|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 19 Apr 2002 21:20:19 To : All Subject : URL: http://www.lwn.net/2002/0418/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo]
[LWN.net]
Sections:
[2]Main page
Security
[3]Kernel
[4]Distributions
[5]Development
[6]Commerce
[7]Linux in the news
[8]Announcements
[9]Letters
[10]All in one big page
See also: [11]last week's Security page.
Security
News and Editorials
Are 1024 bit RSA keys secure? RSA Laboratories has [12]published an
FAQ about Dan Bernstein's [13]recent research on factoring. Some
recent posts and articles have expressed concern that 1024-bit RSA
keys are no longer secure based on Dr. Bernstein's research.
RSA Laboratories, [14]Dan Bernstein himself and [15]Bruce Schneier do
not predict any immediate threat to the security of 1024 bit RSA keys
based on this research. When choosing a key size, RSA Laboratories
considers the table of proposed key sizes offered for discussion at
[16]NIST's key management workshop in November 2001 (PDF format) to
still be "reasonable general guidelines".
CRYPTO-GRAM Newsletter. [17]Bruce Schneier's CRYPTO-GRAM Newsletter
for April is out. He looks at ways of thinking about security,
corporate liability for security vulnerabilities, and more. "If
security has a silly season, we're in it. After September 11, every
two-bit peddler of security technology crawled out of the woodwork
with new claims about how his product can make us all safe again.
Every misguided and defeated government security initiative was
dragged out of the closet, dusted off, and presented as the savior of
our way of life."
Security Reports
mod_python 2.7.7 released. Version 2.7.7 of mod_python [18]has been
announced. "This release (as far as I could tell adequately) addresses
the security issue whereby a module indirectly imported by a published
module could then be accessed via the publisher." Upgrades are
recommended.
Debian security update to xpilot. The Debian Project has sent out
[19]a security alert for xpilot regarding a buffer overflow
vulnerability which could be remotely exploitable.
Squid vulnerable to a DNS server based attack. The [20]vulnerability
exists in Squid-2.x up to and including 2.4.STABLE4. "A malicous DNS
server could craft a DNS reply that causes Squid to exit with a
SIGSEGV." MandrakeSoft has released what appears to be the first
[21]security update from a distributor to fix the problem for ML 7.1,
7.2, 8.0, 8.1, 8.2, Corporate Server 1.0.1, and Single Network
Firewall 7.2.
Webalizer is also vulnerable to a DNS server based attach because of a
[22]buffer overflow bug. This [23]unofficial patch to fix the problem
was posted on Bugtraq. This one sounds nasty. If reverse DNS lookups
are enabled in webalizer, "an attacker with command over his own DNS
service, has the ability to gain remote root acces to a machine."
Multiple vulnerabilities in the Melange chat system were [24]reported
by Leon Harris. "[25]Melange is a chat system written in C and java
which is freely available under GPL. It is quite a nice system, and
has been my pleasure to work with it. It was also coded nearly five
years ago, at a time when people were not quite so security conscious.
Its author has indicated that he is not currently maintaining it, due
to other commitments."
web scripts.
The following web scripts were reported to contain vulnerabilities:
* [26]Guestbook and [27]xNewsletter from [28]x-dev.de were
[29]reported to have multiple vulnerabilities including cross site
scripting and "Arbitrary Command Execution under certain
circumstances."
Proprietary products.
The following proprietary products were reported to contain
vulnerabilities:
* IBM Informix Web DataBlade [30]SQL injection and related
[31]auto-decoding HTML vulnerabilities were reported by Simon
Lodal. When contacted by LWN, IBM Informix Support stated that a
fix is being tested and is expected to be released "soon."
Updates
Cross-site scripting vulnerability in Horde/IMP. Version 2.2.8 of IMP
[32]has been released, it fixes some vulnerabilities. "The Horde team
announces the availability of IMP 2.2.8, which prevents some potential
cross-site scripting (CSS) attacks. Site administrators should
consider upgrading to IMP 3 (our first recommendation), but if this is
not possible, IMP 2.2.8 should be used to prevent these potential
attacks." (First LWN report: [33]April 11, 2002).
This week's updates:
* [34]Debian (April 16, 2002)
* [35]Caldera (April 16, 2002)
Format string exploits in libsafe [36]Libsafe versions prior to 2.0-12
are [37]vulnerable to format string exploits. "Libsafe protection
against format string exploits may be easily bypassed using flag
characters that are implemented in glibc but are not implemented in
libsafe." The current version is [38]libsafe 2.0-13. Steve Beattie
[39]pointed out that the [40]Immunix FormatGuard tool is not
vulnerable to these kinds of attacks. (First LWN report: [41]March 28,
2002).
This week's updates:
* [42]Mandrake (April 11, 2002)
rsync supplementary groups vulnerability. Ethan Benson [43]reported
that rsyncd fails to remove supplementary groups (such as root) from
the server process after changing to the specified unprivileged uid
and gid. "This seems only serious if rsync is called using "rsync
--daemon" from the command line where it will inherit the group of the
user starting the server (usually root)." (First LWN report:
[44] March 14th, 2002).
This week's updates:
Previous updates:
* [45]Caldera (April 3, 2002)
* [46]Conectiva (March 14, 2002)
* [47]Mandrake (March 13, 2002)
* [48]Red Hat (March 21, 2002)
* [49]Slackware (March 12, 2002)
Resources
[50]Fragroute 1.2 has been [51]released by dug song. "fragroute
intercepts, modifies, and rewrites egress traffic destined for a
specified host, implementing most of the attacks described in the
Secure Networks "Insertion, Evasion, and Denial of Service: Eluding
Network Intrusion Detection" paper of January 1998." [52]Fragroute is
intended to aid in the testing of network intrusion detection systems
and firewalls.
Keyed-Hash Message Authentication Code standard. The US NIST has
[53]published FIPS 198, The Keyed-Hash Message Authentication Code.
FIPS 198 "became a [US] Federal standard on March 6, 2002 [...] The
standard describes a keyed-hash message authentication code (HMAC), a
mechanism for message authentication using cryptographic hash
functions."
Linux security week. The [54]Linux Advisory Watch publications from
LinuxSecurity.com is available.
Events
Upcoming Security Events.
Date Event Location
April 18 - 19, 2002 [55]The Twelfth Conference on Computers, Freedom &
Privacy (Cathedral Hill Hotel)San Francisco, California, USA
April 18 - 19, 2002 [56]InfoSec 2002 UniNet IRC network
(irc.uninet.edu) - channel #infosec
April 23 - 25, 2002 [57]Infosecurity Europe 2002 Olympia, London, UK
May 1 - 3, 2002 [58]cansecwest/core02 Vancouver, Canada
May 4 - 5, 2002 [59]DallasCon Dallas, TX., USA
May 12 - 15, 2002 [60]2002 IEEE Symposium on Security and Privacy (The
Claremont Resort)Oakland, California, USA
May 13 - 14, 2002 [61]3rd International Common Criteria
Conference(ICCC) Ottawa, Ont., Canada
May 13 - 17, 2002 14th Annual Canadian Information Technology Security
Symposium(CITSS) (Ottawa Congress Centre)Ottawa, Ontario, Canada
May 27 - 31, 2002 [62]3rd International SANE Conference(SANE 2002)
Maastricht, The Netherlands
May 29 - 30, 2002 [63]RSA Conference 2002 Japan (Akasaka Prince
Hotel)Tokyo, Japan
June 17 - 19, 2002 [64]NetSec 2002 San Fransisco, California, USA
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [65]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [66]lwn@lwn.net.
Section Editor: [67]Dennis Tenney
April 18, 2002
Sponsored Link
[68]Your Text Ad Here
Purchase your own text ad with our self-serve advertising system.
LWN Resources
[69]Security alerts archive
Secured Distributions:
[70]Astaro Security
[71]Blue Linux
[72]Castle
[73]Engarde Secure Linux
[74]Immunix
[75]Kaladix Linux
[76]NSA Security Enhanced
[77]Openwall GNU/Linux
[78]Trustix
Security Projects
[79]Bastille
[80]Linux Security Audit Project
[81]Linux Security Module
[82]OpenSSH
Security List Archives
[83]Bugtraq Archive
[84]Firewall Wizards Archive
[85]ISN Archive
Distribution-specific links
[86]Caldera Advisories
[87]Conectiva Updates
[88]Debian Alerts
[89]Kondara Advisories
[90]Esware Alerts
[91]LinuxPPC Security Updates
[92]Mandrake Updates
[93]Red Hat Errata
[94]SuSE Announcements
[95]Turbolinux
[96]Yellow Dog Errata
BSD-specific links
[97]BSDi
[98]FreeBSD
[99]NetBSD
[100]OpenBSD
Security mailing lists
[101]Caldera
[102]Cobalt
[103]Conectiva
[104]Debian
[105]Esware
[106]FreeBSD
[107]Kondara
[108]LASER5
[109]Linux From Scratch
[110]Linux-Mandrake
[111]NetBSD
[112]OpenBSD
[113]Red Hat
[114]Slackware
[115]Stampede
[116]SuSE
[117]Trustix
[118]turboLinux
[119]Yellow Dog
Security Software Archives
[120]munitions
[121]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[122]CERT
[123]CIAC
[124]Comp Sec News Daily
[125]Crypto-GRAM
[126]LinuxLock.org
[127]LinuxSecurity.com
[128]Security Focus
[129]SecurityPortal
[130]Next: Kernel
[131]Eklektix, Inc. Linux powered! Copyright Л 2002 [132]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://lwn.net/2002/0418/
3. http://lwn.net/2002/0418/kernel.php3
4. http://lwn.net/2002/0418/dists.php3
5. http://lwn.net/2002/0418/devel.php3
6. http://lwn.net/2002/0418/commerce.php3
7. http://lwn.net/2002/0418/press.php3
8. http://lwn.net/2002/0418/announce.php3
9. http://lwn.net/2002/0418/letters.php3
10. http://lwn.net/2002/0418/bigpage.php3
11. http://lwn.net/2002/0411/security.php3
12. http://www.rsasecurity.com/rsalabs/
13. http://cr.yp.to/papers.html#nfscircuit.
14. http://www.infosecuritymag.com/2002/apr/news.shtml#factoringfriction
15. http://lwn.net/2002/0418/a/crypto-gram.php3
16.
http://csrc.nist.gov/encryption/kms/key-management-guideline-(workshop).pdf
17. http://lwn.net/2002/0418/a/crypto-gram.php3
18. http://lwn.net/2002/0418/a/modpy277.php3
19. http://lwn.net/alerts/Debian/DSA-127-1.php3
20. http://www.squid-cache.org/Advisories/SQUID-2002_2.txt
21. http://lwn.net/alerts/Mandrake/MDKSA-2002:027.php3
22. http://lwn.net/2002/0418/a/webalizer.php3
23. http://lwn.net/2002/0418/a/webalizerpatch.php3
24. http://lwn.net/2002/0418/a/melange.php3
25. http://melange.terminal.at/
26. http://www.x-gfx.de/index.php?cat=php&page=./download/down.php
27. http://www.x-gfx.de/index.php?cat=php&page=./download/down.php
28. http://www.x-dev.de/
29. http://lwn.net/2002/0418/a/x-devde.php3
30. http://lwn.net/2002/0418/a/informixdbsql.php3
31. http://lwn.net/2002/0418/a/informixdbautodec.php3
32. http://lwn.net/2002/0411/a/imp228.php3
33. http://lwn.net/2002/0411/security.php3#imp
34. http://lwn.net/alerts/Debian/DSA-126-1.php3
35. http://lwn.net/alerts/Caldera/CSSA-2002-016.0.php3
36. http://www.research.avayalabs.com/project/libsafe/
37. http://lwn.net/2002/0328/a/libsafe.php3
38. http://www.research.avayalabs.com/project/libsafe/
39. http://lwn.net/2002/0328/a/formatguard.php3
40. http://immunix.org/formatguard.html
41. http://lwn.net/2002/0328/security.php3#libsafe
42. http://lwn.net/alerts/Mandrake/MDKSA-2002:026.php3
43. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=132272
44. http://lwn.net/2002/0314/security.php3#rsync
45. http://lwn.net/alerts/Caldera/CSSA-2002-014.0.php3
46. http://lwn.net/alerts/Conectiva/CLA-2002:469.php3
47. http://lwn.net/alerts/Mandrake/MDKSA-2002:024.php3
48. http://lwn.net/alerts/RedHat/RHSA-2002:026-43.php3
49. http://lwn.net/alerts/Slackware/sl-1015950024.php3
50. http://www.monkey.org/~dugsong/fragroute/
51. http://lwn.net/2002/0418/a/twomonkeys.php3
52. http://www.monkey.org/~dugsong/fragroute/
53. http://lwn.net/2002/0418/a/fips198.php3
54. http://lwn.net/2002/0418/a/advisory-watch.php3
55. http://www.cfp2002.org/
56. http://infosec.uninet.edu/
57. http://www.infosec.co.uk/
58. http://cansecwest.com/
59. http://www.dallascon.com/
60. http://www.ieee-security.org/TC/SP02/sp02index.html
61. http://www.cse-cst.gc.ca/en/iccc/iccc.html
62. http://www.nluug.nl/sane/
63. http://www.rsaconference.net/
64. http://www.gocsi.com/#netsec
65. http://securityfocus.com/calendar
66. mailto:lwn@lwn.net
67. mailto:lwn@lwn.net
68.
http://oasis.lwn.net/oasisc.php?s=4&c=5&cb=862023136&url=http%3A%2F%2Flwn.net%2F
corp%2Fadvertise%2Ftext%2F
69. http://lwn.net/alerts/
70. http://www.astaro.com/products/index.html
71. http://bluelinux.sourceforge.net/
72. http://castle.altlinux.ru/
73. http://www.engardelinux.org/
74. http://www.immunix.org/
75. http://www.kaladix.org/
76. http://www.nsa.gov/selinux/
77. http://www.openwall.com/Owl/
78. http://www.trustix.com/
79. http://www.bastille-linux.org/
80. http://lsap.org/
81. http://lsm.immunix.org/
82. http://www.openssh.com/
83. http://www.securityfocus.com/archive/1
84. http://www.nfr.net/firewall-wizards/
85. http://www.jammed.com/Lists/ISN/
86. http://www.calderasystems.com/support/security/
87. http://www.conectiva.com.br/atualizacoes/
88. http://www.debian.org/security/
89. http://www.kondara.org/errata/k12-security.html
90. http://www.esware.com/actualizaciones.html
91. http://linuxppc.org/security/advisories/
92. http://www.linux-mandrake.com/en/fupdates.php3
93. http://www.redhat.com/support/errata/index.html
94. http://www.suse.de/security/index.html
95. http://www.turbolinux.com/security/
96. http://www.yellowdoglinux.com/resources/
97. http://www.BSDI.COM/services/support/patches/
98. http://www.freebsd.org/security/security.html
99. http://www.NetBSD.ORG/Security/
100. http://www.openbsd.org/security.html
101. http://www.calderasystems.com/support/forums/announce.html
102. http://www.cobalt.com/support/resources/usergroups.html
103. http://distro.conectiva.com.br/atualizacoes/
104. http://www.debian.org/MailingLists/subscribe
105. http://www.esware.com/lista_correo.html
106. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
107. http://www.kondara.org/mailinglist.html.en
108. http://l5web.laser5.co.jp/ml/ml.html
109. http://www.linuxfromscratch.org/services/mailinglistinfo.php
110. http://www.linux-mandrake.com/en/flists.php3
111. http://www.netbsd.org/MailingLists/
112. http://www.openbsd.org/mail.html
113. http://www.redhat.com/mailing-lists/
114. http://www.slackware.com/lists/
115. http://www.stampede.org/mailinglists.php3
116. http://www.suse.com/en/support/mailinglists/index.html
117. http://www.trustix.net/support/
118. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
119. http://lists.yellowdoglinux.com/ydl_updates.shtml
120. http://munitions.vipul.net/
121. http://www.zedz.net/
122. http://www.cert.org/nav/alerts.html
123. http://ciac.llnl.gov/ciac/
124. http://www.MountainWave.com/
125. http://www.counterpane.com/crypto-gram.html
126. http://linuxlock.org/
127. http://linuxsecurity.com/
128. http://www.securityfocus.com/
129. http://www.securityportal.com/
130. http://lwn.net/2002/0418/kernel.php3
131. http://www.eklektix.com/
132. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/198617401e06d.html, оценка из 5, голосов 10
|