Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   02 Aug 2001  16:37:52
 To : All
 Subject : URL: http://www.lwn.net/2001/0802/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] 
    
                                [2]Click Here 
    [LWN.net]
    
    Sections:
     [3]Main page
     Security
     [4]Kernel
     [5]Distributions
     [6]On the Desktop
     [7]Development
     [8]Commerce
     [9]Linux in the news
     [10]Announcements
     [11]Linux History
     [12]Letters
    [13]All in one big page
    
    See also: [14]last week's Security page.
    
 Security
 
 News and Editorials
 
    Second coming of Code Red. CERT posted a [15]warning to administrators
    regarding the potential resurfacing of the [16]Code Red worm this past
    week. The worm was expected to awaken on Tuesday, July 31st, 2001
    starting at 8PM. The report noted that after an 11 day quiet period
    the worm would likely begin to spread again from previously infected
    systems in a mutated form.
    
    While Microsoft has [17]taken some heat for the spread of the worm,
    experts are worried a second outbreak might raise the costs of dealing
    with the virus even higher, with the first wave having [18]approached
    $1.2 billion in lost services so far.
    
    By early morning on Wednesday the worm [19]had resurfaced, and by late
    afternoon had affected upwards of [20]135,000 systems. The growth of
    infected systems once again appears to be [21]exponential, but mixed
    reports were made as to whether this second round of infections would
    eventually be [22]worse than the first outbreak or [23]less severe.
    
    Late Tuesday afternoon, [24]Cisco posted an update to their advisory
    for the Code Red worm which describes the potential impact on their
    customers from side affects of the worm.
    
      When the traffic from the worm reaches a significant level, a Cisco
      CSS 11000 series Content Service Switch may suffer a memory
      allocation error that leads to memory corruption and will require a
      reboot. The defect is documented in DDTS CSCdu76237.
      
    While none of this directly impacts Linux users, it indirectly affects
    everyone on the Internet due to the potential such attacks have to
    slow or even stop the movement of traffic. Fortunately, at least by
    press time for LWN.net, round 2 in this battle seems to have gone to
    the administrators.
    
    Linux kernel IP masquerading vulnerability. A report was posted to
    BugTraq this week on a [25]remotely exploitable IP masquerading
    vulnerability in the Linux kernel. The problem includes the Linux 2.2
    ip_masq_irc module and involves situations where certain browser or
    MUA helper applications can cause firewalls to act as proxies to open
    inbound connections when they shouldn't. A [26]patch has been provided
    by the IP MASQ 2.2 maintainer, JuanJo Ciarlante.
    
    RATS 1.1 (beta). A new beta version of the [27]source code auditing
    tool RATS has been released, adding the ability to scan both Perl and
    Python code for vulnerabilities.
    
 Security Reports
 
    Debian security updates for apache and apache-ssl. There have been
    reports that the 'apache' http daemon, as included in the Debian
    'stable' distribution, is vulnerable to the 'artificially long slash
    path directory listing vulnerability'. There are [28]fixes available
    in apache-ssl 1.3.9-13.3 and apache_1.3.9-14. It is recommended that
    you upgrade your packages immediately.
    
    Trustix advisory for PHPLib. Trustix Secure Linux issued an advisory
    for [29]PHPLib to address problems where an attacker can execute
    scripts from another server.
    
    Long messages ids in elm cause buffer overflows. An advisory was
    issued by Linux-Mandrake this week for the [30]elm mail client to
    address an issue with long headers causing buffer overflows.
    
    Proprietary products.
    The following proprietary products were reported to contain
    vulnerabilities:
      * A bug in [31]Cold Fusion 5.0 is reported to crash the server,
        dumping a core file that can allow decrypted tags to be seen in
        clear text.
      * [32]Quake 3: Arena 1.29f/g is reported Conectiva update to the to
        have a buffer overflow vulnerability. No word yet on if this
        exploitable.
      * [33]Cisco SN 5420 Storage Router software have been found to
        contain multiple vulnerabilities which can potentially provide a
        denial of service to user access to storage systems.
    
 Updates
 
    Multiple Horde IMP vulnerabilities.
    Check the [34]July 26th Security Summary for details.
    
    This week's updates:
      * [35]Conectiva
      * [36]Caldera
        
    Squid httpd acceleration ACL vulnerability.
    Check the [37]July 26th Security Summary for details. Squid 2.3STABLE4
    is affected; earlier versions are not. Red Hat 7.0 is reported to be
    vulnerable, while earlier and later versions are not. Debian is
    reported not vulnerable. A patch to fix the problem is available.
    
    This week's updates:
      * [38]Linux-Mandrake
        
    Previous updates:
      * [39]Immunix
      * [40]Trustix
      * [41]Red Hat
        
 Resources
 
    Cracking activity at all-time high (Register). According to statistics
    compiled by the Honeynet Project, [42]cracking activity is at an
    all-time high. "Between April and December 2000, seven default
    installations of Red Hat 6.2 servers were attacked within three days
    of connecting to the Internet. From this the people behind the project
    concluded that 'the life expectancy of a default installation of Red
    Hat 6.2 server to be less then 72 hours'. Scary stuff."
    
    Hacking Vegas at Black Hat and DEF CON: One Geek's Experience (Linux
    Journal). Linux Journal [43]covers the Black Hat Briefings and DEF
    CON. "Darth Elmo had the good fortune to attend both this year. Unlike
    many Black Hat attendees he went with somewhat more of an underground
    perspective, or at least a non-corporate one. And unlike many DEF CON
    attendees, Darth can remember where he was, what he saw and what he
    drank for most of the time he was there. Here, then, are one geek's
    observations and opinions on these two fine events."
    
 Events
 
    Upcoming Security Events.
    
    Date Event Location
    August 6 - 10, 2001 [44]CERT Conference 2001 Omaha, NE, USA.
    August 7, 2001 [45]CIBC World Markets First Annual Security & Privacy
    Conference New York, NY, USA.
    August 10 - 12, 2001 [46]Hackers at Large 2001(HAL2001) Enschede,
    Netherlands
    August 13 - 17, 2001 [47]10th USENIX Security Symposium 2001
    Conference Washington, D.C.
    September 11 - 13, 2001 [48]New Security Paradigms Workshop 2001(NSPW)
    Cloudcroft, New Mexico, USA
    September 28 - 30, 2001 [49]Canadian Association for Security and
    Intelligence Studies(CASIS 2001) (Dalhousie University)Halifax, Nova
    Scotia, Canada.
    
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [50]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [51]lwn@lwn.net.
    
    Section Editor: [52]Michael Hammel
    August 2, 2001
    
                               [53]Click Here 
    Secured Distributions:
    [54]Blue Linux
    [55]Engarde Secure Linux
    [56]Immunix
    [57]Kaladix
    [58]NSA Security Enhanced
    [59]Openwall GNU/Linux
    [60]Trustix
    Security Projects
    [61]Bastille
    [62]Linux Security Audit Project
    [63]Linux Security Module
    [64]OpenSSH
    Security List Archives
    [65]Bugtraq Archive
    [66]Firewall Wizards Archive
    [67]ISN Archive
    Distribution-specific links
    [68]Caldera Advisories
    [69]Conectiva Updates
    [70]Debian Alerts
    [71]Kondara Advisories
    [72]Esware Alerts
    [73]LinuxPPC Security Updates
    [74]Mandrake Updates
    [75]Red Hat Errata
    [76]SuSE Announcements
    [77]Yellow Dog Errata
    BSD-specific links
    [78]BSDi
    [79]FreeBSD
    [80]NetBSD
    [81]OpenBSD
    Security mailing lists [82]Caldera
    [83]Cobalt
    [84]Conectiva
    [85]Debian
    [86]Esware
    [87]FreeBSD
    [88]Kondara
    [89]LASER5
    [90]Linux From Scratch
    [91]Linux-Mandrake
    [92]NetBSD
    [93]OpenBSD
    [94]Red Hat
    [95]Slackware
    [96]Stampede
    [97]SuSE
    [98]Trustix
    [99]turboLinux
    [100]Yellow Dog
    Security Software Archives
    [101]munitions
    [102]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [103]CERT
    [104]CIAC
    [105]Comp Sec News Daily
    [106]Crypto-GRAM
    [107]LinuxLock.org
    [108]LinuxSecurity.com
    [109]OpenSEC
    [110]Security Focus
    [111]SecurityPortal
    
    
                                                         [112]Next: Kernel
    
    [113]Eklektix, Inc. Linux powered! Copyright Л 2001 [114]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
    3. http://lwn.net/2001/0802/
    4. http://lwn.net/2001/0802/kernel.php3
    5. http://lwn.net/2001/0802/dists.php3
    6. http://lwn.net/2001/0802/desktop.php3
    7. http://lwn.net/2001/0802/devel.php3
    8. http://lwn.net/2001/0802/commerce.php3
    9. http://lwn.net/2001/0802/press.php3
   10. http://lwn.net/2001/0802/announce.php3
   11. http://lwn.net/2001/0802/history.php3
   12. http://lwn.net/2001/0802/letters.php3
   13. http://lwn.net/2001/0802/bigpage.php3
   14. http://lwn.net/2001/0726/security.php3
   15. http://lwn.net/2001/0802/a/code-red-part2.php3
   16. http://www.cert.org/advisories/CA-2001-19.html
   17. http://news.cnet.com/news/0-1003-200-6730674.html
   18. http://dailynews.yahoo.com/h/nm/20010731/tc/tech_codered_costs_dc_1.html
   19. http://dailynews.yahoo.com/h/nm/20010801/ts/tech_codered_dc_21.html
   20. http://dailynews.yahoo.com/h/ap/20010801/ts/code_red_worm_29.html
   21. http://lwn.net/2001/0802/a/codered-spread-data.php3
   22. http://news.cnet.com/news/0-1003-200-6738969.html
   23. http://dailynews.yahoo.com/h/ap/20010801/ts/code_red_worm_29.html
   24. http://lwn.net/2001/0802/a/codered-cisco-update.php3
   25. http://www.securityfocus.com/archive/1/200361
   26. http://lwn.net/2001/0802/a/ip-masq-2.2-patch.php3
   27. http://lwn.net/2001/0802/a/rats-1.1b.php3
   28. http://lwn.net/2001/0802/a/deb-apache-update.php3
   29. http://lwn.net/2001/0802/a/trustix-phplib.php3
   30. http://lwn.net/2001/0802/a/lm-elm.php3
   31. http://lwn.net/2001/0802/a/sec-cold-fusion.php3
   32. http://lwn.net/2001/0802/a/sec-q3-arena.php3
   33. http://lwn.net/2001/0802/a/cisco-sn5420.php3
   34. http://lwn.net/2001/0726/security.php3#hordeimp
   35. http://lwn.net/2001/0802/a/con-imp.php3
   36. http://lwn.net/2001/0802/a/caldera-imp.php3
   37. http://lwn.net/2001/0726/security.php3#squid
   38. http://lwn.net/2001/0802/a/lm-squid.php3
   39. http://lwn.net/2001/0726/a/imm-squid.php3
   40. http://lwn.net/2001/0726/a/trustix-squid.php3
   41. http://lwn.net/2001/0726/a/rh-squid.php3
   42. http://www.theregister.co.uk/content/55/20714.html
   43. http://noframes.linuxjournal.com/articles/tradeshow/0038.html
   44. http://www.certconf.org/
   45. http://www.cibcwm.com/eq/conference/security/
   46. http://www.hal2001.org/hal/01Home/index.html
   47. http://www.usenix.org/events/sec2001
   48. http://www.nspw.org/
   49. http://www.sfu.ca/igs/CASIS/
   50. http://securityfocus.com/calendar
   51. mailto:lwn@lwn.net
   52. mailto:lwn@lwn.net
   53. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
   54. http://bluelinux.sourceforge.net/
   55. http://www.engardelinux.org/
   56. http://www.immunix.org/
   57. http://www.maganation.com/~kaladix/
   58. http://www.nsa.gov/selinux/
   59. http://www.openwall.com/Owl/
   60. http://www.trustix.com/
   61. http://www.bastille-linux.org/
   62. http://lsap.org/
   63. http://lsm.immunix.org/
   64. http://www.openssh.com/
   65. http://www.securityfocus.com/bugtraq/archive/
   66. http://www.nfr.net/firewall-wizards/
   67. http://www.jammed.com/Lists/ISN/
   68. http://www.calderasystems.com/support/security/
   69. http://www.conectiva.com.br/atualizacoes/
   70. http://www.debian.org/security/
   71. http://www.kondara.org/errata/k12-security.html
   72. http://www.esware.com/actualizaciones.html
   73. http://linuxppc.org/security/advisories/
   74. http://www.linux-mandrake.com/en/fupdates.php3
   75. http://www.redhat.com/support/errata/index.html
   76. http://www.suse.de/security/index.html
   77. http://www.yellowdoglinux.com/resources/errata.shtml
   78. http://www.BSDI.COM/services/support/patches/
   79. http://www.freebsd.org/security/security.html
   80. http://www.NetBSD.ORG/Security/
   81. http://www.openbsd.org/security.html
   82. http://www.calderasystems.com/support/forums/announce.html
   83. http://www.cobalt.com/support/resources/usergroups.html
   84. http://distro.conectiva.com.br/atualizacoes/
   85. http://www.debian.org/MailingLists/subscribe
   86. http://www.esware.com/lista_correo.html
   87. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
   88. http://www.kondara.org/mailinglist.html.en
   89. http://l5web.laser5.co.jp/ml/ml.html
   90. http://www.linuxfromscratch.org/services/mailinglistinfo.php
   91. http://www.linux-mandrake.com/en/flists.php3
   92. http://www.netbsd.org/MailingLists/
   93. http://www.openbsd.org/mail.html
   94. http://www.redhat.com/mailing-lists/
   95. http://www.slackware.com/lists/
   96. http://www.stampede.org/mailinglists.php3
   97. http://www.suse.com/en/support/mailinglists/index.html
   98. http://www.trustix.net/support/
   99. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  100. http://lists.yellowdoglinux.com/ydl_updates.shtml
  101. http://munitions.vipul.net/
  102. http://www.zedz.net/
  103. http://www.cert.org/nav/alerts.html
  104. http://ciac.llnl.gov/ciac/
  105. http://www.MountainWave.com/
  106. http://www.counterpane.com/crypto-gram.html
  107. http://linuxlock.org/
  108. http://linuxsecurity.com/
  109. http://www.opensec.net/
  110. http://www.securityfocus.com/
  111. http://www.securityportal.com/
  112. http://lwn.net/2001/0802/kernel.php3
  113. http://www.eklektix.com/
  114. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://www.lwn.net/2001/0802/security.php3   Sergey Lentsov   02 Aug 2001 16:37:52 
Архивное /ru.linux/19861e68d7cb4.html, оценка 3 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional