Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   19 Apr 2002  21:20:19
 To : All
 Subject : URL: http://www.lwn.net/2002/0418/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] 
    [LWN.net]
 
    Sections:
     [2]Main page
     Security
     [3]Kernel
     [4]Distributions
     [5]Development
     [6]Commerce
     [7]Linux in the news
     [8]Announcements
     [9]Letters
    [10]All in one big page
 
    See also: [11]last week's Security page.
 
 Security
 
 News and Editorials
 
    Are 1024 bit RSA keys secure? RSA Laboratories has [12]published an
    FAQ about Dan Bernstein's [13]recent research on factoring. Some
    recent posts and articles have expressed concern that 1024-bit RSA
    keys are no longer secure based on Dr. Bernstein's research.
 
    RSA Laboratories, [14]Dan Bernstein himself and [15]Bruce Schneier do
    not predict any immediate threat to the security of 1024 bit RSA keys
    based on this research. When choosing a key size, RSA Laboratories
    considers the table of proposed key sizes offered for discussion at
    [16]NIST's key management workshop in November 2001 (PDF format) to
    still be "reasonable general guidelines".
 
    CRYPTO-GRAM Newsletter. [17]Bruce Schneier's CRYPTO-GRAM Newsletter
    for April is out. He looks at ways of thinking about security,
    corporate liability for security vulnerabilities, and more. "If
    security has a silly season, we're in it. After September 11, every
    two-bit peddler of security technology crawled out of the woodwork
    with new claims about how his product can make us all safe again.
    Every misguided and defeated government security initiative was
    dragged out of the closet, dusted off, and presented as the savior of
    our way of life."
 
 Security Reports
 
    mod_python 2.7.7 released. Version 2.7.7 of mod_python [18]has been
    announced. "This release (as far as I could tell adequately) addresses
    the security issue whereby a module indirectly imported by a published
    module could then be accessed via the publisher." Upgrades are
    recommended.
 
    Debian security update to xpilot. The Debian Project has sent out
    [19]a security alert for xpilot regarding a buffer overflow
    vulnerability which could be remotely exploitable.
 
    Squid vulnerable to a DNS server based attack. The [20]vulnerability
    exists in Squid-2.x up to and including 2.4.STABLE4. "A malicous DNS
    server could craft a DNS reply that causes Squid to exit with a
    SIGSEGV." MandrakeSoft has released what appears to be the first
    [21]security update from a distributor to fix the problem for ML 7.1,
    7.2, 8.0, 8.1, 8.2, Corporate Server 1.0.1, and Single Network
    Firewall 7.2.
 
    Webalizer is also vulnerable to a DNS server based attach because of a
    [22]buffer overflow bug. This [23]unofficial patch to fix the problem
    was posted on Bugtraq. This one sounds nasty. If reverse DNS lookups
    are enabled in webalizer, "an attacker with command over his own DNS
    service, has the ability to gain remote root acces to a machine."
 
    Multiple vulnerabilities in the Melange chat system were [24]reported
    by Leon Harris. "[25]Melange is a chat system written in C and java
    which is freely available under GPL. It is quite a nice system, and
    has been my pleasure to work with it. It was also coded nearly five
    years ago, at a time when people were not quite so security conscious.
    Its author has indicated that he is not currently maintaining it, due
    to other commitments."
 
    web scripts.
    The following web scripts were reported to contain vulnerabilities:
      * [26]Guestbook and [27]xNewsletter from [28]x-dev.de were
        [29]reported to have multiple vulnerabilities including cross site
        scripting and "Arbitrary Command Execution under certain
        circumstances."
 
    Proprietary products.
    The following proprietary products were reported to contain
    vulnerabilities:
      * IBM Informix Web DataBlade [30]SQL injection and related
        [31]auto-decoding HTML vulnerabilities were reported by Simon
        Lodal. When contacted by LWN, IBM Informix Support stated that a
        fix is being tested and is expected to be released "soon."
 
 Updates
 
    Cross-site scripting vulnerability in Horde/IMP. Version 2.2.8 of IMP
    [32]has been released, it fixes some vulnerabilities. "The Horde team
    announces the availability of IMP 2.2.8, which prevents some potential
    cross-site scripting (CSS) attacks. Site administrators should
    consider upgrading to IMP 3 (our first recommendation), but if this is
    not possible, IMP 2.2.8 should be used to prevent these potential
    attacks." (First LWN report: [33]April 11, 2002).
 
    This week's updates:
      * [34]Debian (April 16, 2002)
      * [35]Caldera (April 16, 2002)
 
    Format string exploits in libsafe [36]Libsafe versions prior to 2.0-12
    are [37]vulnerable to format string exploits. "Libsafe protection
    against format string exploits may be easily bypassed using flag
    characters that are implemented in glibc but are not implemented in
    libsafe." The current version is [38]libsafe 2.0-13. Steve Beattie
    [39]pointed out that the [40]Immunix FormatGuard tool is not
    vulnerable to these kinds of attacks. (First LWN report: [41]March 28,
    2002).
 
    This week's updates:
      * [42]Mandrake (April 11, 2002)
 
    rsync supplementary groups vulnerability. Ethan Benson [43]reported
    that rsyncd fails to remove supplementary groups (such as root) from
    the server process after changing to the specified unprivileged uid
    and gid. "This seems only serious if rsync is called using "rsync
    --daemon" from the command line where it will inherit the group of the
    user starting the server (usually root)." (First LWN report:
    [44] March 14th, 2002).
 
    This week's updates:
 
    Previous updates:
      * [45]Caldera (April 3, 2002)
      * [46]Conectiva (March 14, 2002)
      * [47]Mandrake (March 13, 2002)
      * [48]Red Hat (March 21, 2002)
      * [49]Slackware (March 12, 2002)
 
 Resources
 
    [50]Fragroute 1.2 has been [51]released by dug song. "fragroute
    intercepts, modifies, and rewrites egress traffic destined for a
    specified host, implementing most of the attacks described in the
    Secure Networks "Insertion, Evasion, and Denial of Service: Eluding
    Network Intrusion Detection" paper of January 1998." [52]Fragroute is
    intended to aid in the testing of network intrusion detection systems
    and firewalls.
 
    Keyed-Hash Message Authentication Code standard. The US NIST has
    [53]published FIPS 198, The Keyed-Hash Message Authentication Code.
    FIPS 198 "became a [US] Federal standard on March 6, 2002 [...] The
    standard describes a keyed-hash message authentication code (HMAC), a
    mechanism for message authentication using cryptographic hash
    functions."
 
    Linux security week. The [54]Linux Advisory Watch publications from
    LinuxSecurity.com is available.
 
 Events
 
    Upcoming Security Events.
 
    Date Event Location
    April 18 - 19, 2002 [55]The Twelfth Conference on Computers, Freedom &
    Privacy (Cathedral Hill Hotel)San Francisco, California, USA
    April 18 - 19, 2002 [56]InfoSec 2002 UniNet IRC network
    (irc.uninet.edu) - channel #infosec
    April 23 - 25, 2002 [57]Infosecurity Europe 2002 Olympia, London, UK
    May 1 - 3, 2002 [58]cansecwest/core02 Vancouver, Canada
    May 4 - 5, 2002 [59]DallasCon Dallas, TX., USA
    May 12 - 15, 2002 [60]2002 IEEE Symposium on Security and Privacy (The
    Claremont Resort)Oakland, California, USA
    May 13 - 14, 2002 [61]3rd International Common Criteria
    Conference(ICCC) Ottawa, Ont., Canada
    May 13 - 17, 2002 14th Annual Canadian Information Technology Security
    Symposium(CITSS) (Ottawa Congress Centre)Ottawa, Ontario, Canada
    May 27 - 31, 2002 [62]3rd International SANE Conference(SANE 2002)
    Maastricht, The Netherlands
    May 29 - 30, 2002 [63]RSA Conference 2002 Japan (Akasaka Prince
    Hotel)Tokyo, Japan
    June 17 - 19, 2002 [64]NetSec 2002 San Fransisco, California, USA
 
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [65]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [66]lwn@lwn.net.
 
    Section Editor: [67]Dennis Tenney
    April 18, 2002
 
                                Sponsored Link
 
    [68]Your Text Ad Here
 
    Purchase your own text ad with our self-serve advertising system.
 
    LWN Resources
    [69]Security alerts archive
    Secured Distributions:
    [70]Astaro Security
    [71]Blue Linux
    [72]Castle
    [73]Engarde Secure Linux
    [74]Immunix
    [75]Kaladix Linux
    [76]NSA Security Enhanced
    [77]Openwall GNU/Linux
    [78]Trustix
    Security Projects
    [79]Bastille
    [80]Linux Security Audit Project
    [81]Linux Security Module
    [82]OpenSSH
    Security List Archives
    [83]Bugtraq Archive
    [84]Firewall Wizards Archive
    [85]ISN Archive
    Distribution-specific links
    [86]Caldera Advisories
    [87]Conectiva Updates
    [88]Debian Alerts
    [89]Kondara Advisories
    [90]Esware Alerts
    [91]LinuxPPC Security Updates
    [92]Mandrake Updates
    [93]Red Hat Errata
    [94]SuSE Announcements
    [95]Turbolinux
    [96]Yellow Dog Errata
    BSD-specific links
    [97]BSDi
    [98]FreeBSD
    [99]NetBSD
    [100]OpenBSD
    Security mailing lists
    [101]Caldera
    [102]Cobalt
    [103]Conectiva
    [104]Debian
    [105]Esware
    [106]FreeBSD
    [107]Kondara
    [108]LASER5
    [109]Linux From Scratch
    [110]Linux-Mandrake
    [111]NetBSD
    [112]OpenBSD
    [113]Red Hat
    [114]Slackware
    [115]Stampede
    [116]SuSE
    [117]Trustix
    [118]turboLinux
    [119]Yellow Dog
    Security Software Archives
    [120]munitions
    [121]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [122]CERT
    [123]CIAC
    [124]Comp Sec News Daily
    [125]Crypto-GRAM
    [126]LinuxLock.org
    [127]LinuxSecurity.com
    [128]Security Focus
    [129]SecurityPortal
                                                         [130]Next: Kernel
 
    [131]Eklektix, Inc. Linux powered! Copyright Л 2002 [132]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://lwn.net/2002/0418/
    3. http://lwn.net/2002/0418/kernel.php3
    4. http://lwn.net/2002/0418/dists.php3
    5. http://lwn.net/2002/0418/devel.php3
    6. http://lwn.net/2002/0418/commerce.php3
    7. http://lwn.net/2002/0418/press.php3
    8. http://lwn.net/2002/0418/announce.php3
    9. http://lwn.net/2002/0418/letters.php3
   10. http://lwn.net/2002/0418/bigpage.php3
   11. http://lwn.net/2002/0411/security.php3
   12. http://www.rsasecurity.com/rsalabs/
   13. http://cr.yp.to/papers.html#nfscircuit.
   14. http://www.infosecuritymag.com/2002/apr/news.shtml#factoringfriction
   15. http://lwn.net/2002/0418/a/crypto-gram.php3
   16.
 http://csrc.nist.gov/encryption/kms/key-management-guideline-(workshop).pdf
   17. http://lwn.net/2002/0418/a/crypto-gram.php3
   18. http://lwn.net/2002/0418/a/modpy277.php3
   19. http://lwn.net/alerts/Debian/DSA-127-1.php3
   20. http://www.squid-cache.org/Advisories/SQUID-2002_2.txt
   21. http://lwn.net/alerts/Mandrake/MDKSA-2002:027.php3
   22. http://lwn.net/2002/0418/a/webalizer.php3
   23. http://lwn.net/2002/0418/a/webalizerpatch.php3
   24. http://lwn.net/2002/0418/a/melange.php3
   25. http://melange.terminal.at/
   26. http://www.x-gfx.de/index.php?cat=php&page=./download/down.php
   27. http://www.x-gfx.de/index.php?cat=php&page=./download/down.php
   28. http://www.x-dev.de/
   29. http://lwn.net/2002/0418/a/x-devde.php3
   30. http://lwn.net/2002/0418/a/informixdbsql.php3
   31. http://lwn.net/2002/0418/a/informixdbautodec.php3
   32. http://lwn.net/2002/0411/a/imp228.php3
   33. http://lwn.net/2002/0411/security.php3#imp
   34. http://lwn.net/alerts/Debian/DSA-126-1.php3
   35. http://lwn.net/alerts/Caldera/CSSA-2002-016.0.php3
   36. http://www.research.avayalabs.com/project/libsafe/
   37. http://lwn.net/2002/0328/a/libsafe.php3
   38. http://www.research.avayalabs.com/project/libsafe/
   39. http://lwn.net/2002/0328/a/formatguard.php3
   40. http://immunix.org/formatguard.html
   41. http://lwn.net/2002/0328/security.php3#libsafe
   42. http://lwn.net/alerts/Mandrake/MDKSA-2002:026.php3
   43. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=132272
   44. http://lwn.net/2002/0314/security.php3#rsync
   45. http://lwn.net/alerts/Caldera/CSSA-2002-014.0.php3
   46. http://lwn.net/alerts/Conectiva/CLA-2002:469.php3
   47. http://lwn.net/alerts/Mandrake/MDKSA-2002:024.php3
   48. http://lwn.net/alerts/RedHat/RHSA-2002:026-43.php3
   49. http://lwn.net/alerts/Slackware/sl-1015950024.php3
   50. http://www.monkey.org/~dugsong/fragroute/
   51. http://lwn.net/2002/0418/a/twomonkeys.php3
   52. http://www.monkey.org/~dugsong/fragroute/
   53. http://lwn.net/2002/0418/a/fips198.php3
   54. http://lwn.net/2002/0418/a/advisory-watch.php3
   55. http://www.cfp2002.org/
   56. http://infosec.uninet.edu/
   57. http://www.infosec.co.uk/
   58. http://cansecwest.com/
   59. http://www.dallascon.com/
   60. http://www.ieee-security.org/TC/SP02/sp02index.html
   61. http://www.cse-cst.gc.ca/en/iccc/iccc.html
   62. http://www.nluug.nl/sane/
   63. http://www.rsaconference.net/
   64. http://www.gocsi.com/#netsec
   65. http://securityfocus.com/calendar
   66. mailto:lwn@lwn.net
   67. mailto:lwn@lwn.net
   68.
 http://oasis.lwn.net/oasisc.php?s=4&c=5&cb=862023136&url=http%3A%2F%2Flwn.net%2F
 corp%2Fadvertise%2Ftext%2F
   69. http://lwn.net/alerts/
   70. http://www.astaro.com/products/index.html
   71. http://bluelinux.sourceforge.net/
   72. http://castle.altlinux.ru/
   73. http://www.engardelinux.org/
   74. http://www.immunix.org/
   75. http://www.kaladix.org/
   76. http://www.nsa.gov/selinux/
   77. http://www.openwall.com/Owl/
   78. http://www.trustix.com/
   79. http://www.bastille-linux.org/
   80. http://lsap.org/
   81. http://lsm.immunix.org/
   82. http://www.openssh.com/
   83. http://www.securityfocus.com/archive/1
   84. http://www.nfr.net/firewall-wizards/
   85. http://www.jammed.com/Lists/ISN/
   86. http://www.calderasystems.com/support/security/
   87. http://www.conectiva.com.br/atualizacoes/
   88. http://www.debian.org/security/
   89. http://www.kondara.org/errata/k12-security.html
   90. http://www.esware.com/actualizaciones.html
   91. http://linuxppc.org/security/advisories/
   92. http://www.linux-mandrake.com/en/fupdates.php3
   93. http://www.redhat.com/support/errata/index.html
   94. http://www.suse.de/security/index.html
   95. http://www.turbolinux.com/security/
   96. http://www.yellowdoglinux.com/resources/
   97. http://www.BSDI.COM/services/support/patches/
   98. http://www.freebsd.org/security/security.html
   99. http://www.NetBSD.ORG/Security/
  100. http://www.openbsd.org/security.html
  101. http://www.calderasystems.com/support/forums/announce.html
  102. http://www.cobalt.com/support/resources/usergroups.html
  103. http://distro.conectiva.com.br/atualizacoes/
  104. http://www.debian.org/MailingLists/subscribe
  105. http://www.esware.com/lista_correo.html
  106. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
  107. http://www.kondara.org/mailinglist.html.en
  108. http://l5web.laser5.co.jp/ml/ml.html
  109. http://www.linuxfromscratch.org/services/mailinglistinfo.php
  110. http://www.linux-mandrake.com/en/flists.php3
  111. http://www.netbsd.org/MailingLists/
  112. http://www.openbsd.org/mail.html
  113. http://www.redhat.com/mailing-lists/
  114. http://www.slackware.com/lists/
  115. http://www.stampede.org/mailinglists.php3
  116. http://www.suse.com/en/support/mailinglists/index.html
  117. http://www.trustix.net/support/
  118. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  119. http://lists.yellowdoglinux.com/ydl_updates.shtml
  120. http://munitions.vipul.net/
  121. http://www.zedz.net/
  122. http://www.cert.org/nav/alerts.html
  123. http://ciac.llnl.gov/ciac/
  124. http://www.MountainWave.com/
  125. http://www.counterpane.com/crypto-gram.html
  126. http://linuxlock.org/
  127. http://linuxsecurity.com/
  128. http://www.securityfocus.com/
  129. http://www.securityportal.com/
  130. http://lwn.net/2002/0418/kernel.php3
  131. http://www.eklektix.com/
  132. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://www.lwn.net/2002/0418/security.php3   Sergey Lentsov   19 Apr 2002 21:20:19 
Архивное /ru.linux/198617401e06d.html, оценка 3 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional