OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Network Computing and The SANS Institute (sans+ZZ19570268751127399_at_sans.org)
Date: Thu Jan 23 2003 - 16:15:00 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Re: Your personalized newsletter

                     -- Security Alert Consensus --
                           Number 003 (03.03)
                      Thursday, January 23, 2003
                           Created for you by
                Network Computing and the SANS Institute
                          Powered by Neohapsis

    ----------------------------------------------------------------------

    Welcome to SANS' distribution of the Security Alert Consensus.

    ************************* Begin Advertisement ************************

    This issue sponsored by SPI Dynamics.

    ALERT: Automatic Remote Code Audit and Report for your Web Apps Test
    your Web applications for SQL Injection, Cross-Site Scripting and
    Session Hijacking
    All undetectable by Firewalls and IDS!
    FREE 15 Day Product Trial and Comprehensive Vulnerability Report
    http://www.spidynamics.com/mktg/freewebinspect38

    ************************** End Advertisement *************************

    An interesting new attack vector was published. Based on cross-site
    scripting, the new 'cross-site tracing' (XST) uses a Web server's
    TRACE method to access a user's cookies and authentication
    information. The net result: HTTP servers that allow TRACE
    requests are open to cross-site scripting regardless of any
    CGIs/scripts on the Web server. You can read more about it at:
    http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdf

    Until next week,
    --Security Alert Consensus Team

    ************************************************************************

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    TABLE OF CONTENTS:

    {03.03.015} Win - WebCollection Plus CGI arbitrary file reading
    {03.03.017} Win - Shambala FTP server ftproot escaping
    {03.03.019} Win - Xynph FTP server ftproot escaping
    {03.03.021} Win - NiteServer FTP server ftproot escaping
    {03.03.024} Win - CuteFTP large LIST response overflow
    {03.03.001} Linux - Update {03.02.016}: Bugzilla backup configuration
                password disclosure
    {03.03.002} Linux - Update {03.01.010}: CUPS multiple vulnerabilities
    {03.03.005} Linux - Update {02.49.013}: Canna two local vulnerabilities
    {03.03.006} Linux - SuSE susehelp CGI command execution
    {03.03.009} Linux - Update {03.02.014}: IMP CGI various SQL injection
    {03.03.011} Linux - Update {02.49.014}: wget directory recursion
                vulnerability
    {03.03.012} Linux - Update {02.49.019}: Cyrus SASL library overflows
    {03.03.025} Linux - Mandrake printer-drivers vulnerability
    {03.03.022} HPUX - Xserver vulnerability on HP-UX 11.22
    {03.03.023} HPUX - sort utility vulnerabilities
    {03.03.007} SCO - Update {02.45.007}: BIND SIG cached RR overflow + 2
                DoS
    {03.03.003} Cross - CVS directory double-free vulnerability
    {03.03.004} Cross - Multiple PHP script vulnerabilities 01/21
    {03.03.008} Cross - MySQL multiple vulnerabilities 01/21
    {03.03.010} Cross - ISC DHCP/minires buffer overflow
    {03.03.013} Cross - PeopleSoft XXE file reading
    {03.03.014} Cross - Apache 2.0.44 released, with security fixes
    {03.03.016} Cross - PostgreSQL VACUUM data destructions
    {03.03.018} Cross - IPFilter bad checksum state tracking DoS
    {03.03.020} Cross - VIM comments command execution

    - --- Windows News -------------------------------------------------------

    *** {03.03.015} Win - WebCollection Plus CGI arbitrary file reading

    Follet Software's WebCollection Plus CGI suite version 5.00 allows
    a remote attacker to view arbitrary files on the system via the
    s.dll CGI.

    This vulnerability is not confirmed.

    Source: SecurityFocus Bugtraq
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0096.html

    *** {03.03.017} Win - Shambala FTP server ftproot escaping

    The Shambala FTP service included with version 4.5 allows remote
    attackers to access files outside the ftproot.

    This vulnerability is not confirmed.

    Source: VulnWatch
    http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0026.html

    *** {03.03.019} Win - Xynph FTP server ftproot escaping

    Xynph FTP server version 1.0 allows attackers to access files outside
    the ftproot via the use of direct and relative directory naming tricks.

    This vulnerability is not confirmed.

    Source: SecurityFocus Bugtraq
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0170.html

    *** {03.03.021} Win - NiteServer FTP server ftproot escaping

    NiteServer FTP service version 1.83 allows remote attackers to access
    files outside the ftproot.

    This vulnerability is not confirmed.

    Source: VulnWatch
    http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0022.html

    *** {03.03.024} Win - CuteFTP large LIST response overflow

    The CuteFTP client version 5.0 XP contains a buffer overflow in the
    handling of large LIST responses that allows a malicious FTP server
    to potentially execute arbitrary code on the user's system.

    This vulnerability is not confirmed.

    Source: SecurityFocus Bugtraq
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0123.html

    - --- Linux News ---------------------------------------------------------

    *** {03.03.001} Linux - Update {03.02.016}: Bugzilla backup
                    configuration password disclosure

    Debian released updated Bugzilla packages, which fix the vulnerability
    discussed in {03.02.016} ("Bugzilla backup configuration password
    disclosure").

    Updated DEBs are listed at the reference URL below.

    Source: Debian
    http://archives.neohapsis.com/archives/vendor/2003-q1/0019.html

    *** {03.03.002} Linux - Update {03.01.010}: CUPS multiple
                    vulnerabilities

    Debian released updated CUPS packages, which fix the vulnerabilities
    discussed in {03.01.010} ("CUPS multiple vulnerabilities").

    Updated Debian DEBs:
    http://archives.neohapsis.com/archives/vendor/2003-q1/0022.html

    Updated Caldera RPMs:
    http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0005.html

    Source: Debian, Caldera
    http://archives.neohapsis.com/archives/vendor/2003-q1/0022.html
    http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0005.html

    *** {03.03.005} Linux - Update {02.49.013}: Canna two local
                    vulnerabilities

    Caldera released updated Canna packages, which fix the vulnerabilities
    discussed in {02.49.013} ("Canna two local vulnerabilities").

    Updated RPMs are listed at the reference URL below.

    Source: Caldera
    http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0006.html

    *** {03.03.006} Linux - SuSE susehelp CGI command execution

    SuSE's susehelp CGI package allows remote attackers to execute
    arbitrary command-line commands under the privilege of the Web server.

    SuSE confirmed this vulnerability and released updated RPMs, listed
    at the reference URL below.

    Source: SuSE
    http://archives.neohapsis.com/archives/linux/suse/2003-q1/0184.html

    *** {03.03.009} Linux - Update {03.02.014}: IMP CGI various SQL
                    injection

    Debian released updated IMP packages, which fix the vulnerability
    discussed in {03.02.014} ("IMP CGI various SQL injection").

    Updated DEBs are listed at the reference URL below.

    Source: Debian
    http://archives.neohapsis.com/archives/vendor/2003-q1/0018.html

    *** {03.03.011} Linux - Update {02.49.014}: wget directory recursion
                    vulnerability

    Caldera released updated wget packages, which fix the vulnerability
    discussed in {02.49.014} ("wget directory recursion vulnerability").

    Updated RPMs are listed at the reference URL below.

    Source: Caldera
    http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0004.html

    *** {03.03.012} Linux - Update {02.49.019}: Cyrus SASL library overflows

    Red Hat released updated Cyrus SASL packages, which fix the
    vulnerabilities discussed in {02.49.019} ("Cyrus SASL library
    overflows").

    Updated RPMs are listed at the reference URL below.

    Source: Red Hat
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0002.html

    *** {03.03.025} Linux - Mandrake printer-drivers vulnerability

    The Mandrake printer-drivers package contains a vulnerability that
    allows a local attacker to empty or create arbitrary files on the
    system.

    Mandrake confirmed this vulnerability and released updated RPMs,
    listed at the reference URL below.

    Source: Mandrake
    http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0039.html

    - --- HPUX News ----------------------------------------------------------

    *** {03.03.022} HPUX - Xserver vulnerability on HP-UX 11.22

    HP released patch PHSS_25291 for HPUX 11.22 systems, which fixes a
    security problem in Xserver. Additional details were not given.

    Source: HP
    http://archives.neohapsis.com/archives/hp/2003-q1/0009.html

    *** {03.03.023} HPUX - sort utility vulnerabilities

    An HP advisory indicates the sort command contains a vulnerability
    that could possibly result in a denial of service or privilege
    elevation. Our guess is that it insecurely creates temporary files.

    Apply the following patch:
    HPUX 11.11: PHCO_25918
    HPUX 11.04: PHCO_28467
    HPUX 11.00: PHCO_27565
    HPUX 10.20: PHCO_27564
    HPUX 10.10: PHCO_27940
    HPUX 10.01: PHCO_28142

    Source: HP
    http://archives.neohapsis.com/archives/hp/2003-q1/0009.html

    - --- SCO News -----------------------------------------------------------

    *** {03.03.007} SCO - Update {02.45.007}: BIND SIG cached RR overflow +
                    2 DoS

    Caldera/SCO released updated BIND packages, which fix the
    vulnerabilities discussed in {02.45.007} ("BIND SIG cached RR overflow
    + 2 DoS").

    Updated binaries are available at:
    ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.2

    Source: Caldera/SCO
    http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0003.html

    - --- Cross-Platform News ------------------------------------------------

    *** {03.03.003} Cross - CVS directory double-free vulnerability

    CVS versions 1.11.4 and prior contain a bug in the handling of
    malformed directory commands, resulting in a double-free vulnerability
    that can potentially execute arbitrary code on some platforms.

    This vulnerability is confirmed. A third-party patch is available at:
    http://security.e-matters.de/patches/cvs_disablexprog.diff

    OpenBSD patches:
    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/006_cvs.patch
    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/020_cvs.patch

    Updated Red Hat RPMs:
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0021.html

    Updated Mandrake RPMs:
    http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0036.html

    Updated Debian DEBs:
    http://archives.neohapsis.com/archives/vendor/2003-q1/0024.html

    Updated Conectiva RPMs:
    http://archives.neohapsis.com/archives/linux/conectiva/2003-q1/0002.html

    Source: VulnWatch, Red Hat, Mandrake, Debian, Conectiva, OpenBSD
    http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0021.html
    http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0036.html
    http://archives.neohapsis.com/archives/vendor/2003-q1/0024.html
    http://archives.neohapsis.com/archives/linux/conectiva/2003-q1/0002.html
    http://archives.neohapsis.com/archives/openbsd/2003-01/1613.html

    *** {03.03.004} Cross - Multiple PHP script vulnerabilities 01/21

    The following PHP scripts reportedly contain various vulnerabilities.

    vAuthenticate 2.8: SQL tampering
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html

    vSignup 2.1: SQL tampering
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html

    DCP-Portal 5.0.1: multiple vulnerabilities
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0136.html

    phpLinks: XSS
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0134.html

    phpBB 2.0.3: SQL injection/data tampering
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html

    phpPass 2.0: SQL injection
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0129.html

    Cyboards 1.25: remote code execution, XSS
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0158.html

    PHP Topsites: multiple vulnerabilities
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0175.html

    YABBSE 1.4.1: SQL injection
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0139.html

    w-agora 4.1.5: arbitrary file reading
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0081.html

    Source: SecurityFocus Bugtraq
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0136.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0134.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0129.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0158.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0175.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0139.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0081.html

    *** {03.03.008} Cross - MySQL multiple vulnerabilities 01/21

    Both MySQL 3.x and 4.x contain multiple vulnerabilities: COM_TABLE_DUMP
    DoS; COM_CHANGE_USER authentication error and buffer overflow; and
    libmysqlclient buffer overflows. A mysqld DoS also is mentioned in
    the change log. Version 3.23.54a contains the fixes.

    These vulnerabilities are confirmed.

    Updated Red Hat RPMs:
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0015.html

    Source: Red Hat
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0015.html

    *** {03.03.010} Cross - ISC DHCP/minires buffer overflow

    The minires library included with ISC's DHCP server package contains a
    buffer overflow in the handling of dynamic DNS host names that allows
    the remote execution of arbitrary code.

    Updated Red Hat RPMs:
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0016.html

    Updated Debian DEBs:
    http://archives.neohapsis.com/archives/vendor/2003-q1/0020.html

    Updated Mandrake RPMs:
    http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0031.html

    Updated SuSE RPMs:
    http://archives.neohapsis.com/archives/vendor/2003-q1/0023.html

    Source: CERT, Red Hat, Debian, Mandrake, SuSE
    http://archives.neohapsis.com/archives/cc/2003-q1/0000.html
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0016.html
    http://archives.neohapsis.com/archives/vendor/2003-q1/0020.html
    http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0031.html
    http://archives.neohapsis.com/archives/vendor/2003-q1/0023.html

    *** {03.03.013} Cross - PeopleSoft XXE file reading

    PeopleSoft's PeopleTools versions 8.1x prior to 8.19 are vulnerable
    to XML external entities (XXE). As a result, remote attackers can
    submit a particularly formed XML submission that allows them to read
    arbitrary files on the PeopleSoft server.

    The advisory indicates vendor confirmation.

    Source: VulnWatch
    http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0027.html

    *** {03.03.014} Cross - Apache 2.0.44 released, with security fixes

    Apache version 2.0.44 was released. The latest version contains
    security-related fixes for those running Apache 2.x on Windows
    platforms. The vulnerabilities include arbitrary file reading,
    arbitrary code execution and a denial of service.

    The latest Apache source code is available at:
    http://www.apache.org/

    Source: Apache
    http://archives.neohapsis.com/archives/apache/2003/0000.html

    *** {03.03.016} Cross - PostgreSQL VACUUM data destructions

    A bug in PostgreSQL versions 7.2.1 and 7.2.2 causes them to improperly
    handle the VACUUM command, potentially allowing normal database users
    to delete data in an unrecoverable manner.

    Red Hat confirmed this vulnerability and released updated RPMs listed
    at the reference URL below.

    Source: Red Hat
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0013.html

    *** {03.03.018} Cross - IPFilter bad checksum state tracking DoS

    A recent post describes a situation in which a random ACK packet with
    a bad checksum will fool IPFilter into believing the connection is
    established, thus reserving an entry in the state tracking table for
    a long length of time. A large number of these packets will exhaust
    the table and result in a denial of service. This situation only
    occurs under certain configurations.

    The vendor confirmed this vulnerability.

    Source: SecurityFocus Bugtraq
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0143.html
    http://archives.neohapsis.com/archives/bugtraq/2003-01/0038.html

    *** {03.03.020} Cross - VIM comments command execution

    The VIM editor executes command-line commands when handling modeline
    comments in a file. This could allow a malicious file to execute
    arbitrary commands when opened with VIM.

    This vulnerability is confirmed. Red Hat has released updated RPMs.

    Source: Red Hat
    http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0018.html

    ************************************************************************

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (BSD/OS)
    Comment: For info see http://www.gnupg.org

    iD8DBQE+MGHt+LUG5KFpTkYRAgVgAKCP+vcO0iTLFybqESG0wMfMHyoeRACghLPt
    IainJ9StSEcskqte/vsw84A=
    =EcOa
    -----END PGP SIGNATURE-----
    ------------------------------------------------------------------------

    ************************* Begin Advertisement ************************

    This issue sponsored by SPI Dynamics.

    ALERT: Automatic Remote Code Audit and Report for your Web Apps Test
    your Web applications for SQL Injection, Cross-Site Scripting and
    Session Hijacking
    All undetectable by Firewalls and IDS!
    FREE 15 Day Product Trial and Comprehensive Vulnerability Report
    http://www.spidynamics.com/mktg/freewebinspect38

    ************************** End Advertisement *************************

    Become a Security Alert Consensus member! If this e-mail was passed
    to you and you would like to begin receiving our security e-mail
    newsletter on a weekly basis, we invite you to subscribe today.
    https://www.sans.org/sansnews/

    We are signing the Consensus newsletter
    with PGP. The new SANS PGP key is posted at:
    http://www.pgp.net:11371/pks/lookup?op=get&search=0xA1694E46 and can
    also be accessed from the SANS Web site (http://www.sans.org).

    Special Note: To better secure your confidential information,
    we will no longer include personal URLs in our Consensus
    newsletter mailings. Instead, we have created a new form
    (http://www.sans.org/sansurl). On this form you can enter the SD
    number located near your name at the top of the newsletter. When you
    submit this form, an e-mail containing a URL will be sent to you at
    the e-mail address on record. With this URL you can make changes to
    your account (edit the content of your Consensus mailing, for example)
    without endangering the security of your personal URL. If you'd like
    to change your e-mail address or other information, please visit your
    new URL as described above. If you have any problems or questions,
    e-mail us at <sanssans.org>.

    If you would like to unsubscribe from this newsletter, grab your SD
    number (next to your name at the top of this message) and visit the
    URL below. You will be sent a personal URL via E-mail, from which
    you can unsubscribe. http://www.sans.org/sansurl

    Missed an issue? You can find back issues of Security Alert Consensus
    (and other SANS newsletters) online.
    http://www.sans.org/newsletters/

    Your opinion counts. We'd like to hear your thoughts on Security Alert
    Consensus. E-mail any questions or comments to <consensusnwc.com>.

    Copyright (c) 2002 Network Computing, a CMP Media LLC
    publication. All Rights Reserved. Distributed by Network
    Computing (http://www.networkcomputing.com) and The SANS Institute
    (http://www.sans.org). Powered by Neohapsis Inc., a Chicago-based
    security assessment and integration services consulting group
    (infoneohapsis.com | http://www.neohapsis.com/).