|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 16 Aug 2001 16:52:47 To : All Subject : URL: http://www.lwn.net/2001/0816/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo]
[2]Click Here
[LWN.net]
Sections:
[3]Main page
Security
[4]Kernel
[5]Distributions
[6]On the Desktop
[7]Development
[8]Commerce
[9]Linux in the news
[10]Announcements
[11]Linux History
[12]Letters
[13]All in one big page
See also: [14]last week's Security page.
Security
News and Editorials
Warhol worms? Nicholas C Weaver has done [15]a worst-case analysis on
just how quickly a virulent worm could infect essentially all of the
vulnerable systems on the net. The answer: 15 minutes. One could
quibble with the details and assumptions of the analysis, but the
answer remains the same. A carefully-written worm could propagate
worldwide in a very short period of time.
This, of course, is a scary result. In 15 minutes, very little can be
accomplished with things like security alerts, worm analysis, and
patches. By the time anybody knows there is a problem, it's over.
Some malware writer is sure to see an analysis of this type as a
challenge; the probability of a high-speed worm in the near future
seems high. The net, as it stands now, is a frighteningly vulnerable
place.
The August CRYPTO-GRAM newsletter. Bruce Schneier's [16]CRYPTO-GRAM
newsletter for August is out. Topics discussed include Code Red and
the arrest of Dmitry Sklyarov.
The truth is that we all got lucky. Code Red could have been much
worse. It had full control of every machine it took over; it could
have been programmed to do anything the author imagined, including
dropping the entire Internet. It could have spread faster and
smarter. It could have exploited several vulnerabilities, and not
just one. It could have been stealthier. It could have been
polymorphic.
The newsletter also points to [17]a biography of 'Alice' and 'Bob' by
John Gordon that is well worth a read.
Against all odds, over a noisy telephone line, tapped by the tax
authorities and the secret police, Alice will happily attempt, with
someone she doesn't trust, whom she cannot hear clearly, and who is
probably someone else, to fiddle her tax returns and to organize a
cout d'etat, while at the same time minimizing the cost of the
phone call. A coding theorist is someone who doesn't think Alice is
crazy.
Security Reports
Buffer overrun vulnerabilities in fetchmail. "antirez" (Salvatore
Sanfilippo) has posted [18]an advisory regarding two buffer overrun
vulnerabilities in the much-used fetchmail program. Given a hostile
server, arbitrary code can be run on the system running fetchmail. The
solution is to upgrade to fetchmail 5.8.17. Distributors have been a
bit slow in coming out with updates; here's what we have so far.
* [19]Debian (August 10, 2001)
[20]Progeny (August 14, 2001)
Debian security update to Window Maker. The Debian Project has issued
[21]a security update to Window Maker fixing a buffer overrun problem
that could, conceivably, be exploited remotely.
* [22]Debian (August 12, 2001)
[23]Conectiva (August 13, 2001)
[24]Progeny (August 14, 2001)
Debian groff update. Debian has posted a security advisory for
[25]groff to address printf format string vulnerabilities. No other
distributors have yet issued updates for this problem.
Local root vulnerability in TrollFTPD. The TrollFTPD FTP server
[26]contains a buffer overflow problem which could result in root
access for local users. The solution is to upgrade to version 1.27 or
later. Note that the [27]Pure-FTPd server, which is derived from
TrollFTPD, is not vulnerable to this problem.
web scripts.
The following web scripts were reported to contain vulnerabilities:
* A [28]vulnerability exists in the phpBB bulletin board system,
versions 1.4.0 and earlier, which can allow an attacker to execute
arbitrary code on the server. Upgrade to 1.4.1 or later to fix the
problem.
* NetCode NC Book 0.2b (a perl-based guest book) [29]has a
vulnerability which allows command execution on the server.
Proprietary products.
The following proprietary products were reported to contain
vulnerabilities:
* Xerox has [30]a firmware upgrade available for N40 printers which,
it seems, do not handle Code Red scans well. Of course, one could
question the wisdom of putting a network printer in a place where
it is exposed to Code Red attacks in the first place.
Updates
Vulnerabilities in Horde IMP Horde IMP has several vulnerabilities
which are fixed in version 2.2.6; see Bugtraq ID's [31]3066, [32]3079,
[33]3082, and [34]3083 for more details.
This week's updates:
* [35]Debian (August 11, 2001)
[36]Progeny (August 14, 2001)
Previous updates:
* [37]Conectiva (August 2)
* [38]Caldera (August 2)
Denial of service vulnerability in OpenLDAP This problem was first
identified in [39]a CERT advisory issued in July, 2001. It was covered
in the [40]July 19, 2001 LWN security page.
New updates:
* [41]Debian (August 9, 2001)
[42]Mandrake (August 13, 2001)
[43]Progeny (August 14, 2001)
[44]Red Hat (August 9, 2001)
[45]Yellow Dog (August 10, 2001) Procmail race conditions. See
[46]the July 26 Security page for the initial report.
This week's updates:
* [47]Yellow Dog (July 25, 2001)
Previous updates:
* [48]Red Hat (July 26)
Squid httpd acceleration ACL vulnerability. This vulnerability could
result in unauthorized access to the squid server. See the [49]July 26
Security page for details.
This week's updates:
* [50]Yellow Dog (July 25, 2001)
Previous updates:
* [51]Caldera (August 9)
* [52]Linux-Mandrake (August 2)
* [53]Immunix (July 26)
* [54]Trustix (July 26)
* [55]Red Hat (July 26)
Multiple vendor telnetd vulnerability. This vulnerability, originally
thought to be confined to BSD-derived systems, was first covered in
the [56]July 26th Security Summary. It is now known that Linux telnet
daemons are vulnerable as well.
New updates:
* [57]Caldera (August 10, 2001)
[58]Debian (August 14, 2001) (SSL version)
[59]Debian (August 14, 2001) (Update for Sparc version)
[60]Mandrake (August 13, 2001)
[61]Progeny (August 14, 2001)
[62]Red Hat (August 9, 2001)
[63]Red Hat (August 9, 2001) (kerberos version).
[64]Slackware (August 9, 2001)
[65]Yellow Dog (August 10, 2001)
[66]Yellow Dog (August 10, 2001) (kerberos version). Buffer
overflows in xloadimage This problem was first covered in the [67]July
12 Security page.
This week's updates:
* [68]Debian (August 9, 2001)
[69]Progeny (August 14, 2001)
[70]Yellow Dog (July 25, 2001) Previous updates:
* [71]Red Hat (July 12)
* [72]SuSE (July 26)
Yellow Dog catches up. A major flurry of security updates came out for
the Yellow Dog Linux distribution this week. Many of them were dated
in July, but didn't hit the net for a while thereafter. Beyond the
ones mentioned above, the new updates include (with links to the first
coverage of the vulnerabilities in LWN):
* [73]gftp (First covered [74]May 3)
* [75]gnupg ([76]May 3)
* [77]krb5 ([78]May 24); this is the FTP server vulnerability.
* [79]imap ([80]March 15)
* [81]LPRng ([82]June 14).
* [83]man ([84]May 17)
* [85]minicom ([86]May 10)
* [87]samba ([88]June 28).
* [89]vim ([90]March 29)
* [91]xinetd ([92]June 14)
Progeny also gets moving. Progeny Linux systems also caught up on its
security updates this week. Beyond the alerts listed above, we have:
* [93]openssl (First covered [94]July 12).
* [95]ssh ([96]June 7).
* [97]apache ([98]March 8).
* [99]cfingerd ([100]June 28).
Resources
The Log Analysis mailing list has been [101]announced. This list
exists for people interested in setting up and using a central logging
infrastructure; "most of the discussion will focus on the care and
feeding of syslog"
Linux Advisory Watch. The [102]LinuxSecurity.com Linux Advisory Watch
for August 10 is out, as is the [103]Linux Security Week Newsletter
for August 13.
Linux IPsec Gateways Using FreeS/Wan. SecurityFocus has put up [104]a
beginner's article on setting up FreeS/WAN. "FreeS/WAN has one
interesting feature that makes it distinct from most other IPsec
implementations: DES encryption is unsupported. According to the
FreeS/WAN home page, 'DES is, unfortunately, a mandatory part of the
IPSEC standard. Despite that, we will not implement DES. We believe it
is more important to provide security than to comply with a standard
which has been subverted into allowing weak algorithms.'"
A new system fingerprinting tool. [105]Xprobe is a new operating
system identification tool by Ofir Arkin and Fyodor Yarochkin. It
claims more accurate results while needing to send fewer probes to the
target system; there is also a white paper describing how it all
works.
Snort 1.8.1 has been [106]released. It contains a number of fixes and
new features; see the announcement for details.
Events
Upcoming Security Events.
Date Event Location
August 16 - 17, 2001 [107]10th USENIX Security Symposium 2001
Conference Washington, D.C.
September 11 - 13, 2001 [108]New Security Paradigms Workshop
2001(NSPW) Cloudcroft, New Mexico, USA
September 28 - 30, 2001 [109]Canadian Association for Security and
Intelligence Studies(CASIS 2001) (Dalhousie University)Halifax, Nova
Scotia, Canada.
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [110]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [111]lwn@lwn.net.
Section Editor: [112]Jonathan Corbet
August 16, 2001
[113]Click Here
Secured Distributions:
[114]Blue Linux
[115]Engarde Secure Linux
[116]Immunix
[117]Kaladix
[118]NSA Security Enhanced
[119]Openwall GNU/Linux
[120]Trustix
Security Projects
[121]Bastille
[122]Linux Security Audit Project
[123]Linux Security Module
[124]OpenSSH
Security List Archives
[125]Bugtraq Archive
[126]Firewall Wizards Archive
[127]ISN Archive
Distribution-specific links
[128]Caldera Advisories
[129]Conectiva Updates
[130]Debian Alerts
[131]Kondara Advisories
[132]Esware Alerts
[133]LinuxPPC Security Updates
[134]Mandrake Updates
[135]Red Hat Errata
[136]SuSE Announcements
[137]Yellow Dog Errata
BSD-specific links
[138]BSDi
[139]FreeBSD
[140]NetBSD
[141]OpenBSD
Security mailing lists [142]Caldera
[143]Cobalt
[144]Conectiva
[145]Debian
[146]Esware
[147]FreeBSD
[148]Kondara
[149]LASER5
[150]Linux From Scratch
[151]Linux-Mandrake
[152]NetBSD
[153]OpenBSD
[154]Red Hat
[155]Slackware
[156]Stampede
[157]SuSE
[158]Trustix
[159]turboLinux
[160]Yellow Dog
Security Software Archives
[161]munitions
[162]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[163]CERT
[164]CIAC
[165]Comp Sec News Daily
[166]Crypto-GRAM
[167]LinuxLock.org
[168]LinuxSecurity.com
[169]OpenSEC
[170]Security Focus
[171]SecurityPortal
[172]Next: Kernel
[173]Eklektix, Inc. Linux powered! Copyright Л 2001 [174]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
3. http://lwn.net/2001/0816/
4. http://lwn.net/2001/0816/kernel.php3
5. http://lwn.net/2001/0816/dists.php3
6. http://lwn.net/2001/0816/desktop.php3
7. http://lwn.net/2001/0816/devel.php3
8. http://lwn.net/2001/0816/commerce.php3
9. http://lwn.net/2001/0816/press.php3
10. http://lwn.net/2001/0816/announce.php3
11. http://lwn.net/2001/0816/history.php3
12. http://lwn.net/2001/0816/letters.php3
13. http://lwn.net/2001/0816/bigpage.php3
14. http://lwn.net/2001/0809/security.php3
15. http://www.cs.berkeley.edu/~nweaver/warhol.html
16. http://lwn.net/2001/0816/a/crypto-gram.php3
17. http://www.conceptlabs.co.uk/alicebob.html
18. http://lwn.net/2001/0816/a/fetchmail.php3
19. http://lwn.net/alerts/Debian/DSA-071-1.php3
20. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-29.php3
21. http://lwn.net/alerts/Debian/DSA-074-1.php3
22. http://lwn.net/alerts/Debian/DSA-074-1.php3
23. http://lwn.net/alerts/Conectiva/CLA-2001:411.php3
24. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-32.php3
25. http://lwn.net/alerts/Debian/DSA-072-1.php3
26. http://lwn.net/2001/0816/a/trollftpd.php3
27. http://www.pureftpd.org/
28. http://lwn.net/2001/0816/a/phpbb.php3
29. http://lwn.net/2001/0816/a/netcode.php3
30. http://lwn.net/2001/0816/a/xerox.php3
31. http://www.securityfocus.com/bid/3066
32. http://www.securityfocus.com/bid/3079
33. http://www.securityfocus.com/bid/3082
34. http://www.securityfocus.com/bid/3083
35. http://lwn.net/alerts/Debian/DSA-073-1.php3
36. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-28.php3
37. http://lwn.net/2001/0802/a/con-imp.php3
38. http://lwn.net/2001/0802/a/caldera-imp.php3
39. http://lwn.net/2001/0719/a/cert-ldap.php3
40. http://lwn.net/2001/0719/security.php3#ldap
41. http://lwn.net/alerts/Debian/DSA-068-1.php3
42. http://lwn.net/alerts/Mandrake/MDKSA-2001:069.php3
43. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-30.php3
44. http://lwn.net/alerts/RedHat/RHSA-2001:098-05.php3
45. http://lwn.net/alerts/YellowDog/YDU-20010810-3.php3
46. http://lwn.net/2001/0726/security.php3#procmail
47. http://lwn.net/alerts/YellowDog/YDU-20010725-12.php3
48. http://lwn.net/2001/0726/a/rh-procmail.php3
49. http://lwn.net/2001/0726/security.php3#squid
50. http://lwn.net/alerts/YellowDog/YDU-20010725-14.php3
51. http://lwn.net/2001/0809/a/caldera-squid.php3
52. http://lwn.net/2001/0802/a/lm-squid.php3
53. http://lwn.net/2001/0726/a/imm-squid.php3
54. http://lwn.net/2001/0726/a/trustix-squid.php3
55. http://lwn.net/2001/0726/a/rh-squid.php3
56. http://lwn.net/2001/0726/security.php3#mtelnetd
57. http://lwn.net/alerts/Caldera/CSSA-2001-030.0.php3
58. http://lwn.net/alerts/Debian/DSA-075-1.php3
59. http://lwn.net/alerts/Debian/DSA.php3
60. http://lwn.net/alerts/Mandrake/MDKSA-2001:068.php3
61. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-27.php3
62. http://lwn.net/alerts/RedHat/RHSA-2001:099-06.php3
63. http://lwn.net/alerts/RedHat/RHSA-2001:100-02.php3
64. http://lwn.net/alerts/Slackware/sl-997726350.php3
65. http://lwn.net/alerts/YellowDog/YDU-20010810-1.php3
66. http://lwn.net/alerts/YellowDog/YDU-20010810-2.php3
67. http://lwn.net/2001/0712/security.php3#xloadimage
68. http://lwn.net/alerts/Debian/DSA-069-1.php3
69. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-31.php3
70. http://lwn.net/alerts/YellowDog/YDU-20010725-11.php3
71. http://lwn.net/2001/0712/a/rh-xloadimage.php3
72. http://lwn.net/2001/0726/a/suse-xli.php3
73. http://lwn.net/alerts/YellowDog/YDU-20010725-2.php3
74. http://lwn.net/2001/0503/security.php3#gftp
75. http://lwn.net/alerts/YellowDog/YDU-20010725-6.php3
76. http://lwn.net/2001/0503/security.php3#gnupg1.0.5
77. http://lwn.net/alerts/YellowDog/YDU-20010725-4.php3
78. http://lwn.net/2001/0524/security.php3#kerberosftp
79. http://lwn.net/alerts/YellowDog/YDU-20010725-15.php3
80. http://lwn.net/2001/0315/security.php3#imap
81. http://lwn.net/alerts/YellowDog/YDU-20010725-7.php3
82. http://lwn.net/2001/0614/security.php3#lprng
83. http://lwn.net/alerts/YellowDog/YDU-20010725-5.php3
84. http://lwn.net/2001/0517/security.php3#manheap
85. http://lwn.net/alerts/YellowDog/YDU-20010725-3.php3
86. http://lwn.net/2001/0510/security.php3#minicom
87. http://lwn.net/alerts/YellowDog/YDU-20010725-8.php3
88. http://lwn.net/2001/0628/security.php3#sambamacro
89. http://lwn.net/alerts/YellowDog/YDU-20010725-13.php3
90. http://lwn.net/2001/0329/security.php3#vim
91. http://lwn.net/alerts/YellowDog/YDU-20010725-10.php3
92. http://lwn.net/2001/0614/security.php3#xinetdbo
93. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-23.php3
94. http://lwn.net/2001/0712/security.php3#openssl
95. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-24.php3
96. http://lwn.net/2001/0607/security.php3#opensshtmplink
97. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-25.php3
98. http://lwn.net/2001/0308/security.php3#apache
99. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-26.php3
100. http://lwn.net/2001/0628/security.php3#cfingerd
101. http://lwn.net/2001/0816/a/loganalysis.php3
102. http://lwn.net/2001/0816/a/advisory-watch.php3
103. http://lwn.net/2001/0816/a/security-week.php3
104.
http://securityfocus.com/frames/?focus=linux&content=/focus/linux/articles/ipsec
gateway.html
105. http://lwn.net/2001/0816/a/xprobe.php3
106. http://lwn.net/2001/0816/a/snort.php3
107. http://www.usenix.org/events/sec2001
108. http://www.nspw.org/
109. http://www.sfu.ca/igs/CASIS/
110. http://securityfocus.com/calendar
111. mailto:lwn@lwn.net
112. mailto:lwn@lwn.net
113. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
114. http://bluelinux.sourceforge.net/
115. http://www.engardelinux.org/
116. http://www.immunix.org/
117. http://www.maganation.com/~kaladix/
118. http://www.nsa.gov/selinux/
119. http://www.openwall.com/Owl/
120. http://www.trustix.com/
121. http://www.bastille-linux.org/
122. http://lsap.org/
123. http://lsm.immunix.org/
124. http://www.openssh.com/
125. http://www.securityfocus.com/bugtraq/archive/
126. http://www.nfr.net/firewall-wizards/
127. http://www.jammed.com/Lists/ISN/
128. http://www.calderasystems.com/support/security/
129. http://www.conectiva.com.br/atualizacoes/
130. http://www.debian.org/security/
131. http://www.kondara.org/errata/k12-security.html
132. http://www.esware.com/actualizaciones.html
133. http://linuxppc.org/security/advisories/
134. http://www.linux-mandrake.com/en/fupdates.php3
135. http://www.redhat.com/support/errata/index.html
136. http://www.suse.de/security/index.html
137. http://www.yellowdoglinux.com/resources/errata.shtml
138. http://www.BSDI.COM/services/support/patches/
139. http://www.freebsd.org/security/security.html
140. http://www.NetBSD.ORG/Security/
141. http://www.openbsd.org/security.html
142. http://www.calderasystems.com/support/forums/announce.html
143. http://www.cobalt.com/support/resources/usergroups.html
144. http://distro.conectiva.com.br/atualizacoes/
145. http://www.debian.org/MailingLists/subscribe
146. http://www.esware.com/lista_correo.html
147. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
148. http://www.kondara.org/mailinglist.html.en
149. http://l5web.laser5.co.jp/ml/ml.html
150. http://www.linuxfromscratch.org/services/mailinglistinfo.php
151. http://www.linux-mandrake.com/en/flists.php3
152. http://www.netbsd.org/MailingLists/
153. http://www.openbsd.org/mail.html
154. http://www.redhat.com/mailing-lists/
155. http://www.slackware.com/lists/
156. http://www.stampede.org/mailinglists.php3
157. http://www.suse.com/en/support/mailinglists/index.html
158. http://www.trustix.net/support/
159. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
160. http://lists.yellowdoglinux.com/ydl_updates.shtml
161. http://munitions.vipul.net/
162. http://www.zedz.net/
163. http://www.cert.org/nav/alerts.html
164. http://ciac.llnl.gov/ciac/
165. http://www.MountainWave.com/
166. http://www.counterpane.com/crypto-gram.html
167. http://linuxlock.org/
168. http://linuxsecurity.com/
169. http://www.opensec.net/
170. http://www.securityfocus.com/
171. http://www.securityportal.com/
172. http://lwn.net/2001/0816/kernel.php3
173. http://www.eklektix.com/
174. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/19861cd023ecf.html, оценка из 5, голосов 10
|