|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 03 Mar 2002 15:38:06 To : All Subject : URL: http://www.lwn.net/2002/0228/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo] [No ads right now]
[LWN.net]
Sections:
[2]Main page
Security
[3]Kernel
[4]Distributions
[5]Development
[6]Commerce
[7]Linux in the news
[8]Announcements
[9]Letters
[10]All in one big page
See also: [11]last week's Security page.
Security
News and Editorials
Toward a common naming system for security vulnerabilities. The
[12]Common Vulnerabilities and Exposures project has been working
since 1999 to create a standard way of talking about security
problems. The problem to be solved is real: one distributor may refer
to a vulnerability in "login," while another fixes a problem with the
PAM libraries. Both are dealing with the same vulnerability, but it
can be hard to tell without taking a detailed look. Even more detailed
descriptions (i.e. "the buffer overflow in wu-ftpd") can be ambiguous.
How is a user to know which problems an update really fixes?
The CVE project steps in by assigning a unique name to each
vulnerability. The full set of vulnerabilities is packaged in a
"freely downloadable" database - you can do almost anything with CVE
except modify it. Last year's mutt format string vulnerability, for
example, is CVE-2001-0473.
The process for creating a CVE entry appears to be long; one must get
a "candidate number" assigned, then wait for a large "editorial board"
to pass judgment on whether a real vulnerability has been described or
not. That process appears to be long; the last Linux-related
vulnerability with a full CVE number is CVE-2001-0489, a format string
vulnerability in gftp which was reported in May, 2001. This is a
problem: time is often of the essence when dealing with security
incidents. During the period in which a security problem is current,
all that is available is an unratified, temporary candidate number.
This slowness is likely to slow the adoption of CVE.
Still, the effort is worthwhile. As we rework our handling of security
vulnerabilities in the near future, we'll look hard at including CVE
identifiers in the database.
Security Reports
Multiple security vulnerabilities in squid. Here is [13]a security
advisory for the Squid proxy server reporting several vulnerabilities
in versions up to and including 2.4.STABLE3. At the minimum, the
vulnerabilities could facilitate denial of service attacks; the
potential for worse also exists. Sites running squid probably should
apply the update sooner rather than later.
Distributor updates seen so far:
* [14]Conectiva (February 27, 2002)
[15]Mandrake (February 21, 2002)
[16]Red Hat (February 26, 2002)
[17]Trustix (February 22, 2002)
IRC connection tracking vulnerability in netfilter. The Netfilter team
has [18]released an advisory warning of a bug in the Linux packet
filtering code. It seems that when connection tracking is used, and a
particular type of IRC connection is made, the firewall can be opened
up to all incoming connections to a particular port for a brief
period. Only certain configurations are vulnerable; see the advisory
for details.
As of this writing, the only distributor update available is from
[19]Red Hat. It is a kernel update, of course, and so should be
applied carefully.
Red Hat security update to ncurses4. Red Hat has issued a security
update to [20]ncurses4 fixing a buffer overrun vulnerability in that
package.
Access control vulnerabilities in gnujsp. The gnujsp Java servlet
[21]has a set of vulnerabilities which make it possible to bypass
access control restrictions on the web server. So far, the only
distributor update we have seen is:
* [22]Debian (February 21, 2002)
Updates
Heap corruption vulnerability in at. The at command has a potentially
exploitable heap corruption bug. (First LWN report:
[23] January 17th).
This week's updates:
* [24]Eridani Linux (February 22, 2002)
Previous updates:
* [25]Debian (January 16, 2002)
[26]Debian (January 18, 2002) (first update did not fix the
problem).
[27]Mandrake (January 18, 2002)
[28]Red Hat (February 7, 2002) (update to the [29]original advisory,
issued January 22, 2002, to fix a Red Hat 6.2 specific problem)
[30]Red Hat (January 22, 2002) Red Hat Linux 7.2 is not vulnerable;
earlier releases are.
[31]Slackware (January 22, 2002)
[32]SuSE (January 16, 2001)
[33]Yellow Dog (January 27, 2002)
Buffer overflow in CUPS. Versions of the Common Unix Print System
prior to 1.1.14 have a buffer overflow vulnerability. (First LWN
report: [34]February 14).
This week's updates:
* [35]SuSE (February 27, 2002)
[36]SuSE (February 23, 2002) (Later [37]withdrawn due to the
introduction of an unrelated bug).
Previous updates:
* [38]Debian (February 13, 2002)
[39]Mandrake (February 15, 2002)
Multiple vulnerabilities in SNMP implementations. Most SNMP
implementations out there have a variety of buffer overflow
vulnerabilities and should be upgraded at first opportunity. See
[40]this CERT advisory for more. (First LWN report: [41]February 14).
This week's updates:
* [42]Eridani Linux (February 22, 2002)
Previous updates:
* [43]Caldera (January 22, 2002)
[44]Conectiva (February 14, 2002)
[45]Debian (February 14, 2002)
[46]Mandrake (February 15, 2002)
[47]Red Hat (February 12, 2002)
[48]Yellow Dog (February 11, 2002)
Resources
Patching the net's fatal flaws (Business Week). Business Week
[49]examines the SNMP vulnerabilities. "So far, the fallout has been
minimal. Major attacks using the SNMP hole have failed to materialize.
That doesn't mean they won't happen, though."
LinuxSecurity.com newsletters. The [50]Linux Advisory Watch and
[51]Linux Security Week newsletters from LinuxSecurity.com are
available.
Events
ICICS 2002 CFP. The 4th International Conference on Information and
Communications Security will be held in Singapore on December 9 to 12.
The Call for papers has gone out; see [52]the ICICS 2002 web page for
details.
Upcoming Security Events.
Date Event Location
February 28 - March 1, 2002 [53]Secure Trusted OS Consortium -
Quarterly Meeting(STOS) (Hyperdigm Research)Chantilly, VA, USA
March 11 - 14, 2002 [54]Financial Cryptography 2002 Sothhampton,
Bermuda
March 18 - 21, 2002 [55]Sixth Annual Distributed Objects and
Components Security Workshop (Pier 5 Hotel at the Inner
Harbor)Baltimore, Maryland, USA
March 18 - 20, 2002 [56]InfoSec World Conference and Expo/2002
Orlando, FL, USA
April 1 - 7, 2002 [57]SANS 2002 Orlando, FL., USA
April 5 - 7, 2002 [58]Rubicon Detroit, Michigan, USA
April 7 - 10, 2002 [59]Techno-Security 2002 Conference Myrtle Beach,
SC
April 14 - 15, 2002 [60]Workshop on Privacy Enhancing Technologies
2002 (Cathedral Hill Hotel)San Francisco, California, USA
April 16 - 19, 2002 [61]The Twelfth Conference on Computers, Freedom &
Privacy (Cathedral Hill Hotel)San Francisco, California, USA
April 23 - 25, 2002 [62]Infosecurity Europe 2002 Olympia, London, UK
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [63]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [64]lwn@lwn.net.
Section Editor: [65]Jonathan Corbet
February 28, 2002
LWN Resources
[66]Security alerts archive
Secured Distributions:
[67]Astaro Security
[68]Blue Linux
[69]Castle
[70]Engarde Secure Linux
[71]Immunix
[72]Kaladix Linux
[73]NSA Security Enhanced
[74]Openwall GNU/Linux
[75]Trustix
Security Projects
[76]Bastille
[77]Linux Security Audit Project
[78]Linux Security Module
[79]OpenSSH
Security List Archives
[80]Bugtraq Archive
[81]Firewall Wizards Archive
[82]ISN Archive
Distribution-specific links
[83]Caldera Advisories
[84]Conectiva Updates
[85]Debian Alerts
[86]Kondara Advisories
[87]Esware Alerts
[88]LinuxPPC Security Updates
[89]Mandrake Updates
[90]Red Hat Errata
[91]SuSE Announcements
[92]Turbolinux
[93]Yellow Dog Errata
BSD-specific links
[94]BSDi
[95]FreeBSD
[96]NetBSD
[97]OpenBSD
Security mailing lists
[98]Caldera
[99]Cobalt
[100]Conectiva
[101]Debian
[102]Esware
[103]FreeBSD
[104]Kondara
[105]LASER5
[106]Linux From Scratch
[107]Linux-Mandrake
[108]NetBSD
[109]OpenBSD
[110]Red Hat
[111]Slackware
[112]Stampede
[113]SuSE
[114]Trustix
[115]turboLinux
[116]Yellow Dog
Security Software Archives
[117]munitions
[118]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[119]CERT
[120]CIAC
[121]Comp Sec News Daily
[122]Crypto-GRAM
[123]LinuxLock.org
[124]LinuxSecurity.com
[125]Security Focus
[126]SecurityPortal
[127]Next: Kernel
[128]Eklektix, Inc. Linux powered! Copyright Л 2002 [129]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://lwn.net/2002/0228/
3. http://lwn.net/2002/0228/kernel.php3
4. http://lwn.net/2002/0228/dists.php3
5. http://lwn.net/2002/0228/devel.php3
6. http://lwn.net/2002/0228/commerce.php3
7. http://lwn.net/2002/0228/press.php3
8. http://lwn.net/2002/0228/announce.php3
9. http://lwn.net/2002/0228/letters.php3
10. http://lwn.net/2002/0228/bigpage.php3
11. http://lwn.net/2002/0221/security.php3
12. http://cve.mitre.org/
13. http://lwn.net/2002/0228/a/squid.php3
14. http://lwn.net/alerts/Conectiva/CLA-2002:464.php3
15. http://lwn.net/alerts/Mandrake/MDKSA-2002:016.php3
16. http://lwn.net/alerts/RedHat/RHSA-2002:029-09.php3
17. http://lwn.net/alerts/Trustix/2002-0031.php3
18. http://lwn.net/2002/0228/a/netfilter-irc.php3
19. http://lwn.net/alerts/RedHat/RHSA-2002:028-13.php3
20. http://lwn.net/alerts/RedHat/RHSA-2002:020-05.php3
21. http://lwn.net/2002/0228/a/gnujsp.php3
22. http://lwn.net/alerts/Debian/DSA-114-1.php3
23. http://lwn.net/2002/0117/security.php3#at
24. http://lwn.net/2002/0228/a/el-sec.php3
25. http://lwn.net/alerts/Debian/DSA-102-1.php3
26. http://lwn.net/alerts/Debian/DSA-102-2.php3
27. http://lwn.net/alerts/Mandrake/MDKSA-2002:007.php3
28. http://lwn.net/alerts/RedHat/RHSA-2002:015-15.php3
29. http://lwn.net/alerts/RedHat/RHSA-2002:015-13.php3
30. http://lwn.net/alerts/RedHat/RHSA-2002:015-13.php3
31. http://lwn.net/alerts/Slackware/sl-1011706104.php3
32. http://lwn.net/alerts/SuSE/SuSE-SA:2002:003.php3
33. http://lwn.net/alerts/YellowDog/YDU-20020127-9.php3
34. http://lwn.net/2002/0214/security.php3#cups
35. http://lwn.net/alerts/SuSE/SuSE-SA:2002:006.php3
36. http://lwn.net/alerts/SuSE/SuSE-SA:2002:005.php3
37. http://lwn.net/2002/0228/a/suse-cups.php3
38. http://lwn.net/alerts/Debian/DSA-110-1.php3
39. http://lwn.net/alerts/Mandrake/MDKSA-2002:015.php3
40. http://lwn.net/2002/0214/a/cert-snmp.php3
41. http://lwn.net/2002/0214/security.php3
42. http://lwn.net/2002/0228/a/el-sec.php3
43. http://lwn.net/alerts/Caldera/CSSA-2002-004.0.php3
44. http://lwn.net/alerts/Conectiva/CLA-2002:462.php3
45. http://lwn.net/alerts/Debian/DSA-111-1.php3
46. http://lwn.net/alerts/Mandrake/MDKSA-2002:014.php3
47. http://lwn.net/alerts/RedHat/RHSA-2001:163-20.php3
48. http://lwn.net/alerts/YellowDog/YDU-20020211-1.php3
49. http://www.businessweek.com/bwdaily/dnflash/feb2002/nf20020220_5030.htm
50. http://lwn.net/2002/0228/a/advisory-watch.php3
51. http://lwn.net/2002/0228/a/security-week.php3
52. http://www.krdl.org.sg/General/conferences/icics/Homepage.html
53. http://www.stosdarwin.org/
54. http://www.fc02.ai/
55. http://www.omg.org/news/meetings/docsec2002/call.htm
56.
http://www.misti.com/northamerica.asp?page=4&subpage=2&disp=showconf&id=os02®
ion=1
57. http://www.sans.org/SANS2002.php
58. http://www.rubi-con.org/
59. http://www.TECHSEC.com/
60. http://www.pet2002.org/
61. http://www.cfp2002.org/
62. http://www.infosec.co.uk/
63. http://securityfocus.com/calendar
64. mailto:lwn@lwn.net
65. mailto:lwn@lwn.net
66. http://lwn.net/alerts/
67. http://www.astaro.com/products/index.html
68. http://bluelinux.sourceforge.net/
69. http://castle.altlinux.ru/
70. http://www.engardelinux.org/
71. http://www.immunix.org/
72. http://www.kaladix.org/
73. http://www.nsa.gov/selinux/
74. http://www.openwall.com/Owl/
75. http://www.trustix.com/
76. http://www.bastille-linux.org/
77. http://lsap.org/
78. http://lsm.immunix.org/
79. http://www.openssh.com/
80. http://www.securityfocus.com/archive/1
81. http://www.nfr.net/firewall-wizards/
82. http://www.jammed.com/Lists/ISN/
83. http://www.calderasystems.com/support/security/
84. http://www.conectiva.com.br/atualizacoes/
85. http://www.debian.org/security/
86. http://www.kondara.org/errata/k12-security.html
87. http://www.esware.com/actualizaciones.html
88. http://linuxppc.org/security/advisories/
89. http://www.linux-mandrake.com/en/fupdates.php3
90. http://www.redhat.com/support/errata/index.html
91. http://www.suse.de/security/index.html
92. http://www.turbolinux.com/security/
93. http://www.yellowdoglinux.com/resources/
94. http://www.BSDI.COM/services/support/patches/
95. http://www.freebsd.org/security/security.html
96. http://www.NetBSD.ORG/Security/
97. http://www.openbsd.org/security.html
98. http://www.calderasystems.com/support/forums/announce.html
99. http://www.cobalt.com/support/resources/usergroups.html
100. http://distro.conectiva.com.br/atualizacoes/
101. http://www.debian.org/MailingLists/subscribe
102. http://www.esware.com/lista_correo.html
103. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
104. http://www.kondara.org/mailinglist.html.en
105. http://l5web.laser5.co.jp/ml/ml.html
106. http://www.linuxfromscratch.org/services/mailinglistinfo.php
107. http://www.linux-mandrake.com/en/flists.php3
108. http://www.netbsd.org/MailingLists/
109. http://www.openbsd.org/mail.html
110. http://www.redhat.com/mailing-lists/
111. http://www.slackware.com/lists/
112. http://www.stampede.org/mailinglists.php3
113. http://www.suse.com/en/support/mailinglists/index.html
114. http://www.trustix.net/support/
115. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
116. http://lists.yellowdoglinux.com/ydl_updates.shtml
117. http://munitions.vipul.net/
118. http://www.zedz.net/
119. http://www.cert.org/nav/alerts.html
120. http://ciac.llnl.gov/ciac/
121. http://www.MountainWave.com/
122. http://www.counterpane.com/crypto-gram.html
123. http://linuxlock.org/
124. http://linuxsecurity.com/
125. http://www.securityfocus.com/
126. http://www.securityportal.com/
127. http://lwn.net/2002/0228/kernel.php3
128. http://www.eklektix.com/
129. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/19861d4d38671.html, оценка из 5, голосов 10
|