CAN-2005-1413

High
Dcrab 's Security Advisory, April 29, 2005

ExoticSoft

FilePocket 1.2

A vulnerability has been reported that could let a local malicious user view passwords. Proxy passwords are stored in the Windows registry in plain text format.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

ExoticSoft FilePocket Password Disclosure

CAN-2005-1414

Medium
Security Tracker Alert, 1013823, April 28, 2005

GlobalSCAPE

Secure FTP Server 3.0.2

A buffer overflow vulnerability has been reported that could let a remote malicious user execute arbitrary code on the target system. The remote user can overwrite the EIP (and SEH) registers with an arbitrary address.

The vendor has reportedly issued a fix: http://www.cuteftp.com/gsftps/

Proofs of Concept exploit scripts have been published.

GlobalSCAPE Secure FTP Server Buffer Overflow Lets Remote Users Execute Arbitrary Code

CAN-2005-1415

High
Security Focus Bugtraq ID 13454, May 2, 2005

Intersoft International

NetTerm 4.x, 5.x

A vulnerability has been reported that could let local malicious users execute arbitrary code. This is due to a boundary error in the NetFtpd program which can cause a buffer overflow by passing an overly long argument to the "USER" FTP command when logging in.

The vendor has removed NetFtpd in NetTerm 5.1.1.1 and later.

Currently we are not aware of any exploits for this vulnerability.

Intersoft NetTerm Remote Code Execution

CAN-2005-1323

Misclassified as Multiple OS in SB05-117.

High
Secunia Advisory, SA15140 April 27, 2005

Kerio

Kerio WinRoute Firewall 6.0.10 and prior

Kerio MailServer 6.0.8 and prior

Kerio Personal Firewall 4.1.2 and prior

Two vulnerabilities have been reported that could let local users cause a Denial of Service and brute force passwords. Local users can exploit an error in the remote administration protocol to brute force passwords if the username is known. Local users can also exploit an error in the remote administration protocol to consume a large amount of CPU resources by continuously sending messages.

The following versions are fixed:
* Kerio WinRoute Firewall version 6.0.11 and later.
* Kerio MailServer version 6.0.9 and later.
* Kerio Personal Firewall version 4.1.3 and later.

Currently we are not aware of any exploits for these vulnerabilities.

Kerio Products Password Brute Force and Denial of Service

CAN-2005-1062
CAN-2005-1063

Medium

Secure Computer Group Document IDs ID: #20050429-1 and #20050429-2, April 29, 2005

 

MaxWebPortal

MaxWebPortal 1.30 - 1.33

A vulnerability exists that could let a remote malicious user inject SQL commands to gain administrative access. Multiple scripts do not properly validate user-supplied input: article_popular.asp, dl_popular.asp, links_popular.asp, pic_popular.asp, article_rate.asp, dl_rate.asp, links_rate.asp, pic_rates.asp, article_toprated.asp, dl_toprated.asp, links_toprated.asp, pic_toprated.asp.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

MaxWebPortal SQL Injection and Privilege Escalation

CAN-2005-1417

High
Security Focus Bugtraq ID 13466, May 2, 2005

Metalinks

MetaBid

Multiple vulnerabilities have been reported in MetaBid that could let remote malicious users conduct SQL injection attacks. This is due to input validation errors in the "intAuctionID" parameter in "item.asp" and the username and password fields in "logIn.asp."

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Metalinks MetaBid Three SQL Injection Vulnerabilities

CAN-2005-1364

High
Dcrab 's Security Advisory, April 27, 2005

NetLeaf Limited

NotJustBrowsing 1.0.3

A vulnerability has been reported that could let a local malicious user obtain an application password. This is because the three character 'View Lock Password' is stored in in plain text format.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

NetLeaf Limited NotJustBrowsing Discloses Application Password

CAN-2005-1418

Medium
Security Focus, Bugtraq ID 13442, April 29, 2005

Ocean12 Technologies

Ocean12 Mailing List Manager 1.06

An input validation vulnerability has been reported that could let a remote malicious user inject SQL commands. Input validation errors exist in the 'Admin_id' and 'Admin_password' fields.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Ocean12 Mailing List Manager Remote SQL Injection

CAN-2005-1419

High
Zinho's Security Advisory,
April 28, 2005

Raysoft

Video Cam Server 1.0.0

Several vulnerabilities have been reported that could let a remote malicious user obtain files from the target system, determine the installation path, and cause a Denial of Service. A remote user can obtain files located outside of the web document directory by supplying a special request, access an administration page to shutdown the camera or the web service, and request a non-existent page to determine the installation path.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Raysoft Video Cam Server Multiple Vulnerabilities

CAN-2005-1420
CAN-2005-1421
CAN-2005-1422

Low
Security Tracker Alert, 1013860, May 2, 2005

Skype

Skype for Windows 1.2.0.0 to 1.2.0.46

A vulnerability has been reported that could let local malicious users bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.

Upgrade to Skype for Windows version 1.2.0.47 or higher: http://www.skype.com/download/

Currently we are not aware of any exploits for this vulnerability.

Skype for Windows Security Bypass

CAN-2005-1407

Medium
Skype Security Advisory, SSA-2005-01, April 20

soft3304

04WebServer 1.81

A input validation vulnerability has been reported that could let remote malicious users gain knowledge of sensitive information. The contents of files and folders one folder outside the document root could be exposed.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

soft3304 04WebServer Directory Traversal

CAN-2005-1416

Low
Secunia Advisory, SA15230, May 3, 2005

Software602

602LAN SUITE 2004.0.05.0413

A vulnerability has been reported that could let remote users detect the presence of local files and cause a Denial of Service. No redirection occurs when accessing the "mail" script with the "A" parameter referencing a valid local file via directory traversal attacks.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Software602 602LAN SUITE Local File Detection and Denial of Service

CAN-2005-1423

Low
Secunia Advisory, SA15231, May 3, 2005
StorePortal

StorePortal 2.63

Multiple SQL injection vulnerabilities have been reported in the 'default.asp' script, which could let a remote malicious user execute arbitrary SQL code.

No workaround or patch available at time of publishing.

There is no exploit code required; however, Proofs of Concept exploits have been published.

StorePortal Multiple SQL Injection

CAN-2005-1293

High
Dcrab 's Security Advisory, April 25, 2005

StumbleInside

GoText 1.01

A vulnerability has been reported that could let a local malicious user view user configuration data. The software stores user information, including username, e-mail address, and phone number in the 'Program Files\GoText\GoText.bin' file.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

StumbleInside GoText Discloses Users Configuration Data

CAN-2005-1424

Low
Security Tracker Alert, 1013825, April 28, 2005

Symantec

Web Security 3.x

Norton SystemWorks 2005

Norton Internet Security 2005

Norton AntiVirus 2005

Mail Security for SMTP 4.x

Mail Security for Exchange 4.x

AntiVirus/Filtering for Domino 3.x

AntiVirus Scan Engine 4.x

 

A vulnerability has been reported that could let a remote malicious user bypass certain scanning functionality.This is due to an error in the Symantec Antivirus component when processing encoded or archived content. This can be exploited to crash the decomposer component when parsing a specially crafted RAR file.

Updates are available via LiveUpdate and from the vendor: http://www.symantec.com/techsupp/

Currently we are not aware of any exploits for this vulnerability.

Symantec AntiVirus Products RAR Archive Virus Detection Bypass

CAN-2005-1346

High
Symantec SYM05-007, April 27, 2005

Uapplication

Uguestbook
Ublog Reload
Uphotogallery

A vulnerability has been reported that could let a remote malicious user obtain the database, which includes the administrative password. A remote authenticated administrator can invoke the uphotogallery 'edit_image.asp' script to upload arbitrary files to the target system.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Uapplication Products Password Disclosure

CAN-2005-1425
CAN-2005-1426
CAN-2005-1427
CAN-2005-1428

Medium
Security Tracker Alert, 1013830, April 28, 2005

WWWguestbook 1.1

An input validation vulnerability has been reported that could let a remote malicious user inject SQL commands. The 'login.asp' script does not properly validate input to the 'password' parameter.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

WWWguestbook SQL Injection

CAN-2005-1429

High
Security Tracker Alert, 1013837, April 29, 2005

[back to top]

UNIX / Linux Operating Systems Only
Vendor & Software Name
Vulnerability - Impact
Patches - Workarounds
Attacks Scripts
Common Name /
CVE Reference
Risk
Source

Apple

Mac OS X 10.0-10.0.4, 10.1-10.1.5, 10.2-10.2.8, 10.3-10.3.9, Mac OS X Server 10.0-10.1.5, 10.2-10.2.8, 10.3-10.3.9

A vulnerability has been reported in the pseudo terminal system due to a design error, which could let a malicious user obtain sensitive information.

Version 10.4 of Apple Mac OS X reportedly fixes this vulnerability by implementing proper default permissions on the pseudo terminal API.

There is no exploit code required.

Apple Mac OS X Default Pseudo-Terminal Permission

CAN-2005-1430

Medium
Bugtraq, 397306, May 1, 2005

Apple

Safari 1.3

A Denial of Service vulnerability has been reported when processing HTTPS URLs due to insufficient bounds checking.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

Apple Safari Web Browser HTTPS Denial of Service

CAN-2005-1385

Low

Security Tracker Alert, 1013835, April 29, 2005

APSIS

Pound 1.8.2

A buffer overflow vulnerability has been reported in the 'add_port()' function due to a boundary error, which could let a remote malicious user cause a Denial of Service and possibly execute arbitrary code.

Upgrade available at:
http://www.apsis.ch/
pound/Pound-1.8.3.tgz

Currently we are not aware of any exploits for this vulnerability.

APSIS Pound Remote Buffer Overflow

CAN-2005-1391

Low/ High

(High if arbitrary code can be executed)

Security Focus, 13436, April 29, 2005

Carnegie Mellon University

Cyrus IMAP Server 2.x

 

Multiple vulnerabilities exist: a buffer overflow vulnerability exists in mailbox handling due to an off-by-one boundary error, which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exists in the imapd annotate extension due to an off-by-one boundary error, which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exists in 'fetchnews,' which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exist because remote administrative users can exploit the backend; and a buffer overflow vulnerability exists in imapd due to a boundary error, which could let a remote malicious user execute arbitrary code.

Update available at:
http://ftp.andrew.cmu.edu/pub/
cyrus/cyrus-imapd-2.2.11.tar.gz

Gentoo:
http://security.gentoo.org/
glsa/glsa-200502-29.xml

SUSE:
ftp://ftp.SUSE.com/pub/SUSE

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/c/cyrus21-imapd/

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

ALT Linux:
http://lists.altlinux.ru/pipermail/
security-announce/2005-March
/000287.html

OpenPKG:
ftp://ftp.openpkg.org/release/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Currently we are not aware of any exploits for these vulnerabilities.

Cyrus IMAP Server Multiple Remote Buffer Overflows

CAN-2005-0546

High

Secunia Advisory,
SA14383,
February 24, 2005

Gentoo Linux Security Advisory, GLSA 200502-29,
February 23, 2005

SUSE Security Announcement,
SUSE-SA:2005:009, February 24, 2005

Ubuntu Security
Notice USN-87-1,
February 28, 2005

Mandrakelinux
Security Update Advisory,
MDKSA-2005:051, March 4, 2005

Conectiva Linux Security
Announcement,
CLA-2005:937,
March 17, 2005

ALTLinux Security Advisory,
March 29, 2005

OpenPKG Security Advisory,
OpenPKG-SA-2005.005,
April 5, 2005

Fedora Update Notification,
FEDORA-2005-339, April 27, 2005

Cocktail

Cocktail 3.5.4

A vulnerability has been reported because the administrator password is passed insecurely, which could let a malicious user obtain sensitive information.

No workaround or patch available at time of publishing.

There is no exploit code required.

Cocktail Admin Password Disclosure

CAN-2005-1387

Medium
Securities, May 1, 2005

Debian

CVS 1.11.1 p1

Several vulnerabilities have been reported: a vulnerability was reported because it is possible to bypass the password protection using the pserver access method, which could let a remote malicious user bypass authentication to obtain unauthorized access; and a Denial of Service vulnerability was reported due to an error in Debian's CVS cvs-repouid patch.

Debian:
http://security.debian.org/
pool/updates/main/c/cvs/

Currently we are not aware of any exploits for these vulnerabilities.

Debian CVS-Repouid Remote Authentication Bypass & Denial of Service

CAN-2004-1342
CAN-2004-1343

Medium
Debian Security Advisory, DSA 715-1, April 27, 2005

ESRI

ArcInfo Workstation on UNIX 9.0

Several vulnerabilities have been reported: a format string vulnerability was reported in the 'lockmgr' and 'wservice' applications, which could let a malicious user execute arbitrary code with root privileges; and a buffer overflow vulnerability was reported in the 'asmaster,' 'asrecovery,' 'asuser,' 'asutulity,' and 'se' applications due to command line argument boundary errors, which could let a malicious user execute arbitrary code with root privileges.

Patch available at:
http://support.esri.com/index.cfm?fa=
downloads.patchesServicePacks.
viewPatch&PID=14&MetaID=1015

Proof of Concept exploits have been published. An exploit script has also been published for the format string vulnerability.

ESRI ArcInfo Workstation s Buffer Overflows and Format String

CAN-2005-1393
CAN-2005-1394

High
Secunia Advisory,
SA15196, May 2, 2005

GNU

sharutils 4.2, 4.2.1

Multiple buffer overflow vulnerabilities exists due to a failure to verify the length of user-supplied strings prior to copying them into finite process buffers, which could let a remote malicious user cause a Denial of Service or execute arbitrary code.

Gentoo:
http://security.gentoo.org/
glsa/glsa-200410-01.xml

FedoraLegacy:
http://download.fedoralegacy.
org/fedora/

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/s/sharutils/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

OpenPKG:
ftp://ftp.openpkg.org/release

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-377.html

Trustix:
ftp://ftp.turbolinux.co.jp/
pub/TurboLinux/TurboLinux/ia32/

We are not aware of any exploits for these vulnerabilities.

GNU Sharutils Multiple Buffer Overflow

CAN-2004-1773

Low/ High

(High if arbitrary code can be executed)

Gentoo Linux
Security Advisory, GLSA 200410-01, October 1, 2004

Fedora Legacy
Update Advisory, FLSA:2155,
March 24, 2005

Ubuntu Security
Notice, USN-102-1 March 29, 2005

Fedora Update Notifications,
FEDORA-2005-
280 & 281, April 1, 2005

Mandrakelinux Security Update Advisory, MDKSA-2005:067, April 7, 2005

RedHat Security Advisory, RHSA-2005:377-07, April 26, 2005

Turbolinux Security Advisory, TLSA-2005-54, April 28, 2005

GNU

sharutils 4.2, 4.2.1

A vulnerability has been reported in the 'unshar' utility due to the insecure creation of temporary files, which could let a malicious user create/overwrite arbitrary files.

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/s/sharutils/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-06.xml

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-377.html

Trustix:
ftp://ftp.turbolinux.co.jp/
pub/TurboLinux/TurboLinux/ia32/

There is no exploit code required.

GNU Sharutils 'Unshar' Insecure Temporary File Creation

CAN-2005-0990

Medium

Ubuntu Security
Notice, USN-104-1, April 4, 2005

Gentoo Linux Security Advisory, GLSA 200504-06, April 6, 2005

Mandrakelinux Security Update Advisory, MDKSA-2005:067, April 7, 2005

Fedora Update Notification,
FEDORA-2005-319, April 14, 2005

RedHat Security Advisory, RHSA-2005:377-07, April 26, 2005

Turbolinux Security Advisory, TLSA-2005-54, April 28, 2005

GNU

Lysator LSH 1.5-1.5.5, 2.0

A remote Denial of Service vulnerability has been reported due to an unspecified error.

Upgrades available at:
http://www.lysator.liu.se/~nisse/
archive/

Patch available at:
ftp://ftp.lysator.liu.se/pub/security/
lsh/lsh-2.0-2.0.1.diff.gz

Debian:
http://security.debian.org/
pool/updates/main/l/lsh-utils/

Currently we are not aware of any exploits for this vulnerability.

Lysator LSH Remote Denial of Service

CAN-2005-0814

Low

Secunia Advisory,
SA14609, March 17, 2005

Debian Security Advisory, DSA 717-1, April 27, 2005

GnuTLS

GnuTLS 1.2 prior to 1.2.3; 1.0 prior to 1.0.25

A remote Denial of Service vulnerability has been reported due to insufficient validation of padding bytes in 'lib/gnutils_cipher.c.'

Updates available at:
http://www.gnu.org/software/
gnutls/download.html

Currently we are not aware of any exploits for this vulnerability.

GnuTLS Padding Validation Remote Denial of Service

CAN-2005-1431

Low
Security Tracker Alert, 1013861, May 2, 2005

Hewlett Packard Company

OpenView Event Correlation Services 3.32, 3.33

Several vulnerabilities have been reported due to unspecified errors, which could let a malicious user cause a Denial of Service or execute arbitrary code.

Patches available at:
http://h20000.www2.hp.com/bizsupport/
TechSupport/Document.jsp?objectID=
PSD_HPSBMA01141

Currently we are not aware of any exploits for these vulnerabilities.

HP OpenView Event Correlation Services

CAN-2005-1433

Low/ High

(High if arbitrary code can be executed)

HP Security Bulletin,
HPSBMA01141, May 2, 2005

 

Hewlett Packard Company

OpenView Network Node Manager 6.2, 6.4, 7.01, 7.50

Several vulnerabilities have been reported due to unspecified errors, which could let a malicious user cause a Denial of Service or execute arbitrary code.

Patches available at:
http://h20000.www2.hp.com/bizsupport/
TechSupport/Document.jsp?objectID=
PSD_HPSBMA01140

Currently we are not aware of any exploits for these vulnerabilities.

HP OpenView Network Node Manager

CAN-2005-1434

Low/ High

(High if arbitrary code can be executed)

HP Security Bulletin,
HPSBMA01140, May 2, 2005

Info-ZIP

Zip 2.3; Avaya CVLAN, Intuity LX, MN100, Modular Messaging (MSS) 1.1, 2.0, Network Routing

A buffer overflow vulnerability exists due to a boundary error when doing recursive compression of directories with 'zip,' which could let a remote malicious user execute arbitrary code.

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/z/zip/

Fedora:
http://download.fedora.redhat.com/pub
/fedora/linux/core/updates/

Gentoo:
http://security.gentoo.org/glsa/
glsa-200411-16.xml

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

SUSE:
ftp://ftp.SUSE.com/pub/SUSE

Red Hat:
http://rhn.redhat.com/errata/
RHSA-2004-634.html

Debian:
http://www.debian.org/
security/2005/dsa-624

TurboLinux:
ftp://ftp.turbolinux.co.jp/pub/
TurboLinux/TurboLinux/ia32/

Avaya:
http://support.avaya.com/elmodocs2/
security/ASA-2005-019_RHSA-2004-634.pdf

Fedora Legacy:
http://download.fedoralegacy.org/
redhat/

http://download.fedoralegacy.org
/fedora/1/updates/

Slackware:
ftp://ftp.slackware.com/
pub/slackware/

Currently we are not aware of any exploits for this vulnerability.

 

Info-ZIP Zip Remote Recursive Directory Compression Buffer Overflow

CAN-2004-1010

High

Bugtraq, November 3, 2004

Ubuntu Security Notice, USN-18-1, November 5, 2004

Fedora Update Notification,
FEDORA-2004-399 & FEDORA-2004-400, November 8 & 9, 2004

Gentoo Linux Security Advisory, GLSA 200411-16, November 9, 2004

Mandrakelinux Security Update Advisory, MDKSA-2004:141, November 26, 2004

SUSE Security Summary Report, SUSE-SR:2004:003, December 7, 2004

Red Hat Advisory, RHSA-2004:634-08, December 16, 2004

Debian DSA-624-1, January 5, 2005

Turbolinux Security Announcement, 20050131, January 31, 2005

Avaya Security Advisory, ASA-2005-019, January 25, 200

Fedora Legacy Update Advisory, FLSA:2255, February 1, 2005

Slackware Security Advisory, SSA:2005-121-01, May 2, 2005

 

Joshua Chamas

Crypt::SSLeay 0.51

A vulnerability has been reported because a file is employed from a world writable location for its fallback entropy source, which could lead to weak cryptographic operations.

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/libn/libnet-ssleay-perl/

There is no exploit code required.

Joshua Chamas Crypt::SSLeay Perl Module Insecure Entropy Source

CAN-2005-0106

Medium
Ubuntu Security Notice, USN-113-1, May 03, 2005

Kalum Somaratna

ProZilla Download Accelerator 1.0 x, 1.3.0-1.3.4, 1.3.5 .2, 1.3.5 .1, 1.3.5-1.3.5.2 1.3.6

A vulnerability exists due to improper implementation of a formatted string function when handling initial server responses, which could let a remote malicious user execute arbitrary code.

Debian:
http://security.debian.org/pool/
updates/main/p/prozilla/p

An exploit script has been published.

ProZilla Initial Server Response Format String

CAN-2005-0523

High

Security Focus, 12635, February 23, 2005

Debian Security Advisory, DSA 719-1, April 28, 2005

KDE

KDE 3.2-3.2.3, 3.3-3.3.2, 3.4,
KDE Quanta 3.1

A vulnerability has been reported due to a design error in Kommander, which could let a remote malicious user execute arbitrary code.

Patches available at:
ftp://ftp.kde.org/pub/kde/
security_patches/f

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-23.xml

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Currently we are not aware of any exploits for this vulnerability.

KDE Kommander Remote Arbitrary
Code Execution

CAN-2005-0754

High

KDE Security Advisory, April 20, 2005

Gentoo Linux Security Advisory, GLSA 200504-23, April 22, 200

Fedora Update Notification
FEDORA-2005-345, April 28, 2005

LBL

tcpdump 3.4 a6, 3.4, 3.5, alpha, 3.5.2, 3.6.2, 3.6.3, 3.7-3.7.2, 3.8.1 -3.8.3

Remote Denials of Service vulnerabilities have been reported due to the way tcpdump decodes Border Gateway Protocol (BGP) packets, Label Distribution Protocol (LDP) datagrams, Resource ReSerVation Protocol (RSVP) packets, and Intermediate System to Intermediate System (ISIS) packets.

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Exploit scripts have been published.

LBL TCPDump Remote Denials of Service

CAN-2005-1278
CAN-2005-1279

CAN-2005-1280

Low

Bugtraq, 396932, April 26, 2005

Fedora Update Notification,
FEDORA-2005-351, May 3, 2005

Linux kernel 2.6.11 .7

A Denial of Service vulnerability has been reported due to the creation of an insecure file by the kernel it87 and via686a drivers.

Patch available at:
http://kernel.org/pub/linux/
kernel/v2.6/patch-2.6.11.8.bz2

There is no exploit code required.

Linux Kernel it87 & via686a Drivers Denial of Service

CAN-2005-1369

Low
Secunia Advisory,
SA15204, May 2, 2005

MandrakeSoft

lam-runtime-7.0.6-2mdk

A vulnerability has been reported in the LAM/MPI Runtime environment due to the creation of an insecure account, which could let a local/remote malicious user obtain unauthorized access.

No workaround or patch available at time of publishing.

There is no exploit code required.

MandrakeSoft LAM/MPI Runtime Insecure Account Creation

CAN-2005-1379

Medium
Bugtraq, 397157, April 28, 2005

Marc Lehmann

Convert-UUlib 1.50

A buffer overflow vulnerability has been reported in the Convert::UUlib module for Perl due to a boundary error, which could let a remote malicious user execute arbitrary code.

Update available at:
http://search.cpan.org/
dist/Convert-UUlib/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-26.xml

Currently we are not aware of any exploits for this vulnerability.

Convert-UUlib Perl Module Buffer Overflow

CAN-2005-1349

High

Gentoo Linux Security Advisory, GLSA 200504-26, April 26, 2005

Secunia Advisory, SA15130, April 27,2 005

mtp-target.org

Mtp-Target for Windows 1.2.2 & prior, Mtp-Target for Linux 1.2.2 & prior

Several vulnerabilities have been reported: a format string vulnerability has been reported in the client code when messages from other users are displayed, which could let a remote malicious user execute arbitrary code; and a remote Denial of Service vulnerability has been reported due to a negative integer overflow from the NeL library.

No workaround or patch available at time of publishing.

A Proof of Concept exploit script has been published.

Mtp Target Format String and Denial of Service

CAN-2005-1401
CAN-2005-1402

Low/ High

(High if arbitrary code can be executed)

Securiteam, May 2, 2005

Multiple Vendors

ImageMagick 6.0-6.0.8, 6.1-6.1.8, 6.2 .0.7, 6.2 .0.4, 6.2, 6.2.1

A buffer overflow vulnerability has been reported due to a failure to properly validate user-supplied string lengths before copying into static process buffers, which could let a remote malicious user cause a Denial of Service.

Upgrades available at:
http://www.imagemagick.org/
script/binary-releases.php

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

A Proof of Concept exploit has been published.

ImageMagick
Remote Buffer Overflow

CAN-2005-1275

Low

Security Focus, 13351, April 25, 2005

Fedora Update Notification
FEDORA-2005-344, April 28, 2005

Multiple Vendors

KDE 2.0, beta, 2.0.1, 2.1-2.1.2, 2.2-2.2.2, 3.0-3.0.5, 3.1-3.1.5, 3.2-3.2.3, 3.3-3.3.2, 3.4; Novell Linux Desktop 9; SuSE E. Linux 9.1, x86_64, 9.2, x86_64, 9.3, Linux Enterprise Server 9

A buffer overflow vulnerability has been reported in the 'kimgio' image library due to insufficient validation of PCX image data, which could let a remote malicious user cause a Denial of Service or possibly execute arbitrary code.

Patches available at:
http://bugs.kde.org/attachment.cgi
?id=10325&action=view

http://bugs.kde.org/attachment.cgi
?id=10326&action=view

SuSE:
ftp://ftp.suse.com/pub/suse/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-22.xml

Debian:
http://security.debian.org/
pool/updates/main/k/kdelibs/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Denial of Service Proofs of Concept exploits have been published.

KDE 'kimgio'
image library
Remote Buffer Overflow

CAN-2005-1046

Low/ High

(High if arbitrary code can be executed)

SUSE Security Announcement, SUSE-SA:2005:022, April 11, 2005

Gentoo Linux Security Advisory, GLSA 200504-22, April 22, 2005

Debian Security Advisory, DSA 714-1, April 26, 2005

Fedora Update Notification,
FEDORA-2005-350, May 2, 2005

Multiple Vendors

Larry Wall Perl 5.0 05_003, 5.0 05, 5.0 04_05, 5.0 04_04, 5.0 04, 5.0 03, 5.6, 5.6.1, 5.8, 5.8.1, 5.8.3, 5.8.4 -5, 5.8.4 -4, 5.8.4 -3, 5.8.4 -2.3, 5.8.4 -2, 5.8.4 -1, 5.8.4, 5.8.5, 5.8.6

A vulnerability has been reported in the 'rmtree()' function in the 'File::Path.pm' module when handling directory permissions while cleaning up directories, which could let a malicious user obtain elevated privileges.

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/universe/p/perl/

Gentoo:
http://security.gentoo.org/glsa/
glsa-200501-38.xml

Debian:
http://security.debian.org/pool
/updates/main/p/perl/

TurboLinux:
ftp://ftp.turbolinux.co.jp/pub/
TurboLinux/TurboLinux/ia32/

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

Currently we are not aware of any exploits for this vulnerability.

Perl 'rmtree()' Function Elevated Privileges

CAN-2005-0448

Medium

Ubuntu Security Notice, USN-94-1 March 09, 2005

Gentoo Linux Security Advisory [UPDATE], GLSA 200501-38:03, March 15, 2005

Debian Security Advisory, DSA 696-1 , March 22, 2005

Turbolinux Security Advisory, TLSA-2005-45, April 19, 2005

Mandriva Linux Security Update Advisory, MDKSA-2005:079, April 29, 2005

Multiple Vendors

Linux kernel 2.4 .0-test1-test12, 2.4-2.4.29, 2.6, 2.6-test1-test11, 2.6.1-2.6.11

Multiple vulnerabilities have been reported in the ISO9660 handling routines, which could let a malicious user execute arbitrary code.

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/l/linux-source-2.6.8.1/

Fedora:
http://download.fedora.
redhat.com/pub/fedora/l
inux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

Currently we are not aware of any exploits for these vulnerabilities.

Linux Kernel
Multiple ISO9660 Filesystem
Handling
Vulnerabilities

CAN-2005-0815

High

Security Focus,
12837,
March 18, 2005

Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005

Ubuntu Security Notice, USN-103-1, April 1, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

Multiple Vendors

Perl

A race condition vulnerability was reported in the 'File::Path::rmtree()' function. A remote user may be able to obtain potentially sensitive information. A remote user may be able to obtain potentially sensitive information or modify files.

The vendor has released Perl version 5.8.4-5 to address this vulnerability. Customers are advised to contact the vendor for information regarding update availability.

Debian:
http://security.debian.org/pool/
updates/main/p/perl/

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/p/perl/

OpenPKG:
ftp://ftp.openpkg.org/release/
2.1/UPD/perl-5.8.4-2.1.1.src.rpm

Gentoo:
http://security.gentoo.org/
glsa/glsa-200501-38.xml

Mandrake:
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2005:031

SUSE:
ftp://ftp.suse.com/pub/suse/

Gentoo:
http://security.gentoo.org
/glsa/glsa-200501-38.xml

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Currently we are not aware of any exploits for this vulnerability.

Multiple Vendors Perl File::Path::rmtree() Permission
Modification
Vulnerability

CAN-2004-0452

Medium

Ubuntu Security Notice, USN-44-1, December 21, 2004

Debian Security Advisory, DSA 620-1, December 30, 2004

OpenPKG Security Advisory, OpenPKG-SA-2005.001, January 11, 2005

Gentoo Linux Security Advisory, GLSA 200501-38, January 26, 2005

MandrakeSoft Security Advisory, MDKSA-2005:031, February 8, 2005

SUSE Security Summary Report, SUSE-SR:2005:004, February 11, 2005

Gentoo Linux Security Advisory [UPDATE], GLSA 200501-38:03, March 15, 2005

Fedora Update Notification,
FEDORA-2005-353, May 2, 2005

Multiple Vendors

Squid Web Proxy Cache 2.5 .STABLE9, .STABLE8, .STABLE7

A vulnerability exists when using the Netscape Set-Cookie recommendations for handling cookies in caches due to a race condition, which could let a malicious user obtain sensitive information.

Patches available at:
http://www.squid-cache.org/Versions
/v2/2.5/bugs/squid-2.5.STABLE9-setcookie.patch

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/s/squid/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

Conectiva:
ftp://atualizacoes.
conectiva.com.br/

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

There is no exploit code required.

Squid Proxy Set-Cookie Headers Information Disclosure

CAN-2005-0626

Medium

Secunia Advisory, SA14451,
March 3, 2005

Ubuntu Security
Notice,
USN-93-1
March 08, 2005

Fedora Update Notifications,
FEDORA-2005-
275 & 276,
March 30, 2005

Conectiva Linux Security Announcement, CLA-2005:948, April 27, 2005

Mandriva Linux Security Update Advisory, MDKSA-2005:078, April 29, 2005

Multiple Vendors

Concurrent Versions System (CVS) 1.x;Gentoo Linux; SuSE Linux 8.2, 9.0, 9.1, x86_64, 9.2, x86_64, 9.3, Linux Enterprise Server 9, 8, Open-Enterprise-Server 9.0, School-Server 1.0, SUSE CORE 9 for x86, UnitedLinux 1.0

Multiple vulnerabilities have been reported: a buffer overflow vulnerability was reported due to an unspecified boundary error, which could let a remote malicious user potentially execute arbitrary code; a remote Denial of Service vulnerability was reported due to memory leaks and NULL pointer dereferences; an unspecified error was reported due to an arbitrary free (the impact was not specified), and several errors were reported in the contributed Perl scripts, which could let a remote malicious user execute arbitrary code.

Update available at:
https://ccvs.cvshome.org/
servlets/ProjectDocumentList

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-16.xml

SuSE:
ftp://ftp.suse.com/pub/suse/i

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

Trustix:
http://http.trustix.org/pub/
trustix/updates/

FreeBSD:
ftp://ftp.FreeBSD.org/pub/

Peachtree:
http://peachtree.burdell.org/
updates/

RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-387.html

OpenBSD:
http://www.openbsd.org/
errata.html#cvs

TurboLinux:
ftp://ftp.turbolinux.co.jp/p
ub/TurboLinux/TurboLinux/ia32/

Currently we are not aware of any exploits for these vulnerabilities.

CVS Multiple Vulnerabilities

CAN-2005-0753

Low/ High

(High if arbitrary code can be executed)

Gentoo Linux Security Advisory, GLSA 200504-16, April 18, 2005

SuSE Security Announcement, SUSE-SA:2005:024, April 18, 2005

Secunia Advisory, SA14976, April 19, 2005

Fedora Update Notification,
FEDORA-2005-330, April 20, 2006

Mandriva Linux Security Update Advisory, MDKSA-2005:073, April 21, 2005

Trustix Secure Linux Security Advisory, TSLSA-2005-0013, April 21, 2005

Gentoo Linux Security Advisory [UPDATE], GLSA 200504-16:02, April 22, 2005

FreeBSD Security Advisory, FreeBSD-SA-05:05, April 22, 2005

Peachtree Linux Security Notice, PLSN-0005, April 22, 2005

RedHat Security Advisory, RHSA-2005:387-06, April 25, 2005

Turbolinux Security Advisory, TLSA-2005-51, April 28, 2005

Multiple Vendors

Larry Wall Perl 5.8, 5.8.1, 5.8.3, 5.8.4, 5.8.4 -1-5.8.4-5; Ubuntu Linux 4.1 ppc, ia64, ia32

 

Multiple vulnerabilities exist: a buffer overflow vulnerability exists in the 'PERLIO_DEBUG' SuidPerl environment variable, which could let a malicious user execute arbitrary code; and a vulnerability exists due to an error when handling debug message output, which could let a malicious user corrupt arbitrary files.

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/universe/p/perl/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200502-13.xml

Mandrake:
http://www.mandrakesoft.com/security/
advisories?name=MDKSA-2005:031

RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-105.html

SGI:
ftp://oss.sgi.com/projects/
sgi_propack/download/3/updates/

SUSE:
ftp://ftp.suse.com/pub/suse/

Trustix:
http://www.trustix.org/errata/2005/0003/

IBM:
ftp://aix.software.ibm.com/
aix/efixes/security/perl58x.tar.Z

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/3/

Proofs of Concept exploits have been published.

Perl SuidPerl Multiple Vulnerabilities

CAN-2005-0155
CAN-2005-0156

Medium/ High

(High if arbitrary code can be executed)

Ubuntu Security Notice, USN-72-1, February 2, 2005

MandrakeSoft Security Advisory, MDKSA-2005:031, February 9, 2005

RedHat Security Advisory, RHSA-2005:105-11, February 7, 2005

SGI Security Advisory, 20050202-01-U, February 9, 2005

SUSE Security Summary Report, SUSE-SR:2005:004, February 11, 2005

Gentoo Linux Security Advisory, GLSA 200502-13, February 11, 2005

Trustix Secure Linux Security Advisory, TSLSA-2005-0003,February 11, 2005

IBM SECURITY ADVISORY, February 28, 2005

Fedora Update Notification,
FEDORA-2005-353, May 2, 2005

Multiple Vendors

Linux kernel 2.4-2.4.29, 2.6 .10, 2.6-2.6.11

A vulnerability has been reported in the 'bluez_sock_create()' function when a negative integer value is submitted, which could let a malicious user execute arbitrary code with root privileges.

Patches available at:
http://www.kernel.org/pub/linux/
kernel/v2.4/testing/patch-
2.4.30-rc3.bz2

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

SUSE:
ftp://ftp.SUSE.com/pub/SUSE

Trustix:
http://http.trustix.org/pub/
trustix/updates/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-283.html

http://rhn.redhat.com/
errata/RHSA-2005-284.html

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

A Proof of Concept exploit script has been published.

Linux Kernel
Bluetooth Signed Buffer Index

CAN-2005-0750

High

Security Tracker
Alert, 1013567,
March 27, 2005

SUSE Security Announcement, SUSE-SA:2005
:021, April 4, 2005

Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005

US-CERT
VU#685461

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

RedHat Security Advisories, RHSA-2005:283-15 & RHSA-2005:284-11, April 28, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

Multiple Vendors

Linux kernel 2.4-2.4.30

 

A Denial of Service vulnerability has been reported due to a failure to handle system calls that contain missing arguments.

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-293.html

http://rhn.redhat.com/
errata/RHSA-2005-284.html

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel Itanium System Call Denial of Service

CAN-2005-0137

Low
RedHat Security Advisories, RHSA-2005:284-11 & RHSA-2005:293-16, April 22 & 28, 2005

Multiple Vendors

Linux Kernel 2.6.10, 2.6 -test1-test11, 2.6-2.6.11

A Denial of Service vulnerability has been reported in the 'load_elf_library' function.

Patches available at:
http://www.kernel.org/pub/
linux/kernel/v2.6/patch-2.6.11.6.bz2

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/

Trustix:
http://http.trustix.org/pub/
trustix/updates/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel Local Denial of Service

CAN-2005-0749

Low

Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005

Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

Multiple Vendors

Linux kernel 2.6.10, 2.6 -test9-CVS, 2.6 -test1-test11, 2.6, 2.6.1 rc1&rc2, 2.6.1-2.6.8

A remote Denial of Service vulnerability has been reported in the Point-to-Point Protocol (PPP) Driver.

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1/

Trustix:
http://http.trustix.org/pub/
trustix/updates

SUSE:
ftp://ftp.SUSE.com/pub/SUSE

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/

ALTLinux:
http://lists.altlinux.ru/
pipermail/security-announce/
2005-March/000287.html

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-283.html

http://rhn.redhat.com/
errata/RHSA-2005-284.html

Conectiva:
ftp://atualizacoes.
conectiva.com.br/

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel PPP Driver Remote
Denial of Service

CAN-2005-0384

Low

Ubuntu Security Notice, USN-95-1 March 15, 2005

Trustix Secure Linux Security Advisory, TSL-2005-0009, March 21, 2005

SUSE Security Announcement, SUSE-SA:2005:018, March 24, 2005

Fedora Security Update Notification,
FEDORA-2005-262, March 28, 2005

ALTLinux Security Advisory, March 29, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

RedHat Security Advisories, RHSA-2005:283-15 & RHSA-2005:284-11, April 28, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

Multiple Vendors

Linux kernel 2.6.10, 2.6 -test9-CVS, 2.6-test1- -test11, 2.6, 2.6.1-2.6.11 ; RedHat Desktop 4.0, Enterprise Linux WS 4, ES 4, AS 4

Multiple vulnerabilities exist: a vulnerability exists in the 'shmctl' function, which could let a malicious user obtain sensitive information; a Denial of Service vulnerability exists in 'nls_ascii.c' due to the use of incorrect table sizes; a race condition vulnerability exists in the 'setsid()' function; and a vulnerability exists in the OUTS instruction on the AMD64 and Intel EM64T architecture, which could let a malicious user obtain elevated privileges.

RedHat:
https://rhn.redhat.com/errata/
RHSA-2005-092.html

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1/

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

SUSE:
ftp://ftp.SUSE.com/pub/SUSE

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/

Conectiva:
ftp://atualizacoes.conectiva.
com.br/10/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-283.html

http://rhn.redhat.com/
errata/RHSA-2005-284.html

Currently we are not aware of any exploits for these vulnerabilities.

Linux Kernel
Multiple
Vulnerabilities

CAN-2005-0176
CAN-2005-0177
CAN-2005-0178
CAN-2005-0204

Low/ Medium

(Low if a DoS)

Ubuntu Security
Notice, USN-82-1, February 15, 2005

RedHat Security Advisory,
RHSA-2005:092-14, February 18, 2005

SUSE Security Announcement,
SUSE-SA:2005:018, March 24, 2005

Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005

Conectiva Linux Security Announcement,
CLA-2005:945,
March 31, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

RedHat Security Advisories, RHSA-2005:283-15 & RHSA-2005:284-11, April 28, 2005

Multiple Vendors

Linux kernel 2.6.10, 2.6, -test1-test 11, 2.6.1- 2.6.11;
RedHat Fedora Core2

A vulnerability has been reported in the EXT2 filesystem handling code, which could let malicious user obtain sensitive information.

Patches available at:
http://www.kernel.org/pub/linux/
kernel/v2.6/patch-2.6.11.6.bz2

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/

Trustix:
http://http.trustix.org/pub/
trustix/updates/

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel
EXT2 File
System
Information Leak

CAN-2005-0400

Medium

Security Focus,
12932,
March 29, 2005

Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

 

Multiple Vendors

Linux kernel 2.6.10, 2.6, -test9-CVS, -test1-test11, 2.6.1-2.6.9;
RedHat Desktop 4.0, Enterprise Linux WS 4, ES 4, AS 4

A Denial of Service vulnerability has been reported in the 'Unw_Unwind_To_User' function.

RedHat;
http://rhn.redhat.com/
errata/RHSA-2005-366.html

http://rhn.redhat.com/
errata/RHSA-2005-293.html

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-284.html

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel Unw_Unwind_
To_User
Denial of Service

CAN-2005-0135

Low

RedHat Security Advisory, RHSA-2005:366-19 & RHSA-2005-2935 , April 19 & 22, 2005

RedHat Security Advisory, RHSA-2005:284-11, April 28, 2005

Multiple Vendors

Linux kernel 2.6-2.6.11

A vulnerability has been reported in 'SYS_EPoll_Wait' due to a failure to properly handle user-supplied size values, which could let a malicious user obtain elevated privileges.

Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-366.html

Conectiva:
ftp://atualizacoes.conectiva.
com.br/

An exploit script has been published.

Linux Kernel SYS_EPoll_Wait Elevated
Privileges

CAN-2005-0736

Medium

Security Focus, 12763, March 8, 2005

Ubuntu Security Notice, USN-95-1 March 15, 2005

Security Focus, 12763, March 22, 2005

Fedora Security Update Notification,
FEDORA-2005-262, March 28, 2005

Fedora Update Notification
FEDORA-2005-313, April 11, 2005

RedHat Security Advisory, RHSA-2005:366-19, April 19, 2005

Conectiva Linux Security Announcement, CLA-2005:952, May 2, 2005

Multiple Vendors

RedHat Fedora Core3, Core2;
Rob Flynn Gaim 1.2; Peachtree Linux release 1

A remote Denial of Service vulnerability has been reported when an unspecified Jabber file transfer request is handled.

Upgrade available at:
http://gaim.sourceforge.net/
downloads.php

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-05.xml

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-365.html

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

SGI:
http://www.sgi.com/support/
security/

Peachtree:
http://peachtree.burdell.org/
updates/

Conectiva:
ftp://atualizacoes.
conectiva.com.br/

There is no exploit code required.

Gaim Jabber File Request Remote Denial of Service

CAN-2005-0967

 

Low

Fedora Update Notifications,
FEDORA-2005-
298 & 299,
April 5, 2005

Gentoo Linux Security Advisory, GLSA 200504-05, April 06, 2005

RedHat Security Advisory, RHSA-2005:365-06, April 12, 2005

Mandriva Linux Security Update Advisory, MDKSA-2005:071, April 14, 2005

SGI Security Advisory, 20050404-01-U, April 20, 2005

Peachtree Linux Security Notice, PLSN-0001, April 21, 2005

Conectiva Linux Security Announcement, CLA-2005:949, April 27, 2005

Multiple Vendors

RedHat Fedora Core3, Core2;
Rob Flynn Gaim 1.2; Ubuntu Linux 4.1 ppc, ia64, ia32; Peachtree Linux release 1

Two vulnerabilities have been reported: a remote Denial of Service vulnerability has been reported due to a buffer overflow in the
'gaim_markup_strip_html()' function; and a vulnerability has been reported in the IRC protocol plug-in due to insufficient sanitization of the 'irc_msg' data, which could let a remote malicious user execute arbitrary code.

Update available at:
http://gaim.sourceforge.net
/downloads.php

Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/

Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/g/gaim/

Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-05.xml

RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-365.html

Mandrake:
http://www.mandrakesecure.net/
en/ftp.php

SGI:
http://www.sgi.com/support/
security/

Peachtree:
http://peachtree.burdell.org/
updates/

Conectiva:
ftp://atualizacoes.
conectiva.com.br/

Currently we are not aware of any exploits for these vulnerabilities.

Gaim 'Gaim_Markup_
Strip_HTML()' Function Remote
Denial of Service & IRC Protocol Plug-in Arbitrary Code Execution

CAN-