|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Network Computing and The SANS Institute (sans+ZZ19570268751127399_at_sans.org)
Date: Thu Jan 23 2003 - 16:15:00 CST
Re: Your personalized newsletter
-- Security Alert Consensus --
Number 003 (03.03)
Thursday, January 23, 2003
Created for you by
Network Computing and the SANS Institute
Powered by Neohapsis
----------------------------------------------------------------------
Welcome to SANS' distribution of the Security Alert Consensus.
************************* Begin Advertisement ************************
This issue sponsored by SPI Dynamics.
ALERT: Automatic Remote Code Audit and Report for your Web Apps Test
your Web applications for SQL Injection, Cross-Site Scripting and
Session Hijacking
All undetectable by Firewalls and IDS!
FREE 15 Day Product Trial and Comprehensive Vulnerability Report
http://www.spidynamics.com/mktg/freewebinspect38
************************** End Advertisement *************************
An interesting new attack vector was published. Based on cross-site
scripting, the new 'cross-site tracing' (XST) uses a Web server's
TRACE method to access a user's cookies and authentication
information. The net result: HTTP servers that allow TRACE
requests are open to cross-site scripting regardless of any
CGIs/scripts on the Web server. You can read more about it at:
http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdf
Until next week,
--Security Alert Consensus Team
************************************************************************
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
TABLE OF CONTENTS:
{03.03.015} Win - WebCollection Plus CGI arbitrary file reading
{03.03.017} Win - Shambala FTP server ftproot escaping
{03.03.019} Win - Xynph FTP server ftproot escaping
{03.03.021} Win - NiteServer FTP server ftproot escaping
{03.03.024} Win - CuteFTP large LIST response overflow
{03.03.001} Linux - Update {03.02.016}: Bugzilla backup configuration
password disclosure
{03.03.002} Linux - Update {03.01.010}: CUPS multiple vulnerabilities
{03.03.005} Linux - Update {02.49.013}: Canna two local vulnerabilities
{03.03.006} Linux - SuSE susehelp CGI command execution
{03.03.009} Linux - Update {03.02.014}: IMP CGI various SQL injection
{03.03.011} Linux - Update {02.49.014}: wget directory recursion
vulnerability
{03.03.012} Linux - Update {02.49.019}: Cyrus SASL library overflows
{03.03.025} Linux - Mandrake printer-drivers vulnerability
{03.03.022} HPUX - Xserver vulnerability on HP-UX 11.22
{03.03.023} HPUX - sort utility vulnerabilities
{03.03.007} SCO - Update {02.45.007}: BIND SIG cached RR overflow + 2
DoS
{03.03.003} Cross - CVS directory double-free vulnerability
{03.03.004} Cross - Multiple PHP script vulnerabilities 01/21
{03.03.008} Cross - MySQL multiple vulnerabilities 01/21
{03.03.010} Cross - ISC DHCP/minires buffer overflow
{03.03.013} Cross - PeopleSoft XXE file reading
{03.03.014} Cross - Apache 2.0.44 released, with security fixes
{03.03.016} Cross - PostgreSQL VACUUM data destructions
{03.03.018} Cross - IPFilter bad checksum state tracking DoS
{03.03.020} Cross - VIM comments command execution
- --- Windows News -------------------------------------------------------
*** {03.03.015} Win - WebCollection Plus CGI arbitrary file reading
Follet Software's WebCollection Plus CGI suite version 5.00 allows
a remote attacker to view arbitrary files on the system via the
s.dll CGI.
This vulnerability is not confirmed.
Source: SecurityFocus Bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-01/0096.html
*** {03.03.017} Win - Shambala FTP server ftproot escaping
The Shambala FTP service included with version 4.5 allows remote
attackers to access files outside the ftproot.
This vulnerability is not confirmed.
Source: VulnWatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0026.html
*** {03.03.019} Win - Xynph FTP server ftproot escaping
Xynph FTP server version 1.0 allows attackers to access files outside
the ftproot via the use of direct and relative directory naming tricks.
This vulnerability is not confirmed.
Source: SecurityFocus Bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-01/0170.html
*** {03.03.021} Win - NiteServer FTP server ftproot escaping
NiteServer FTP service version 1.83 allows remote attackers to access
files outside the ftproot.
This vulnerability is not confirmed.
Source: VulnWatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0022.html
*** {03.03.024} Win - CuteFTP large LIST response overflow
The CuteFTP client version 5.0 XP contains a buffer overflow in the
handling of large LIST responses that allows a malicious FTP server
to potentially execute arbitrary code on the user's system.
This vulnerability is not confirmed.
Source: SecurityFocus Bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-01/0123.html
- --- Linux News ---------------------------------------------------------
*** {03.03.001} Linux - Update {03.02.016}: Bugzilla backup
configuration password disclosure
Debian released updated Bugzilla packages, which fix the vulnerability
discussed in {03.02.016} ("Bugzilla backup configuration password
disclosure").
Updated DEBs are listed at the reference URL below.
Source: Debian
http://archives.neohapsis.com/archives/vendor/2003-q1/0019.html
*** {03.03.002} Linux - Update {03.01.010}: CUPS multiple
vulnerabilities
Debian released updated CUPS packages, which fix the vulnerabilities
discussed in {03.01.010} ("CUPS multiple vulnerabilities").
Updated Debian DEBs:
http://archives.neohapsis.com/archives/vendor/2003-q1/0022.html
Updated Caldera RPMs:
http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0005.html
Source: Debian, Caldera
http://archives.neohapsis.com/archives/vendor/2003-q1/0022.html
http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0005.html
*** {03.03.005} Linux - Update {02.49.013}: Canna two local
vulnerabilities
Caldera released updated Canna packages, which fix the vulnerabilities
discussed in {02.49.013} ("Canna two local vulnerabilities").
Updated RPMs are listed at the reference URL below.
Source: Caldera
http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0006.html
*** {03.03.006} Linux - SuSE susehelp CGI command execution
SuSE's susehelp CGI package allows remote attackers to execute
arbitrary command-line commands under the privilege of the Web server.
SuSE confirmed this vulnerability and released updated RPMs, listed
at the reference URL below.
Source: SuSE
http://archives.neohapsis.com/archives/linux/suse/2003-q1/0184.html
*** {03.03.009} Linux - Update {03.02.014}: IMP CGI various SQL
injection
Debian released updated IMP packages, which fix the vulnerability
discussed in {03.02.014} ("IMP CGI various SQL injection").
Updated DEBs are listed at the reference URL below.
Source: Debian
http://archives.neohapsis.com/archives/vendor/2003-q1/0018.html
*** {03.03.011} Linux - Update {02.49.014}: wget directory recursion
vulnerability
Caldera released updated wget packages, which fix the vulnerability
discussed in {02.49.014} ("wget directory recursion vulnerability").
Updated RPMs are listed at the reference URL below.
Source: Caldera
http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0004.html
*** {03.03.012} Linux - Update {02.49.019}: Cyrus SASL library overflows
Red Hat released updated Cyrus SASL packages, which fix the
vulnerabilities discussed in {02.49.019} ("Cyrus SASL library
overflows").
Updated RPMs are listed at the reference URL below.
Source: Red Hat
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0002.html
*** {03.03.025} Linux - Mandrake printer-drivers vulnerability
The Mandrake printer-drivers package contains a vulnerability that
allows a local attacker to empty or create arbitrary files on the
system.
Mandrake confirmed this vulnerability and released updated RPMs,
listed at the reference URL below.
Source: Mandrake
http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0039.html
- --- HPUX News ----------------------------------------------------------
*** {03.03.022} HPUX - Xserver vulnerability on HP-UX 11.22
HP released patch PHSS_25291 for HPUX 11.22 systems, which fixes a
security problem in Xserver. Additional details were not given.
Source: HP
http://archives.neohapsis.com/archives/hp/2003-q1/0009.html
*** {03.03.023} HPUX - sort utility vulnerabilities
An HP advisory indicates the sort command contains a vulnerability
that could possibly result in a denial of service or privilege
elevation. Our guess is that it insecurely creates temporary files.
Apply the following patch:
HPUX 11.11: PHCO_25918
HPUX 11.04: PHCO_28467
HPUX 11.00: PHCO_27565
HPUX 10.20: PHCO_27564
HPUX 10.10: PHCO_27940
HPUX 10.01: PHCO_28142
Source: HP
http://archives.neohapsis.com/archives/hp/2003-q1/0009.html
- --- SCO News -----------------------------------------------------------
*** {03.03.007} SCO - Update {02.45.007}: BIND SIG cached RR overflow +
2 DoS
Caldera/SCO released updated BIND packages, which fix the
vulnerabilities discussed in {02.45.007} ("BIND SIG cached RR overflow
+ 2 DoS").
Updated binaries are available at:
ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.2
Source: Caldera/SCO
http://archives.neohapsis.com/archives/linux/caldera/2003-q1/0003.html
- --- Cross-Platform News ------------------------------------------------
*** {03.03.003} Cross - CVS directory double-free vulnerability
CVS versions 1.11.4 and prior contain a bug in the handling of
malformed directory commands, resulting in a double-free vulnerability
that can potentially execute arbitrary code on some platforms.
This vulnerability is confirmed. A third-party patch is available at:
http://security.e-matters.de/patches/cvs_disablexprog.diff
OpenBSD patches:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/006_cvs.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/020_cvs.patch
Updated Red Hat RPMs:
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0021.html
Updated Mandrake RPMs:
http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0036.html
Updated Debian DEBs:
http://archives.neohapsis.com/archives/vendor/2003-q1/0024.html
Updated Conectiva RPMs:
http://archives.neohapsis.com/archives/linux/conectiva/2003-q1/0002.html
Source: VulnWatch, Red Hat, Mandrake, Debian, Conectiva, OpenBSD
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0021.html
http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0036.html
http://archives.neohapsis.com/archives/vendor/2003-q1/0024.html
http://archives.neohapsis.com/archives/linux/conectiva/2003-q1/0002.html
http://archives.neohapsis.com/archives/openbsd/2003-01/1613.html
*** {03.03.004} Cross - Multiple PHP script vulnerabilities 01/21
The following PHP scripts reportedly contain various vulnerabilities.
vAuthenticate 2.8: SQL tampering
http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html
vSignup 2.1: SQL tampering
http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html
DCP-Portal 5.0.1: multiple vulnerabilities
http://archives.neohapsis.com/archives/bugtraq/2003-01/0136.html
phpLinks: XSS
http://archives.neohapsis.com/archives/bugtraq/2003-01/0134.html
phpBB 2.0.3: SQL injection/data tampering
http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html
phpPass 2.0: SQL injection
http://archives.neohapsis.com/archives/bugtraq/2003-01/0129.html
Cyboards 1.25: remote code execution, XSS
http://archives.neohapsis.com/archives/bugtraq/2003-01/0158.html
PHP Topsites: multiple vulnerabilities
http://archives.neohapsis.com/archives/bugtraq/2003-01/0175.html
YABBSE 1.4.1: SQL injection
http://archives.neohapsis.com/archives/bugtraq/2003-01/0139.html
w-agora 4.1.5: arbitrary file reading
http://archives.neohapsis.com/archives/bugtraq/2003-01/0081.html
Source: SecurityFocus Bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-01/0159.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0136.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0134.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0129.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0158.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0175.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0139.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0081.html
*** {03.03.008} Cross - MySQL multiple vulnerabilities 01/21
Both MySQL 3.x and 4.x contain multiple vulnerabilities: COM_TABLE_DUMP
DoS; COM_CHANGE_USER authentication error and buffer overflow; and
libmysqlclient buffer overflows. A mysqld DoS also is mentioned in
the change log. Version 3.23.54a contains the fixes.
These vulnerabilities are confirmed.
Updated Red Hat RPMs:
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0015.html
Source: Red Hat
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0015.html
*** {03.03.010} Cross - ISC DHCP/minires buffer overflow
The minires library included with ISC's DHCP server package contains a
buffer overflow in the handling of dynamic DNS host names that allows
the remote execution of arbitrary code.
Updated Red Hat RPMs:
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0016.html
Updated Debian DEBs:
http://archives.neohapsis.com/archives/vendor/2003-q1/0020.html
Updated Mandrake RPMs:
http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0031.html
Updated SuSE RPMs:
http://archives.neohapsis.com/archives/vendor/2003-q1/0023.html
Source: CERT, Red Hat, Debian, Mandrake, SuSE
http://archives.neohapsis.com/archives/cc/2003-q1/0000.html
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0016.html
http://archives.neohapsis.com/archives/vendor/2003-q1/0020.html
http://archives.neohapsis.com/archives/linux/mandrake/2003-q1/0031.html
http://archives.neohapsis.com/archives/vendor/2003-q1/0023.html
*** {03.03.013} Cross - PeopleSoft XXE file reading
PeopleSoft's PeopleTools versions 8.1x prior to 8.19 are vulnerable
to XML external entities (XXE). As a result, remote attackers can
submit a particularly formed XML submission that allows them to read
arbitrary files on the PeopleSoft server.
The advisory indicates vendor confirmation.
Source: VulnWatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0027.html
*** {03.03.014} Cross - Apache 2.0.44 released, with security fixes
Apache version 2.0.44 was released. The latest version contains
security-related fixes for those running Apache 2.x on Windows
platforms. The vulnerabilities include arbitrary file reading,
arbitrary code execution and a denial of service.
The latest Apache source code is available at:
http://www.apache.org/
Source: Apache
http://archives.neohapsis.com/archives/apache/2003/0000.html
*** {03.03.016} Cross - PostgreSQL VACUUM data destructions
A bug in PostgreSQL versions 7.2.1 and 7.2.2 causes them to improperly
handle the VACUUM command, potentially allowing normal database users
to delete data in an unrecoverable manner.
Red Hat confirmed this vulnerability and released updated RPMs listed
at the reference URL below.
Source: Red Hat
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0013.html
*** {03.03.018} Cross - IPFilter bad checksum state tracking DoS
A recent post describes a situation in which a random ACK packet with
a bad checksum will fool IPFilter into believing the connection is
established, thus reserving an entry in the state tracking table for
a long length of time. A large number of these packets will exhaust
the table and result in a denial of service. This situation only
occurs under certain configurations.
The vendor confirmed this vulnerability.
Source: SecurityFocus Bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-01/0143.html
http://archives.neohapsis.com/archives/bugtraq/2003-01/0038.html
*** {03.03.020} Cross - VIM comments command execution
The VIM editor executes command-line commands when handling modeline
comments in a file. This could allow a malicious file to execute
arbitrary commands when opened with VIM.
This vulnerability is confirmed. Red Hat has released updated RPMs.
Source: Red Hat
http://archives.neohapsis.com/archives/linux/redhat/2003-q1/0018.html
************************************************************************
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (BSD/OS)
Comment: For info see http://www.gnupg.org
iD8DBQE+MGHt+LUG5KFpTkYRAgVgAKCP+vcO0iTLFybqESG0wMfMHyoeRACghLPt
IainJ9StSEcskqte/vsw84A=
=EcOa
-----END PGP SIGNATURE-----
------------------------------------------------------------------------
************************* Begin Advertisement ************************
This issue sponsored by SPI Dynamics.
ALERT: Automatic Remote Code Audit and Report for your Web Apps Test
your Web applications for SQL Injection, Cross-Site Scripting and
Session Hijacking
All undetectable by Firewalls and IDS!
FREE 15 Day Product Trial and Comprehensive Vulnerability Report
http://www.spidynamics.com/mktg/freewebinspect38
************************** End Advertisement *************************
Become a Security Alert Consensus member! If this e-mail was passed
to you and you would like to begin receiving our security e-mail
newsletter on a weekly basis, we invite you to subscribe today.
https://www.sans.org/sansnews/
We are signing the Consensus newsletter
with PGP. The new SANS PGP key is posted at:
http://www.pgp.net:11371/pks/lookup?op=get&search=0xA1694E46 and can
also be accessed from the SANS Web site (http://www.sans.org).
Special Note: To better secure your confidential information,
we will no longer include personal URLs in our Consensus
newsletter mailings. Instead, we have created a new form
(http://www.sans.org/sansurl). On this form you can enter the SD
number located near your name at the top of the newsletter. When you
submit this form, an e-mail containing a URL will be sent to you at
the e-mail address on record. With this URL you can make changes to
your account (edit the content of your Consensus mailing, for example)
without endangering the security of your personal URL. If you'd like
to change your e-mail address or other information, please visit your
new URL as described above. If you have any problems or questions,
e-mail us at <sans
sans.org>.
If you would like to unsubscribe from this newsletter, grab your SD
number (next to your name at the top of this message) and visit the
URL below. You will be sent a personal URL via E-mail, from which
you can unsubscribe. http://www.sans.org/sansurl
Missed an issue? You can find back issues of Security Alert Consensus
(and other SANS newsletters) online.
http://www.sans.org/newsletters/
Your opinion counts. We'd like to hear your thoughts on Security Alert
Consensus. E-mail any questions or comments to <consensus
nwc.com>.
Copyright (c) 2002 Network Computing, a CMP Media LLC
publication. All Rights Reserved. Distributed by Network
Computing (http://www.networkcomputing.com) and The SANS Institute
(http://www.sans.org). Powered by Neohapsis Inc., a Chicago-based
security assessment and integration services consulting group
(info
neohapsis.com | http://www.neohapsis.com/).
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]