|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 02 Aug 2001 16:37:52 To : All Subject : URL: http://www.lwn.net/2001/0802/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo]
[2]Click Here
[LWN.net]
Sections:
[3]Main page
Security
[4]Kernel
[5]Distributions
[6]On the Desktop
[7]Development
[8]Commerce
[9]Linux in the news
[10]Announcements
[11]Linux History
[12]Letters
[13]All in one big page
See also: [14]last week's Security page.
Security
News and Editorials
Second coming of Code Red. CERT posted a [15]warning to administrators
regarding the potential resurfacing of the [16]Code Red worm this past
week. The worm was expected to awaken on Tuesday, July 31st, 2001
starting at 8PM. The report noted that after an 11 day quiet period
the worm would likely begin to spread again from previously infected
systems in a mutated form.
While Microsoft has [17]taken some heat for the spread of the worm,
experts are worried a second outbreak might raise the costs of dealing
with the virus even higher, with the first wave having [18]approached
$1.2 billion in lost services so far.
By early morning on Wednesday the worm [19]had resurfaced, and by late
afternoon had affected upwards of [20]135,000 systems. The growth of
infected systems once again appears to be [21]exponential, but mixed
reports were made as to whether this second round of infections would
eventually be [22]worse than the first outbreak or [23]less severe.
Late Tuesday afternoon, [24]Cisco posted an update to their advisory
for the Code Red worm which describes the potential impact on their
customers from side affects of the worm.
When the traffic from the worm reaches a significant level, a Cisco
CSS 11000 series Content Service Switch may suffer a memory
allocation error that leads to memory corruption and will require a
reboot. The defect is documented in DDTS CSCdu76237.
While none of this directly impacts Linux users, it indirectly affects
everyone on the Internet due to the potential such attacks have to
slow or even stop the movement of traffic. Fortunately, at least by
press time for LWN.net, round 2 in this battle seems to have gone to
the administrators.
Linux kernel IP masquerading vulnerability. A report was posted to
BugTraq this week on a [25]remotely exploitable IP masquerading
vulnerability in the Linux kernel. The problem includes the Linux 2.2
ip_masq_irc module and involves situations where certain browser or
MUA helper applications can cause firewalls to act as proxies to open
inbound connections when they shouldn't. A [26]patch has been provided
by the IP MASQ 2.2 maintainer, JuanJo Ciarlante.
RATS 1.1 (beta). A new beta version of the [27]source code auditing
tool RATS has been released, adding the ability to scan both Perl and
Python code for vulnerabilities.
Security Reports
Debian security updates for apache and apache-ssl. There have been
reports that the 'apache' http daemon, as included in the Debian
'stable' distribution, is vulnerable to the 'artificially long slash
path directory listing vulnerability'. There are [28]fixes available
in apache-ssl 1.3.9-13.3 and apache_1.3.9-14. It is recommended that
you upgrade your packages immediately.
Trustix advisory for PHPLib. Trustix Secure Linux issued an advisory
for [29]PHPLib to address problems where an attacker can execute
scripts from another server.
Long messages ids in elm cause buffer overflows. An advisory was
issued by Linux-Mandrake this week for the [30]elm mail client to
address an issue with long headers causing buffer overflows.
Proprietary products.
The following proprietary products were reported to contain
vulnerabilities:
* A bug in [31]Cold Fusion 5.0 is reported to crash the server,
dumping a core file that can allow decrypted tags to be seen in
clear text.
* [32]Quake 3: Arena 1.29f/g is reported Conectiva update to the to
have a buffer overflow vulnerability. No word yet on if this
exploitable.
* [33]Cisco SN 5420 Storage Router software have been found to
contain multiple vulnerabilities which can potentially provide a
denial of service to user access to storage systems.
Updates
Multiple Horde IMP vulnerabilities.
Check the [34]July 26th Security Summary for details.
This week's updates:
* [35]Conectiva
* [36]Caldera
Squid httpd acceleration ACL vulnerability.
Check the [37]July 26th Security Summary for details. Squid 2.3STABLE4
is affected; earlier versions are not. Red Hat 7.0 is reported to be
vulnerable, while earlier and later versions are not. Debian is
reported not vulnerable. A patch to fix the problem is available.
This week's updates:
* [38]Linux-Mandrake
Previous updates:
* [39]Immunix
* [40]Trustix
* [41]Red Hat
Resources
Cracking activity at all-time high (Register). According to statistics
compiled by the Honeynet Project, [42]cracking activity is at an
all-time high. "Between April and December 2000, seven default
installations of Red Hat 6.2 servers were attacked within three days
of connecting to the Internet. From this the people behind the project
concluded that 'the life expectancy of a default installation of Red
Hat 6.2 server to be less then 72 hours'. Scary stuff."
Hacking Vegas at Black Hat and DEF CON: One Geek's Experience (Linux
Journal). Linux Journal [43]covers the Black Hat Briefings and DEF
CON. "Darth Elmo had the good fortune to attend both this year. Unlike
many Black Hat attendees he went with somewhat more of an underground
perspective, or at least a non-corporate one. And unlike many DEF CON
attendees, Darth can remember where he was, what he saw and what he
drank for most of the time he was there. Here, then, are one geek's
observations and opinions on these two fine events."
Events
Upcoming Security Events.
Date Event Location
August 6 - 10, 2001 [44]CERT Conference 2001 Omaha, NE, USA.
August 7, 2001 [45]CIBC World Markets First Annual Security & Privacy
Conference New York, NY, USA.
August 10 - 12, 2001 [46]Hackers at Large 2001(HAL2001) Enschede,
Netherlands
August 13 - 17, 2001 [47]10th USENIX Security Symposium 2001
Conference Washington, D.C.
September 11 - 13, 2001 [48]New Security Paradigms Workshop 2001(NSPW)
Cloudcroft, New Mexico, USA
September 28 - 30, 2001 [49]Canadian Association for Security and
Intelligence Studies(CASIS 2001) (Dalhousie University)Halifax, Nova
Scotia, Canada.
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [50]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [51]lwn@lwn.net.
Section Editor: [52]Michael Hammel
August 2, 2001
[53]Click Here
Secured Distributions:
[54]Blue Linux
[55]Engarde Secure Linux
[56]Immunix
[57]Kaladix
[58]NSA Security Enhanced
[59]Openwall GNU/Linux
[60]Trustix
Security Projects
[61]Bastille
[62]Linux Security Audit Project
[63]Linux Security Module
[64]OpenSSH
Security List Archives
[65]Bugtraq Archive
[66]Firewall Wizards Archive
[67]ISN Archive
Distribution-specific links
[68]Caldera Advisories
[69]Conectiva Updates
[70]Debian Alerts
[71]Kondara Advisories
[72]Esware Alerts
[73]LinuxPPC Security Updates
[74]Mandrake Updates
[75]Red Hat Errata
[76]SuSE Announcements
[77]Yellow Dog Errata
BSD-specific links
[78]BSDi
[79]FreeBSD
[80]NetBSD
[81]OpenBSD
Security mailing lists [82]Caldera
[83]Cobalt
[84]Conectiva
[85]Debian
[86]Esware
[87]FreeBSD
[88]Kondara
[89]LASER5
[90]Linux From Scratch
[91]Linux-Mandrake
[92]NetBSD
[93]OpenBSD
[94]Red Hat
[95]Slackware
[96]Stampede
[97]SuSE
[98]Trustix
[99]turboLinux
[100]Yellow Dog
Security Software Archives
[101]munitions
[102]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[103]CERT
[104]CIAC
[105]Comp Sec News Daily
[106]Crypto-GRAM
[107]LinuxLock.org
[108]LinuxSecurity.com
[109]OpenSEC
[110]Security Focus
[111]SecurityPortal
[112]Next: Kernel
[113]Eklektix, Inc. Linux powered! Copyright Л 2001 [114]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
3. http://lwn.net/2001/0802/
4. http://lwn.net/2001/0802/kernel.php3
5. http://lwn.net/2001/0802/dists.php3
6. http://lwn.net/2001/0802/desktop.php3
7. http://lwn.net/2001/0802/devel.php3
8. http://lwn.net/2001/0802/commerce.php3
9. http://lwn.net/2001/0802/press.php3
10. http://lwn.net/2001/0802/announce.php3
11. http://lwn.net/2001/0802/history.php3
12. http://lwn.net/2001/0802/letters.php3
13. http://lwn.net/2001/0802/bigpage.php3
14. http://lwn.net/2001/0726/security.php3
15. http://lwn.net/2001/0802/a/code-red-part2.php3
16. http://www.cert.org/advisories/CA-2001-19.html
17. http://news.cnet.com/news/0-1003-200-6730674.html
18. http://dailynews.yahoo.com/h/nm/20010731/tc/tech_codered_costs_dc_1.html
19. http://dailynews.yahoo.com/h/nm/20010801/ts/tech_codered_dc_21.html
20. http://dailynews.yahoo.com/h/ap/20010801/ts/code_red_worm_29.html
21. http://lwn.net/2001/0802/a/codered-spread-data.php3
22. http://news.cnet.com/news/0-1003-200-6738969.html
23. http://dailynews.yahoo.com/h/ap/20010801/ts/code_red_worm_29.html
24. http://lwn.net/2001/0802/a/codered-cisco-update.php3
25. http://www.securityfocus.com/archive/1/200361
26. http://lwn.net/2001/0802/a/ip-masq-2.2-patch.php3
27. http://lwn.net/2001/0802/a/rats-1.1b.php3
28. http://lwn.net/2001/0802/a/deb-apache-update.php3
29. http://lwn.net/2001/0802/a/trustix-phplib.php3
30. http://lwn.net/2001/0802/a/lm-elm.php3
31. http://lwn.net/2001/0802/a/sec-cold-fusion.php3
32. http://lwn.net/2001/0802/a/sec-q3-arena.php3
33. http://lwn.net/2001/0802/a/cisco-sn5420.php3
34. http://lwn.net/2001/0726/security.php3#hordeimp
35. http://lwn.net/2001/0802/a/con-imp.php3
36. http://lwn.net/2001/0802/a/caldera-imp.php3
37. http://lwn.net/2001/0726/security.php3#squid
38. http://lwn.net/2001/0802/a/lm-squid.php3
39. http://lwn.net/2001/0726/a/imm-squid.php3
40. http://lwn.net/2001/0726/a/trustix-squid.php3
41. http://lwn.net/2001/0726/a/rh-squid.php3
42. http://www.theregister.co.uk/content/55/20714.html
43. http://noframes.linuxjournal.com/articles/tradeshow/0038.html
44. http://www.certconf.org/
45. http://www.cibcwm.com/eq/conference/security/
46. http://www.hal2001.org/hal/01Home/index.html
47. http://www.usenix.org/events/sec2001
48. http://www.nspw.org/
49. http://www.sfu.ca/igs/CASIS/
50. http://securityfocus.com/calendar
51. mailto:lwn@lwn.net
52. mailto:lwn@lwn.net
53. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
54. http://bluelinux.sourceforge.net/
55. http://www.engardelinux.org/
56. http://www.immunix.org/
57. http://www.maganation.com/~kaladix/
58. http://www.nsa.gov/selinux/
59. http://www.openwall.com/Owl/
60. http://www.trustix.com/
61. http://www.bastille-linux.org/
62. http://lsap.org/
63. http://lsm.immunix.org/
64. http://www.openssh.com/
65. http://www.securityfocus.com/bugtraq/archive/
66. http://www.nfr.net/firewall-wizards/
67. http://www.jammed.com/Lists/ISN/
68. http://www.calderasystems.com/support/security/
69. http://www.conectiva.com.br/atualizacoes/
70. http://www.debian.org/security/
71. http://www.kondara.org/errata/k12-security.html
72. http://www.esware.com/actualizaciones.html
73. http://linuxppc.org/security/advisories/
74. http://www.linux-mandrake.com/en/fupdates.php3
75. http://www.redhat.com/support/errata/index.html
76. http://www.suse.de/security/index.html
77. http://www.yellowdoglinux.com/resources/errata.shtml
78. http://www.BSDI.COM/services/support/patches/
79. http://www.freebsd.org/security/security.html
80. http://www.NetBSD.ORG/Security/
81. http://www.openbsd.org/security.html
82. http://www.calderasystems.com/support/forums/announce.html
83. http://www.cobalt.com/support/resources/usergroups.html
84. http://distro.conectiva.com.br/atualizacoes/
85. http://www.debian.org/MailingLists/subscribe
86. http://www.esware.com/lista_correo.html
87. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
88. http://www.kondara.org/mailinglist.html.en
89. http://l5web.laser5.co.jp/ml/ml.html
90. http://www.linuxfromscratch.org/services/mailinglistinfo.php
91. http://www.linux-mandrake.com/en/flists.php3
92. http://www.netbsd.org/MailingLists/
93. http://www.openbsd.org/mail.html
94. http://www.redhat.com/mailing-lists/
95. http://www.slackware.com/lists/
96. http://www.stampede.org/mailinglists.php3
97. http://www.suse.com/en/support/mailinglists/index.html
98. http://www.trustix.net/support/
99. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
100. http://lists.yellowdoglinux.com/ydl_updates.shtml
101. http://munitions.vipul.net/
102. http://www.zedz.net/
103. http://www.cert.org/nav/alerts.html
104. http://ciac.llnl.gov/ciac/
105. http://www.MountainWave.com/
106. http://www.counterpane.com/crypto-gram.html
107. http://linuxlock.org/
108. http://linuxsecurity.com/
109. http://www.opensec.net/
110. http://www.securityfocus.com/
111. http://www.securityportal.com/
112. http://lwn.net/2001/0802/kernel.php3
113. http://www.eklektix.com/
114. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/19861e68d7cb4.html, оценка из 5, голосов 10
|