Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   03 Mar 2002  15:38:06
 To : All
 Subject : URL: http://www.lwn.net/2002/0228/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] [No ads right now]
    [LWN.net]
 
    Sections:
     [2]Main page
     Security
     [3]Kernel
     [4]Distributions
     [5]Development
     [6]Commerce
     [7]Linux in the news
     [8]Announcements
     [9]Letters
    [10]All in one big page
 
    See also: [11]last week's Security page.
 
 Security
 
 News and Editorials
 
    Toward a common naming system for security vulnerabilities. The
    [12]Common Vulnerabilities and Exposures project has been working
    since 1999 to create a standard way of talking about security
    problems. The problem to be solved is real: one distributor may refer
    to a vulnerability in "login," while another fixes a problem with the
    PAM libraries. Both are dealing with the same vulnerability, but it
    can be hard to tell without taking a detailed look. Even more detailed
    descriptions (i.e. "the buffer overflow in wu-ftpd") can be ambiguous.
    How is a user to know which problems an update really fixes?
 
    The CVE project steps in by assigning a unique name to each
    vulnerability. The full set of vulnerabilities is packaged in a
    "freely downloadable" database - you can do almost anything with CVE
    except modify it. Last year's mutt format string vulnerability, for
    example, is CVE-2001-0473.
 
    The process for creating a CVE entry appears to be long; one must get
    a "candidate number" assigned, then wait for a large "editorial board"
    to pass judgment on whether a real vulnerability has been described or
    not. That process appears to be long; the last Linux-related
    vulnerability with a full CVE number is CVE-2001-0489, a format string
    vulnerability in gftp which was reported in May, 2001. This is a
    problem: time is often of the essence when dealing with security
    incidents. During the period in which a security problem is current,
    all that is available is an unratified, temporary candidate number.
    This slowness is likely to slow the adoption of CVE.
 
    Still, the effort is worthwhile. As we rework our handling of security
    vulnerabilities in the near future, we'll look hard at including CVE
    identifiers in the database.
 
 Security Reports
 
    Multiple security vulnerabilities in squid. Here is [13]a security
    advisory for the Squid proxy server reporting several vulnerabilities
    in versions up to and including 2.4.STABLE3. At the minimum, the
    vulnerabilities could facilitate denial of service attacks; the
    potential for worse also exists. Sites running squid probably should
    apply the update sooner rather than later.
 
    Distributor updates seen so far:
      * [14]Conectiva (February 27, 2002)
 
      [15]Mandrake (February 21, 2002)
 
      [16]Red Hat (February 26, 2002)
 
      [17]Trustix (February 22, 2002)
 
    IRC connection tracking vulnerability in netfilter. The Netfilter team
    has [18]released an advisory warning of a bug in the Linux packet
    filtering code. It seems that when connection tracking is used, and a
    particular type of IRC connection is made, the firewall can be opened
    up to all incoming connections to a particular port for a brief
    period. Only certain configurations are vulnerable; see the advisory
    for details.
 
    As of this writing, the only distributor update available is from
    [19]Red Hat. It is a kernel update, of course, and so should be
    applied carefully.
 
    Red Hat security update to ncurses4. Red Hat has issued a security
    update to [20]ncurses4 fixing a buffer overrun vulnerability in that
    package.
 
    Access control vulnerabilities in gnujsp. The gnujsp Java servlet
    [21]has a set of vulnerabilities which make it possible to bypass
    access control restrictions on the web server. So far, the only
    distributor update we have seen is:
      * [22]Debian (February 21, 2002)
 
 Updates
 
    Heap corruption vulnerability in at. The at command has a potentially
    exploitable heap corruption bug. (First LWN report:
    [23] January 17th).
 
    This week's updates:
      * [24]Eridani Linux (February 22, 2002)
 
    Previous updates:
      * [25]Debian (January 16, 2002)
 
      [26]Debian (January 18, 2002) (first update did not fix the
    problem).
 
      [27]Mandrake (January 18, 2002)
 
      [28]Red Hat (February 7, 2002) (update to the [29]original advisory,
    issued January 22, 2002, to fix a Red Hat 6.2 specific problem)
 
      [30]Red Hat (January 22, 2002) Red Hat Linux 7.2 is not vulnerable;
    earlier releases are.
 
      [31]Slackware (January 22, 2002)
 
      [32]SuSE (January 16, 2001)
 
      [33]Yellow Dog (January 27, 2002)
 
    Buffer overflow in CUPS. Versions of the Common Unix Print System
    prior to 1.1.14 have a buffer overflow vulnerability. (First LWN
    report: [34]February 14).
 
    This week's updates:
      * [35]SuSE (February 27, 2002)
 
      [36]SuSE (February 23, 2002) (Later [37]withdrawn due to the
    introduction of an unrelated bug).
 
    Previous updates:
      * [38]Debian (February 13, 2002)
 
      [39]Mandrake (February 15, 2002)
 
    Multiple vulnerabilities in SNMP implementations. Most SNMP
    implementations out there have a variety of buffer overflow
    vulnerabilities and should be upgraded at first opportunity. See
    [40]this CERT advisory for more. (First LWN report: [41]February 14).
 
    This week's updates:
      * [42]Eridani Linux (February 22, 2002)
 
    Previous updates:
      * [43]Caldera (January 22, 2002)
 
      [44]Conectiva (February 14, 2002)
 
      [45]Debian (February 14, 2002)
 
      [46]Mandrake (February 15, 2002)
 
      [47]Red Hat (February 12, 2002)
 
      [48]Yellow Dog (February 11, 2002)
 
 Resources
 
    Patching the net's fatal flaws (Business Week). Business Week
    [49]examines the SNMP vulnerabilities. "So far, the fallout has been
    minimal. Major attacks using the SNMP hole have failed to materialize.
    That doesn't mean they won't happen, though."
 
    LinuxSecurity.com newsletters. The [50]Linux Advisory Watch and
    [51]Linux Security Week newsletters from LinuxSecurity.com are
    available.
 
 Events
 
    ICICS 2002 CFP. The 4th International Conference on Information and
    Communications Security will be held in Singapore on December 9 to 12.
    The Call for papers has gone out; see [52]the ICICS 2002 web page for
    details.
 
    Upcoming Security Events.
 
    Date Event Location
    February 28 - March 1, 2002 [53]Secure Trusted OS Consortium -
    Quarterly Meeting(STOS) (Hyperdigm Research)Chantilly, VA, USA
    March 11 - 14, 2002 [54]Financial Cryptography 2002 Sothhampton,
    Bermuda
    March 18 - 21, 2002 [55]Sixth Annual Distributed Objects and
    Components Security Workshop (Pier 5 Hotel at the Inner
    Harbor)Baltimore, Maryland, USA
    March 18 - 20, 2002 [56]InfoSec World Conference and Expo/2002
    Orlando, FL, USA
    April 1 - 7, 2002 [57]SANS 2002 Orlando, FL., USA
    April 5 - 7, 2002 [58]Rubicon Detroit, Michigan, USA
    April 7 - 10, 2002 [59]Techno-Security 2002 Conference Myrtle Beach,
    SC
    April 14 - 15, 2002 [60]Workshop on Privacy Enhancing Technologies
    2002 (Cathedral Hill Hotel)San Francisco, California, USA
    April 16 - 19, 2002 [61]The Twelfth Conference on Computers, Freedom &
    Privacy (Cathedral Hill Hotel)San Francisco, California, USA
    April 23 - 25, 2002 [62]Infosecurity Europe 2002 Olympia, London, UK
 
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [63]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [64]lwn@lwn.net.
 
    Section Editor: [65]Jonathan Corbet
    February 28, 2002
 
    LWN Resources
    [66]Security alerts archive
    Secured Distributions:
    [67]Astaro Security
    [68]Blue Linux
    [69]Castle
    [70]Engarde Secure Linux
    [71]Immunix
    [72]Kaladix Linux
    [73]NSA Security Enhanced
    [74]Openwall GNU/Linux
    [75]Trustix
    Security Projects
    [76]Bastille
    [77]Linux Security Audit Project
    [78]Linux Security Module
    [79]OpenSSH
    Security List Archives
    [80]Bugtraq Archive
    [81]Firewall Wizards Archive
    [82]ISN Archive
    Distribution-specific links
    [83]Caldera Advisories
    [84]Conectiva Updates
    [85]Debian Alerts
    [86]Kondara Advisories
    [87]Esware Alerts
    [88]LinuxPPC Security Updates
    [89]Mandrake Updates
    [90]Red Hat Errata
    [91]SuSE Announcements
    [92]Turbolinux
    [93]Yellow Dog Errata
    BSD-specific links
    [94]BSDi
    [95]FreeBSD
    [96]NetBSD
    [97]OpenBSD
    Security mailing lists
    [98]Caldera
    [99]Cobalt
    [100]Conectiva
    [101]Debian
    [102]Esware
    [103]FreeBSD
    [104]Kondara
    [105]LASER5
    [106]Linux From Scratch
    [107]Linux-Mandrake
    [108]NetBSD
    [109]OpenBSD
    [110]Red Hat
    [111]Slackware
    [112]Stampede
    [113]SuSE
    [114]Trustix
    [115]turboLinux
    [116]Yellow Dog
    Security Software Archives
    [117]munitions
    [118]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [119]CERT
    [120]CIAC
    [121]Comp Sec News Daily
    [122]Crypto-GRAM
    [123]LinuxLock.org
    [124]LinuxSecurity.com
    [125]Security Focus
    [126]SecurityPortal
                                                         [127]Next: Kernel
 
    [128]Eklektix, Inc. Linux powered! Copyright Л 2002 [129]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://lwn.net/2002/0228/
    3. http://lwn.net/2002/0228/kernel.php3
    4. http://lwn.net/2002/0228/dists.php3
    5. http://lwn.net/2002/0228/devel.php3
    6. http://lwn.net/2002/0228/commerce.php3
    7. http://lwn.net/2002/0228/press.php3
    8. http://lwn.net/2002/0228/announce.php3
    9. http://lwn.net/2002/0228/letters.php3
   10. http://lwn.net/2002/0228/bigpage.php3
   11. http://lwn.net/2002/0221/security.php3
   12. http://cve.mitre.org/
   13. http://lwn.net/2002/0228/a/squid.php3
   14. http://lwn.net/alerts/Conectiva/CLA-2002:464.php3
   15. http://lwn.net/alerts/Mandrake/MDKSA-2002:016.php3
   16. http://lwn.net/alerts/RedHat/RHSA-2002:029-09.php3
   17. http://lwn.net/alerts/Trustix/2002-0031.php3
   18. http://lwn.net/2002/0228/a/netfilter-irc.php3
   19. http://lwn.net/alerts/RedHat/RHSA-2002:028-13.php3
   20. http://lwn.net/alerts/RedHat/RHSA-2002:020-05.php3
   21. http://lwn.net/2002/0228/a/gnujsp.php3
   22. http://lwn.net/alerts/Debian/DSA-114-1.php3
   23. http://lwn.net/2002/0117/security.php3#at
   24. http://lwn.net/2002/0228/a/el-sec.php3
   25. http://lwn.net/alerts/Debian/DSA-102-1.php3
   26. http://lwn.net/alerts/Debian/DSA-102-2.php3
   27. http://lwn.net/alerts/Mandrake/MDKSA-2002:007.php3
   28. http://lwn.net/alerts/RedHat/RHSA-2002:015-15.php3
   29. http://lwn.net/alerts/RedHat/RHSA-2002:015-13.php3
   30. http://lwn.net/alerts/RedHat/RHSA-2002:015-13.php3
   31. http://lwn.net/alerts/Slackware/sl-1011706104.php3
   32. http://lwn.net/alerts/SuSE/SuSE-SA:2002:003.php3
   33. http://lwn.net/alerts/YellowDog/YDU-20020127-9.php3
   34. http://lwn.net/2002/0214/security.php3#cups
   35. http://lwn.net/alerts/SuSE/SuSE-SA:2002:006.php3
   36. http://lwn.net/alerts/SuSE/SuSE-SA:2002:005.php3
   37. http://lwn.net/2002/0228/a/suse-cups.php3
   38. http://lwn.net/alerts/Debian/DSA-110-1.php3
   39. http://lwn.net/alerts/Mandrake/MDKSA-2002:015.php3
   40. http://lwn.net/2002/0214/a/cert-snmp.php3
   41. http://lwn.net/2002/0214/security.php3
   42. http://lwn.net/2002/0228/a/el-sec.php3
   43. http://lwn.net/alerts/Caldera/CSSA-2002-004.0.php3
   44. http://lwn.net/alerts/Conectiva/CLA-2002:462.php3
   45. http://lwn.net/alerts/Debian/DSA-111-1.php3
   46. http://lwn.net/alerts/Mandrake/MDKSA-2002:014.php3
   47. http://lwn.net/alerts/RedHat/RHSA-2001:163-20.php3
   48. http://lwn.net/alerts/YellowDog/YDU-20020211-1.php3
   49. http://www.businessweek.com/bwdaily/dnflash/feb2002/nf20020220_5030.htm
   50. http://lwn.net/2002/0228/a/advisory-watch.php3
   51. http://lwn.net/2002/0228/a/security-week.php3
   52. http://www.krdl.org.sg/General/conferences/icics/Homepage.html
   53. http://www.stosdarwin.org/
   54. http://www.fc02.ai/
   55. http://www.omg.org/news/meetings/docsec2002/call.htm
   56.
 http://www.misti.com/northamerica.asp?page=4&subpage=2&disp=showconf&id=os02®
 ion=1
   57. http://www.sans.org/SANS2002.php
   58. http://www.rubi-con.org/
   59. http://www.TECHSEC.com/
   60. http://www.pet2002.org/
   61. http://www.cfp2002.org/
   62. http://www.infosec.co.uk/
   63. http://securityfocus.com/calendar
   64. mailto:lwn@lwn.net
   65. mailto:lwn@lwn.net
   66. http://lwn.net/alerts/
   67. http://www.astaro.com/products/index.html
   68. http://bluelinux.sourceforge.net/
   69. http://castle.altlinux.ru/
   70. http://www.engardelinux.org/
   71. http://www.immunix.org/
   72. http://www.kaladix.org/
   73. http://www.nsa.gov/selinux/
   74. http://www.openwall.com/Owl/
   75. http://www.trustix.com/
   76. http://www.bastille-linux.org/
   77. http://lsap.org/
   78. http://lsm.immunix.org/
   79. http://www.openssh.com/
   80. http://www.securityfocus.com/archive/1
   81. http://www.nfr.net/firewall-wizards/
   82. http://www.jammed.com/Lists/ISN/
   83. http://www.calderasystems.com/support/security/
   84. http://www.conectiva.com.br/atualizacoes/
   85. http://www.debian.org/security/
   86. http://www.kondara.org/errata/k12-security.html
   87. http://www.esware.com/actualizaciones.html
   88. http://linuxppc.org/security/advisories/
   89. http://www.linux-mandrake.com/en/fupdates.php3
   90. http://www.redhat.com/support/errata/index.html
   91. http://www.suse.de/security/index.html
   92. http://www.turbolinux.com/security/
   93. http://www.yellowdoglinux.com/resources/
   94. http://www.BSDI.COM/services/support/patches/
   95. http://www.freebsd.org/security/security.html
   96. http://www.NetBSD.ORG/Security/
   97. http://www.openbsd.org/security.html
   98. http://www.calderasystems.com/support/forums/announce.html
   99. http://www.cobalt.com/support/resources/usergroups.html
  100. http://distro.conectiva.com.br/atualizacoes/
  101. http://www.debian.org/MailingLists/subscribe
  102. http://www.esware.com/lista_correo.html
  103. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
  104. http://www.kondara.org/mailinglist.html.en
  105. http://l5web.laser5.co.jp/ml/ml.html
  106. http://www.linuxfromscratch.org/services/mailinglistinfo.php
  107. http://www.linux-mandrake.com/en/flists.php3
  108. http://www.netbsd.org/MailingLists/
  109. http://www.openbsd.org/mail.html
  110. http://www.redhat.com/mailing-lists/
  111. http://www.slackware.com/lists/
  112. http://www.stampede.org/mailinglists.php3
  113. http://www.suse.com/en/support/mailinglists/index.html
  114. http://www.trustix.net/support/
  115. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  116. http://lists.yellowdoglinux.com/ydl_updates.shtml
  117. http://munitions.vipul.net/
  118. http://www.zedz.net/
  119. http://www.cert.org/nav/alerts.html
  120. http://ciac.llnl.gov/ciac/
  121. http://www.MountainWave.com/
  122. http://www.counterpane.com/crypto-gram.html
  123. http://linuxlock.org/
  124. http://linuxsecurity.com/
  125. http://www.securityfocus.com/
  126. http://www.securityportal.com/
  127. http://lwn.net/2002/0228/kernel.php3
  128. http://www.eklektix.com/
  129. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://www.lwn.net/2002/0228/security.php3   Sergey Lentsov   03 Mar 2002 15:38:06 
Архивное /ru.linux/19861d4d38671.html, оценка 2 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional