Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   16 Aug 2001  16:52:47
 To : All
 Subject : URL: http://www.lwn.net/2001/0816/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] 
    
                                [2]Click Here 
    [LWN.net]
    
    Sections:
     [3]Main page
     Security
     [4]Kernel
     [5]Distributions
     [6]On the Desktop
     [7]Development
     [8]Commerce
     [9]Linux in the news
     [10]Announcements
     [11]Linux History
     [12]Letters
    [13]All in one big page
    
    See also: [14]last week's Security page.
    
 Security
 
 News and Editorials
 
    Warhol worms? Nicholas C Weaver has done [15]a worst-case analysis on
    just how quickly a virulent worm could infect essentially all of the
    vulnerable systems on the net. The answer: 15 minutes. One could
    quibble with the details and assumptions of the analysis, but the
    answer remains the same. A carefully-written worm could propagate
    worldwide in a very short period of time.
    
    This, of course, is a scary result. In 15 minutes, very little can be
    accomplished with things like security alerts, worm analysis, and
    patches. By the time anybody knows there is a problem, it's over.
    
    Some malware writer is sure to see an analysis of this type as a
    challenge; the probability of a high-speed worm in the near future
    seems high. The net, as it stands now, is a frighteningly vulnerable
    place.
    
    The August CRYPTO-GRAM newsletter. Bruce Schneier's [16]CRYPTO-GRAM
    newsletter for August is out. Topics discussed include Code Red and
    the arrest of Dmitry Sklyarov.
    
      The truth is that we all got lucky. Code Red could have been much
      worse. It had full control of every machine it took over; it could
      have been programmed to do anything the author imagined, including
      dropping the entire Internet. It could have spread faster and
      smarter. It could have exploited several vulnerabilities, and not
      just one. It could have been stealthier. It could have been
      polymorphic.
      
    The newsletter also points to [17]a biography of 'Alice' and 'Bob' by
    John Gordon that is well worth a read.
    
      Against all odds, over a noisy telephone line, tapped by the tax
      authorities and the secret police, Alice will happily attempt, with
      someone she doesn't trust, whom she cannot hear clearly, and who is
      probably someone else, to fiddle her tax returns and to organize a
      cout d'etat, while at the same time minimizing the cost of the
      phone call. A coding theorist is someone who doesn't think Alice is
      crazy.
      
 Security Reports
 
    Buffer overrun vulnerabilities in fetchmail. "antirez" (Salvatore
    Sanfilippo) has posted [18]an advisory regarding two buffer overrun
    vulnerabilities in the much-used fetchmail program. Given a hostile
    server, arbitrary code can be run on the system running fetchmail. The
    solution is to upgrade to fetchmail 5.8.17. Distributors have been a
    bit slow in coming out with updates; here's what we have so far.
      * [19]Debian (August 10, 2001)
    
      [20]Progeny (August 14, 2001)
    
    Debian security update to Window Maker. The Debian Project has issued
    [21]a security update to Window Maker fixing a buffer overrun problem
    that could, conceivably, be exploited remotely.
      * [22]Debian (August 12, 2001)
        
      [23]Conectiva (August 13, 2001)
    
      [24]Progeny (August 14, 2001)
    
    Debian groff update. Debian has posted a security advisory for
    [25]groff to address printf format string vulnerabilities. No other
    distributors have yet issued updates for this problem.
    
    Local root vulnerability in TrollFTPD. The TrollFTPD FTP server
    [26]contains a buffer overflow problem which could result in root
    access for local users. The solution is to upgrade to version 1.27 or
    later. Note that the [27]Pure-FTPd server, which is derived from
    TrollFTPD, is not vulnerable to this problem.
    
    web scripts.
    The following web scripts were reported to contain vulnerabilities:
      * A [28]vulnerability exists in the phpBB bulletin board system,
        versions 1.4.0 and earlier, which can allow an attacker to execute
        arbitrary code on the server. Upgrade to 1.4.1 or later to fix the
        problem.
      * NetCode NC Book 0.2b (a perl-based guest book) [29]has a
        vulnerability which allows command execution on the server.
        
    Proprietary products.
    The following proprietary products were reported to contain
    vulnerabilities:
      * Xerox has [30]a firmware upgrade available for N40 printers which,
        it seems, do not handle Code Red scans well. Of course, one could
        question the wisdom of putting a network printer in a place where
        it is exposed to Code Red attacks in the first place.
        
 Updates
 
    Vulnerabilities in Horde IMP Horde IMP has several vulnerabilities
    which are fixed in version 2.2.6; see Bugtraq ID's [31]3066, [32]3079,
    [33]3082, and [34]3083 for more details.
    
    This week's updates:
      * [35]Debian (August 11, 2001)
        
      [36]Progeny (August 14, 2001)
    
    Previous updates:
      * [37]Conectiva (August 2)
      * [38]Caldera (August 2)
        
    Denial of service vulnerability in OpenLDAP This problem was first
    identified in [39]a CERT advisory issued in July, 2001. It was covered
    in the [40]July 19, 2001 LWN security page.
    
    New updates:
      * [41]Debian (August 9, 2001)
        
      [42]Mandrake (August 13, 2001)
    
      [43]Progeny (August 14, 2001)
    
      [44]Red Hat (August 9, 2001)
    
      [45]Yellow Dog (August 10, 2001) Procmail race conditions. See
    [46]the July 26 Security page for the initial report.
    
    This week's updates:
      * [47]Yellow Dog (July 25, 2001)
        
    Previous updates:
      * [48]Red Hat (July 26)
        
    Squid httpd acceleration ACL vulnerability. This vulnerability could
    result in unauthorized access to the squid server. See the [49]July 26
    Security page for details.
    
    This week's updates:
      * [50]Yellow Dog (July 25, 2001)
        
    Previous updates:
      * [51]Caldera (August 9)
      * [52]Linux-Mandrake (August 2)
      * [53]Immunix (July 26)
      * [54]Trustix (July 26)
      * [55]Red Hat (July 26)
        
    Multiple vendor telnetd vulnerability. This vulnerability, originally
    thought to be confined to BSD-derived systems, was first covered in
    the [56]July 26th Security Summary. It is now known that Linux telnet
    daemons are vulnerable as well.
    
    New updates:
      * [57]Caldera (August 10, 2001)
        
      [58]Debian (August 14, 2001) (SSL version)
    
      [59]Debian (August 14, 2001) (Update for Sparc version)
    
      [60]Mandrake (August 13, 2001)
    
      [61]Progeny (August 14, 2001)
    
      [62]Red Hat (August 9, 2001)
    
      [63]Red Hat (August 9, 2001) (kerberos version).
    
      [64]Slackware (August 9, 2001)
    
      [65]Yellow Dog (August 10, 2001)
    
      [66]Yellow Dog (August 10, 2001) (kerberos version). Buffer
    overflows in xloadimage This problem was first covered in the [67]July
    12 Security page.
    
    This week's updates:
      * [68]Debian (August 9, 2001)
        
      [69]Progeny (August 14, 2001)
    
      [70]Yellow Dog (July 25, 2001) Previous updates:
      * [71]Red Hat (July 12)
      * [72]SuSE (July 26)
        
    Yellow Dog catches up. A major flurry of security updates came out for
    the Yellow Dog Linux distribution this week. Many of them were dated
    in July, but didn't hit the net for a while thereafter. Beyond the
    ones mentioned above, the new updates include (with links to the first
    coverage of the vulnerabilities in LWN):
      * [73]gftp (First covered [74]May 3)
      * [75]gnupg ([76]May 3)
      * [77]krb5 ([78]May 24); this is the FTP server vulnerability.
      * [79]imap ([80]March 15)
      * [81]LPRng ([82]June 14).
      * [83]man ([84]May 17)
      * [85]minicom ([86]May 10)
      * [87]samba ([88]June 28).
      * [89]vim ([90]March 29)
      * [91]xinetd ([92]June 14)
        
    Progeny also gets moving. Progeny Linux systems also caught up on its
    security updates this week. Beyond the alerts listed above, we have:
      * [93]openssl (First covered [94]July 12).
      * [95]ssh ([96]June 7).
      * [97]apache ([98]March 8).
      * [99]cfingerd ([100]June 28).
        
 Resources
 
    The Log Analysis mailing list has been [101]announced. This list
    exists for people interested in setting up and using a central logging
    infrastructure; "most of the discussion will focus on the care and
    feeding of syslog"
    
    Linux Advisory Watch. The [102]LinuxSecurity.com Linux Advisory Watch
    for August 10 is out, as is the [103]Linux Security Week Newsletter
    for August 13.
    
    Linux IPsec Gateways Using FreeS/Wan. SecurityFocus has put up [104]a
    beginner's article on setting up FreeS/WAN. "FreeS/WAN has one
    interesting feature that makes it distinct from most other IPsec
    implementations: DES encryption is unsupported. According to the
    FreeS/WAN home page, 'DES is, unfortunately, a mandatory part of the
    IPSEC standard. Despite that, we will not implement DES. We believe it
    is more important to provide security than to comply with a standard
    which has been subverted into allowing weak algorithms.'"
    
    A new system fingerprinting tool. [105]Xprobe is a new operating
    system identification tool by Ofir Arkin and Fyodor Yarochkin. It
    claims more accurate results while needing to send fewer probes to the
    target system; there is also a white paper describing how it all
    works.
    
    Snort 1.8.1 has been [106]released. It contains a number of fixes and
    new features; see the announcement for details.
    
 Events
 
    Upcoming Security Events.
    
    Date Event Location
    August 16 - 17, 2001 [107]10th USENIX Security Symposium 2001
    Conference Washington, D.C.
    September 11 - 13, 2001 [108]New Security Paradigms Workshop
    2001(NSPW) Cloudcroft, New Mexico, USA
    September 28 - 30, 2001 [109]Canadian Association for Security and
    Intelligence Studies(CASIS 2001) (Dalhousie University)Halifax, Nova
    Scotia, Canada.
    
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [110]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [111]lwn@lwn.net.
    
    Section Editor: [112]Jonathan Corbet
    August 16, 2001
    
                               [113]Click Here 
    Secured Distributions:
    [114]Blue Linux
    [115]Engarde Secure Linux
    [116]Immunix
    [117]Kaladix
    [118]NSA Security Enhanced
    [119]Openwall GNU/Linux
    [120]Trustix
    Security Projects
    [121]Bastille
    [122]Linux Security Audit Project
    [123]Linux Security Module
    [124]OpenSSH
    Security List Archives
    [125]Bugtraq Archive
    [126]Firewall Wizards Archive
    [127]ISN Archive
    Distribution-specific links
    [128]Caldera Advisories
    [129]Conectiva Updates
    [130]Debian Alerts
    [131]Kondara Advisories
    [132]Esware Alerts
    [133]LinuxPPC Security Updates
    [134]Mandrake Updates
    [135]Red Hat Errata
    [136]SuSE Announcements
    [137]Yellow Dog Errata
    BSD-specific links
    [138]BSDi
    [139]FreeBSD
    [140]NetBSD
    [141]OpenBSD
    Security mailing lists [142]Caldera
    [143]Cobalt
    [144]Conectiva
    [145]Debian
    [146]Esware
    [147]FreeBSD
    [148]Kondara
    [149]LASER5
    [150]Linux From Scratch
    [151]Linux-Mandrake
    [152]NetBSD
    [153]OpenBSD
    [154]Red Hat
    [155]Slackware
    [156]Stampede
    [157]SuSE
    [158]Trustix
    [159]turboLinux
    [160]Yellow Dog
    Security Software Archives
    [161]munitions
    [162]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [163]CERT
    [164]CIAC
    [165]Comp Sec News Daily
    [166]Crypto-GRAM
    [167]LinuxLock.org
    [168]LinuxSecurity.com
    [169]OpenSEC
    [170]Security Focus
    [171]SecurityPortal
    
    
                                                         [172]Next: Kernel
    
    [173]Eklektix, Inc. Linux powered! Copyright Л 2001 [174]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
    3. http://lwn.net/2001/0816/
    4. http://lwn.net/2001/0816/kernel.php3
    5. http://lwn.net/2001/0816/dists.php3
    6. http://lwn.net/2001/0816/desktop.php3
    7. http://lwn.net/2001/0816/devel.php3
    8. http://lwn.net/2001/0816/commerce.php3
    9. http://lwn.net/2001/0816/press.php3
   10. http://lwn.net/2001/0816/announce.php3
   11. http://lwn.net/2001/0816/history.php3
   12. http://lwn.net/2001/0816/letters.php3
   13. http://lwn.net/2001/0816/bigpage.php3
   14. http://lwn.net/2001/0809/security.php3
   15. http://www.cs.berkeley.edu/~nweaver/warhol.html
   16. http://lwn.net/2001/0816/a/crypto-gram.php3
   17. http://www.conceptlabs.co.uk/alicebob.html
   18. http://lwn.net/2001/0816/a/fetchmail.php3
   19. http://lwn.net/alerts/Debian/DSA-071-1.php3
   20. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-29.php3
   21. http://lwn.net/alerts/Debian/DSA-074-1.php3
   22. http://lwn.net/alerts/Debian/DSA-074-1.php3
   23. http://lwn.net/alerts/Conectiva/CLA-2001:411.php3
   24. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-32.php3
   25. http://lwn.net/alerts/Debian/DSA-072-1.php3
   26. http://lwn.net/2001/0816/a/trollftpd.php3
   27. http://www.pureftpd.org/
   28. http://lwn.net/2001/0816/a/phpbb.php3
   29. http://lwn.net/2001/0816/a/netcode.php3
   30. http://lwn.net/2001/0816/a/xerox.php3
   31. http://www.securityfocus.com/bid/3066
   32. http://www.securityfocus.com/bid/3079
   33. http://www.securityfocus.com/bid/3082
   34. http://www.securityfocus.com/bid/3083
   35. http://lwn.net/alerts/Debian/DSA-073-1.php3
   36. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-28.php3
   37. http://lwn.net/2001/0802/a/con-imp.php3
   38. http://lwn.net/2001/0802/a/caldera-imp.php3
   39. http://lwn.net/2001/0719/a/cert-ldap.php3
   40. http://lwn.net/2001/0719/security.php3#ldap
   41. http://lwn.net/alerts/Debian/DSA-068-1.php3
   42. http://lwn.net/alerts/Mandrake/MDKSA-2001:069.php3
   43. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-30.php3
   44. http://lwn.net/alerts/RedHat/RHSA-2001:098-05.php3
   45. http://lwn.net/alerts/YellowDog/YDU-20010810-3.php3
   46. http://lwn.net/2001/0726/security.php3#procmail
   47. http://lwn.net/alerts/YellowDog/YDU-20010725-12.php3
   48. http://lwn.net/2001/0726/a/rh-procmail.php3
   49. http://lwn.net/2001/0726/security.php3#squid
   50. http://lwn.net/alerts/YellowDog/YDU-20010725-14.php3
   51. http://lwn.net/2001/0809/a/caldera-squid.php3
   52. http://lwn.net/2001/0802/a/lm-squid.php3
   53. http://lwn.net/2001/0726/a/imm-squid.php3
   54. http://lwn.net/2001/0726/a/trustix-squid.php3
   55. http://lwn.net/2001/0726/a/rh-squid.php3
   56. http://lwn.net/2001/0726/security.php3#mtelnetd
   57. http://lwn.net/alerts/Caldera/CSSA-2001-030.0.php3
   58. http://lwn.net/alerts/Debian/DSA-075-1.php3
   59. http://lwn.net/alerts/Debian/DSA.php3
   60. http://lwn.net/alerts/Mandrake/MDKSA-2001:068.php3
   61. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-27.php3
   62. http://lwn.net/alerts/RedHat/RHSA-2001:099-06.php3
   63. http://lwn.net/alerts/RedHat/RHSA-2001:100-02.php3
   64. http://lwn.net/alerts/Slackware/sl-997726350.php3
   65. http://lwn.net/alerts/YellowDog/YDU-20010810-1.php3
   66. http://lwn.net/alerts/YellowDog/YDU-20010810-2.php3
   67. http://lwn.net/2001/0712/security.php3#xloadimage
   68. http://lwn.net/alerts/Debian/DSA-069-1.php3
   69. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-31.php3
   70. http://lwn.net/alerts/YellowDog/YDU-20010725-11.php3
   71. http://lwn.net/2001/0712/a/rh-xloadimage.php3
   72. http://lwn.net/2001/0726/a/suse-xli.php3
   73. http://lwn.net/alerts/YellowDog/YDU-20010725-2.php3
   74. http://lwn.net/2001/0503/security.php3#gftp
   75. http://lwn.net/alerts/YellowDog/YDU-20010725-6.php3
   76. http://lwn.net/2001/0503/security.php3#gnupg1.0.5
   77. http://lwn.net/alerts/YellowDog/YDU-20010725-4.php3
   78. http://lwn.net/2001/0524/security.php3#kerberosftp
   79. http://lwn.net/alerts/YellowDog/YDU-20010725-15.php3
   80. http://lwn.net/2001/0315/security.php3#imap
   81. http://lwn.net/alerts/YellowDog/YDU-20010725-7.php3
   82. http://lwn.net/2001/0614/security.php3#lprng
   83. http://lwn.net/alerts/YellowDog/YDU-20010725-5.php3
   84. http://lwn.net/2001/0517/security.php3#manheap
   85. http://lwn.net/alerts/YellowDog/YDU-20010725-3.php3
   86. http://lwn.net/2001/0510/security.php3#minicom
   87. http://lwn.net/alerts/YellowDog/YDU-20010725-8.php3
   88. http://lwn.net/2001/0628/security.php3#sambamacro
   89. http://lwn.net/alerts/YellowDog/YDU-20010725-13.php3
   90. http://lwn.net/2001/0329/security.php3#vim
   91. http://lwn.net/alerts/YellowDog/YDU-20010725-10.php3
   92. http://lwn.net/2001/0614/security.php3#xinetdbo
   93. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-23.php3
   94. http://lwn.net/2001/0712/security.php3#openssl
   95. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-24.php3
   96. http://lwn.net/2001/0607/security.php3#opensshtmplink
   97. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-25.php3
   98. http://lwn.net/2001/0308/security.php3#apache
   99. http://lwn.net/alerts/Progeny/PROGENY-SA-2001-26.php3
  100. http://lwn.net/2001/0628/security.php3#cfingerd
  101. http://lwn.net/2001/0816/a/loganalysis.php3
  102. http://lwn.net/2001/0816/a/advisory-watch.php3
  103. http://lwn.net/2001/0816/a/security-week.php3
  104.
 http://securityfocus.com/frames/?focus=linux&content=/focus/linux/articles/ipsec
 gateway.html
  105. http://lwn.net/2001/0816/a/xprobe.php3
  106. http://lwn.net/2001/0816/a/snort.php3
  107. http://www.usenix.org/events/sec2001
  108. http://www.nspw.org/
  109. http://www.sfu.ca/igs/CASIS/
  110. http://securityfocus.com/calendar
  111. mailto:lwn@lwn.net
  112. mailto:lwn@lwn.net
  113. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
  114. http://bluelinux.sourceforge.net/
  115. http://www.engardelinux.org/
  116. http://www.immunix.org/
  117. http://www.maganation.com/~kaladix/
  118. http://www.nsa.gov/selinux/
  119. http://www.openwall.com/Owl/
  120. http://www.trustix.com/
  121. http://www.bastille-linux.org/
  122. http://lsap.org/
  123. http://lsm.immunix.org/
  124. http://www.openssh.com/
  125. http://www.securityfocus.com/bugtraq/archive/
  126. http://www.nfr.net/firewall-wizards/
  127. http://www.jammed.com/Lists/ISN/
  128. http://www.calderasystems.com/support/security/
  129. http://www.conectiva.com.br/atualizacoes/
  130. http://www.debian.org/security/
  131. http://www.kondara.org/errata/k12-security.html
  132. http://www.esware.com/actualizaciones.html
  133. http://linuxppc.org/security/advisories/
  134. http://www.linux-mandrake.com/en/fupdates.php3
  135. http://www.redhat.com/support/errata/index.html
  136. http://www.suse.de/security/index.html
  137. http://www.yellowdoglinux.com/resources/errata.shtml
  138. http://www.BSDI.COM/services/support/patches/
  139. http://www.freebsd.org/security/security.html
  140. http://www.NetBSD.ORG/Security/
  141. http://www.openbsd.org/security.html
  142. http://www.calderasystems.com/support/forums/announce.html
  143. http://www.cobalt.com/support/resources/usergroups.html
  144. http://distro.conectiva.com.br/atualizacoes/
  145. http://www.debian.org/MailingLists/subscribe
  146. http://www.esware.com/lista_correo.html
  147. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
  148. http://www.kondara.org/mailinglist.html.en
  149. http://l5web.laser5.co.jp/ml/ml.html
  150. http://www.linuxfromscratch.org/services/mailinglistinfo.php
  151. http://www.linux-mandrake.com/en/flists.php3
  152. http://www.netbsd.org/MailingLists/
  153. http://www.openbsd.org/mail.html
  154. http://www.redhat.com/mailing-lists/
  155. http://www.slackware.com/lists/
  156. http://www.stampede.org/mailinglists.php3
  157. http://www.suse.com/en/support/mailinglists/index.html
  158. http://www.trustix.net/support/
  159. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  160. http://lists.yellowdoglinux.com/ydl_updates.shtml
  161. http://munitions.vipul.net/
  162. http://www.zedz.net/
  163. http://www.cert.org/nav/alerts.html
  164. http://ciac.llnl.gov/ciac/
  165. http://www.MountainWave.com/
  166. http://www.counterpane.com/crypto-gram.html
  167. http://linuxlock.org/
  168. http://linuxsecurity.com/
  169. http://www.opensec.net/
  170. http://www.securityfocus.com/
  171. http://www.securityportal.com/
  172. http://lwn.net/2001/0816/kernel.php3
  173. http://www.eklektix.com/
  174. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://www.lwn.net/2001/0816/security.php3   Sergey Lentsov   16 Aug 2001 16:52:47 
Архивное /ru.linux/19861cd023ecf.html, оценка 3 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional