Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   06 Apr 2002  00:34:22
 To : All
 Subject : URL: http://www.lwn.net/2002/0404/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] 
    [LWN.net]
 
    Sections:
     [2]Main page
     Security
     [3]Kernel
     [4]Distributions
     [5]Development
     [6]Commerce
     [7]Linux in the news
     [8]Announcements
     [9]Letters
    [10]All in one big page
 
    See also: [11]last week's Security page.
 
 Security
 
 News and Editorials
 
    Stores find security in Linux (ZDNet). ZDNet has a [12]very short
    article, trying to give an overview of the superiority of Linux's
    security over DOS (No, that's not a typo). "The inherent security of
    the Linux environment was a key motivation for Burlington Coat Factory
    in choosing the operating system for a large retail point-of-sale
    environment." There is a [13]companion article that gives a little
    more detail.
 
    Introduction to msec (MandrakeSecure). Here's [14]an article that
    provides insight into what exactly msec is, what it does, and how it
    can be customized to suit your tastes and environment. "The
    Mandrake-Security package, more commonly known as msec, has been one
    of the base packages in Mandrake Linux since it was first introduced
    in version 7.0. Since that time, msec has undergone a lot of changes,
    most notably the transformation from being a series of shell scripts
    in 8.1 to the python-based system it is currently in 8.2."
 
    Caldera International - Updated Caldera Public Keys. Caldera generated
    [15]new security keys. Now that the new key is out, Caldera seems to
    be getting caught up with security alerts.
 
 Security Reports
 
    Debian update for analog. Debian has issued a security for the
    [16]analog web log analyzer that addresses a cross-site scripting
    vulnerability. Updates are highly recommended.
 
    Caldera update to XFree86. This update to [17]XFree86, fixes a problem
    in which any user with local X access can exploit the MIT-SHM
    extension and gain read/write access to any shared memory segment on
    the system. Packages prior to XFree86-4.1-12 are vulnerable.
 
    Security advisory for the Name Service Cache Daemon (nscd). Caldera
    issued [18]an advisory that nscd has a default behavior that does not
    allow applications to validate DNS "PTR" records against "A" records.
    "Caldera recommends that this problem be worked around by disabling
    the hosts cache in the nscd configuration file."
 
    Caldera OpenLinux 3.1.1, startkde script vulnerability. startkde sets
    the [19]LD_LIBRARY_PATH environment variable to "/opt/kde2/lib:" which
    includes the current working directory in the library search path.
    This exposes users to shared library attacks.
 
    Caldera fix for packages previous to cups-1.1.10-5. This [20]CUPS
    update fixes a buffer overflow vulnerability when reading names of
    attributes in versions prior to 1.1.10-5. It does not appear to fix
    the more recent buffer overflow vulnerability found in versions prior
    to 1.1.14 described below under "Updates".
 
    web scripts.
    The following web scripts were reported to contain vulnerabilities:
      * phpBB 1.4.4 [21]still suffers from a variation of the cross site
        scripting vulnerability discovered in phpBB 1.4.2.
 
    Proprietary products.
    The following proprietary products were reported to contain
    vulnerabilities:
      * wwwisis has a reported [22]remote command execution vulnerability.
 
 Updates
 
    Apache mod_ssl buffer overflow vulnerability. According to [23]this
    announcement "modssl versions prior to 2.8.7-1.3.23 (Feb 23, 2002)
    make use of the underlying OpenSSL routines in a manner which could
    overflow a buffer within the implementation. This situation appears
    difficult to exploit in a production environment[...]." (First LWN
    report: [24]March 7).
 
    This week's updates:
      * [25]Caldera (March 18, 2002)
 
    Previous updates:
      * [26]Conectiva (March 4, 2002)
      * [27]Debian (March 10, 2002)
      * [28]EnGarde (March 1, 2002)
      * [29]Eridani (March 7, 2002)
      * [30]Mandrake (March 7, 2002)
      * [31]Red Hat (March 13, 2002) (Red Hat Secure Web Server)
      * [32]Red Hat (March 6, 2002) (Red Hat 7, 7.1 & 7.2)
      * [33]Trustix (February 28, 2002)
 
    Buffer overflow in CUPS. Versions of the Common Unix Print System
    prior to 1.1.14 have a buffer overflow vulnerability. (First LWN
    report: [34]February 14).
 
    This week's updates:
      * [35]Conectiva (April 3, 2002)
 
    Previous updates:
      * [36]Debian (February 13, 2002)
      * [37]Mandrake (February 15, 2002)
      * [38]Red Hat (March 13, 2002) (Red Hat Powertools)
      * [39]SuSE (February 27, 2002)
      * [40]SuSE (February 23, 2002) ([41]withdrawn; it introduced an
        unrelated bug)
 
    Problem loading untrusted images in imlib. Versions of imlib prior to
    1.9.13 used the NetPBM package in ways which "make it possible for
    attackers to create image files such that when loaded via software
    which uses Imlib, could crash the program or potentially allow
    arbitrary code to be executed." (First LWN report: [42]March 28).
 
    This week's updates:
      * [43]Conectiva (March 28, 2002)
      * [44]Eridani (March 27, 2002)
 
    Previous updates:
      * [45]Red Hat (March 20, 2002)
 
    An off-by-one error in the channel code of OpenSSH versions 2.0 to
    3.0.2 [46]has been found. Users are advised to upgrade to OpenSSH 3.1,
    or to apply the relevant security update. "This bug can be exploited
    locally by an authenticated user logging into a vulnerable OpenSSH
    server or by a malicious SSH server attacking a vulnerable OpenSSH
    client." (First LWN report: [47]March 14).
 
    Also see the [48]the advisory from Pine for this vulnerability.
 
    This week's updates:
      * [49]Caldera (March 28, 2002)
 
    Previous updates:
      * [50]Conectiva (March 7, 2002)
      * [51]Debian (March 7, 2002)
      * [52]EnGarde (March 7, 2002)
      * [53]Eridani (March 7, 2002)
      * [54]Mandrake (March 7, 2002)
      * [55]OpenPKG (March 8, 2002)
      * [56]Trustix (March 7, 2002)
      * [57]Red Hat (March 8, 2002)
      * [58]Slackware (March 8, 2002)
      * [59]SuSE (March 7, 2002)
      * [60]Yellow Dog (March 9, 2002)
 
    Denial of service vulnerability in squid-2.4STABLE1. The squid server
    can be out of service for a few seconds when it reloads after a crash
    caused by a burst of certain FTP requests. See the [61]September 18th
    bug report for details.
 
    This week's updates:
      * [62]Caldera (March 18, 2002)
 
    Previous updates:
      * [63]Mandrake (November 21, 2001)
      * [64]Turbolinux (January 24, 2002)
 
 Resources
 
    The Common Vulnerabilities and Exposures (CVE) [65]dictionary achieved
    a [66]major milestone with over 2,000 official entries. MITRE's CVE
    Lexicon of Information Security Vulnerabilities aims to standardize
    the names for all publicly known vulnerabilities and security
    exposures.
 
    Linux security week. The [67]Linux Security Week and [68]Linux
    Advisory Watch publications from LinuxSecurity.com are available.
 
    Pierre-Alain Fayolle and Vincent Glaume have written a study on buffer
    overflows and the existing protections a Linux system may use against
    them;
    [69]A Buffer Overflow Study Attacks & Defenses. The authors are
    Computer Science students at Ecole Nationale Superieure
    d'Electronique, d'Informatique et de Radiocommunications de Bordeaux.
    A [70]similar paper was published in 2000 by researchers at the Oregon
    Graduate Institute of Science & Technology.
 
 Events
 
    Upcoming Security Events.
 
    Date Event Location
    April 4 - 7, 2002 [71]SANS 2002 Orlando, FL., USA
    April 5 - 7, 2002 [72]Rubicon Detroit, Michigan, USA
    April 7 - 10, 2002 [73]Techno-Security 2002 Conference Myrtle Beach,
    SC
    April 14 - 15, 2002 [74]Workshop on Privacy Enhancing Technologies
    2002 (Cathedral Hill Hotel)San Francisco, California, USA
    April 15 - 19, 2002 [75]InfoSec 2002 UniNet IRC network
    (irc.uninet.edu) - channel #infosec
    April 16 - 19, 2002 [76]The Twelfth Conference on Computers, Freedom &
    Privacy (Cathedral Hill Hotel)San Francisco, California, USA
    April 23 - 25, 2002 [77]Infosecurity Europe 2002 Olympia, London, UK
    May 1 - 3, 2002 [78]cansecwest/core02 Vancouver, Canada
    May 4 - 5, 2002 [79]DallasCon Dallas, TX., USA
    May 12 - 15, 2002 [80]2002 IEEE Symposium on Security and Privacy (The
    Claremont Resort)Oakland, California, USA
    May 13 - 14, 2002 [81]3rd International Common Criteria
    Conference(ICCC) Ottawa, Ont., Canada
    May 13 - 17, 2002 14th Annual Canadian Information Technology Security
    Symposium(CITSS) (Ottawa Congress Centre)Ottawa, Ontario, Canada
    May 27 - 31, 2002 [82]3rd International SANE Conference(SANE 2002)
    Maastricht, The Netherlands
    May 29 - 30, 2002 [83]RSA Conference 2002 Japan (Akasaka Prince
    Hotel)Tokyo, Japan
 
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [84]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [85]lwn@lwn.net.
 
    Section Editor: [86]Dennis Tenney
    April 4, 2002
 
                                Sponsored Link
 
    [87]Ghostscript
 
    The Ghostscript project is proud to sponsor the good work of LWN.
 
    LWN Resources
    [88]Security alerts archive
    Secured Distributions:
    [89]Astaro Security
    [90]Blue Linux
    [91]Castle
    [92]Engarde Secure Linux
    [93]Immunix
    [94]Kaladix Linux
    [95]NSA Security Enhanced
    [96]Openwall GNU/Linux
    [97]Trustix
    Security Projects
    [98]Bastille
    [99]Linux Security Audit Project
    [100]Linux Security Module
    [101]OpenSSH
    Security List Archives
    [102]Bugtraq Archive
    [103]Firewall Wizards Archive
    [104]ISN Archive
    Distribution-specific links
    [105]Caldera Advisories
    [106]Conectiva Updates
    [107]Debian Alerts
    [108]Kondara Advisories
    [109]Esware Alerts
    [110]LinuxPPC Security Updates
    [111]Mandrake Updates
    [112]Red Hat Errata
    [113]SuSE Announcements
    [114]Turbolinux
    [115]Yellow Dog Errata
    BSD-specific links
    [116]BSDi
    [117]FreeBSD
    [118]NetBSD
    [119]OpenBSD
    Security mailing lists
    [120]Caldera
    [121]Cobalt
    [122]Conectiva
    [123]Debian
    [124]Esware
    [125]FreeBSD
    [126]Kondara
    [127]LASER5
    [128]Linux From Scratch
    [129]Linux-Mandrake
    [130]NetBSD
    [131]OpenBSD
    [132]Red Hat
    [133]Slackware
    [134]Stampede
    [135]SuSE
    [136]Trustix
    [137]turboLinux
    [138]Yellow Dog
    Security Software Archives
    [139]munitions
    [140]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [141]CERT
    [142]CIAC
    [143]Comp Sec News Daily
    [144]Crypto-GRAM
    [145]LinuxLock.org
    [146]LinuxSecurity.com
    [147]Security Focus
    [148]SecurityPortal
                                                         [149]Next: Kernel
 
    [150]Eklektix, Inc. Linux powered! Copyright Л 2002 [151]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://lwn.net/2002/0404/
    3. http://lwn.net/2002/0404/kernel.php3
    4. http://lwn.net/2002/0404/dists.php3
    5. http://lwn.net/2002/0404/devel.php3
    6. http://lwn.net/2002/0404/commerce.php3
    7. http://lwn.net/2002/0404/press.php3
    8. http://lwn.net/2002/0404/announce.php3
    9. http://lwn.net/2002/0404/letters.php3
   10. http://lwn.net/2002/0404/bigpage.php3
   11. http://lwn.net/2002/0328/security.php3
   12. http://www.zdnet.com/techupdate/stories/main/0,14179,2859688,00.html
   13.
 http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2859671,00.html
   14. http://www.mandrakesecure.net/en/docs/msec.php
   15. http://lwn.net/alerts/Caldera/CSSA-2002-007.0.php3
   16. http://lwn.net/alerts/Debian/DSA-125-1.php3
   17. http://lwn.net/alerts/Caldera/CSSA-2002-009.0.php3
   18. http://lwn.net/alerts/Caldera/CSSA-2002-013.0.php3
   19. http://lwn.net/alerts/Caldera/CSSA-2002-005.0.php3
   20. http://lwn.net/alerts/Caldera/CSSA-2002-008.0.php3
   21. http://lwn.net/2002/0404/a/phpbb.php3
   22. http://lwn.net/2002/0404/a/wwwisis.php3
   23. http://online.securityfocus.com/archive/1/258646
   24. http://lwn.net/2002/0307/security.php3#apachemodssl
   25. http://lwn.net/alerts/Caldera/CSSA-2002-011.0.php3
   26. http://lwn.net/alerts/Conectiva/CLA-2002:465.php3
   27. http://lwn.net/alerts/Debian/DSA-120-1.php3
   28. http://lwn.net/alerts/EnGarde/ESA-20020301-005.php3
   29. http://lwn.net/alerts/Eridani/ERISA-2002:006.php3
   30. http://lwn.net/alerts/Mandrake/MDKSA-2002:020.php3
   31. http://lwn.net/alerts/RedHat/RHSA-2002:042-12.php3
   32. http://lwn.net/alerts/RedHat/RHSA-2002:041-08.php3
   33. http://lwn.net/alerts/Trustix/2002-0034.php3
   34. http://lwn.net/2002/0214/security.php3#cups
   35. http://lwn.net/alerts/Conectiva/CLA-2002:471.php3
   36. http://lwn.net/alerts/Debian/DSA-110-1.php3
   37. http://lwn.net/alerts/Mandrake/MDKSA-2002:015.php3
   38. http://lwn.net/alerts/RedHat/RHSA-2002:032-12.php3
   39. http://lwn.net/alerts/SuSE/SuSE-SA:2002:006.php3
   40. http://lwn.net/alerts/SuSE/SuSE-SA:2002:005.php3
   41. http://lwn.net/2002/0228/a/suse-cups.php3
   42. http://lwn.net/2002/0328/security.php3#imlib
   43. http://lwn.net/alerts/Conectiva/CLA-2002:470.php3
   44. http://lwn.net/alerts/Eridani/ERISA-2002:011.php3
   45. http://lwn.net/alerts/RedHat/RHSA-2002:048-06.php3
   46. http://lwn.net/2002/0314/a/opensshoffby1.php3
   47. http://lwn.net/2002/0314/security.php3#openss
   48. http://www.pine.nl/advisories/pine-cert-20020301.txt
   49. http://lwn.net/alerts/Caldera/CSSA-2002-012.0.php3
   50. http://lwn.net/alerts/Conectiva/CLA-2002:467.php3
   51. http://lwn.net/alerts/Debian/DSA-119-1.php3
   52. http://lwn.net/alerts/EnGarde/ESA-20020307-007.php3
   53. http://lwn.net/alerts/Eridani/ERISA-2002:007.php3
   54. http://lwn.net/alerts/Mandrake/MDKSA-2002:019.php3
   55. http://lwn.net/alerts/OpenPKG/OpenPKG-SA-2002.001.php3
   56. http://lwn.net/alerts/Trustix/2002-0039.php3
   57. http://lwn.net/alerts/RedHat/RHSA-2002:043-10.php3
   58. http://lwn.net/alerts/Slackware/sl-1015606633.php3
   59. http://lwn.net/alerts/SuSE/SuSE-SA:2002:009.php3
   60. http://lwn.net/alerts/YellowDog/YDU-20020309-1.php3
   61. http://www.squid-cache.org/bugs/show_bug.cgi?id=233
   62. http://lwn.net/alerts/Caldera/CSSA-2002-010.0.php3
   63. http://lwn.net/alerts/Mandrake/MDKSA-2001:088.php3
   64. http://lwn.net/alerts/Turbolinux/TLSA2002003.php3
   65. http://cve.mitre.org/
   66. http://lwn.net/2002/0404/a/mitrecve.php3
   67. http://lwn.net/2002/0404/a/security-week.php3
   68. http://lwn.net/2002/0404/a/advisory-watch.php3
   69. http://lwn.net/2002/0404/a/bufferoverflowstudy.php3
   70. http://lwn.net/2002/0404/a/bufferoverflowstudy2.php3
   71. http://www.sans.org/SANS2002.php
   72. http://www.rubi-con.org/
   73. http://www.TECHSEC.com/
   74. http://www.pet2002.org/
   75. http://infosec.uninet.edu/
   76. http://www.cfp2002.org/
   77. http://www.infosec.co.uk/
   78. http://cansecwest.com/
   79. http://www.dallascon.com/
   80. http://www.ieee-security.org/TC/SP02/sp02index.html
   81. http://www.cse-cst.gc.ca/en/iccc/iccc.html
   82. http://www.nluug.nl/sane/
   83. http://www.rsaconference.net/
   84. http://securityfocus.com/calendar
   85. mailto:lwn@lwn.net
   86. mailto:lwn@lwn.net
   87.
 http://oasis.lwn.net/oasisc.php?s=4&c=18&cb=1331823632&url=http%3A%2F%2Fwww.ghos
 tscript.com%2F
   88. http://lwn.net/alerts/
   89. http://www.astaro.com/products/index.html
   90. http://bluelinux.sourceforge.net/
   91. http://castle.altlinux.ru/
   92. http://www.engardelinux.org/
   93. http://www.immunix.org/
   94. http://www.kaladix.org/
   95. http://www.nsa.gov/selinux/
   96. http://www.openwall.com/Owl/
   97. http://www.trustix.com/
   98. http://www.bastille-linux.org/
   99. http://lsap.org/
  100. http://lsm.immunix.org/
  101. http://www.openssh.com/
  102. http://www.securityfocus.com/archive/1
  103. http://www.nfr.net/firewall-wizards/
  104. http://www.jammed.com/Lists/ISN/
  105. http://www.calderasystems.com/support/security/
  106. http://www.conectiva.com.br/atualizacoes/
  107. http://www.debian.org/security/
  108. http://www.kondara.org/errata/k12-security.html
  109. http://www.esware.com/actualizaciones.html
  110. http://linuxppc.org/security/advisories/
  111. http://www.linux-mandrake.com/en/fupdates.php3
  112. http://www.redhat.com/support/errata/index.html
  113. http://www.suse.de/security/index.html
  114. http://www.turbolinux.com/security/
  115. http://www.yellowdoglinux.com/resources/
  116. http://www.BSDI.COM/services/support/patches/
  117. http://www.freebsd.org/security/security.html
  118. http://www.NetBSD.ORG/Security/
  119. http://www.openbsd.org/security.html
  120. http://www.calderasystems.com/support/forums/announce.html
  121. http://www.cobalt.com/support/resources/usergroups.html
  122. http://distro.conectiva.com.br/atualizacoes/
  123. http://www.debian.org/MailingLists/subscribe
  124. http://www.esware.com/lista_correo.html
  125. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
  126. http://www.kondara.org/mailinglist.html.en
  127. http://l5web.laser5.co.jp/ml/ml.html
  128. http://www.linuxfromscratch.org/services/mailinglistinfo.php
  129. http://www.linux-mandrake.com/en/flists.php3
  130. http://www.netbsd.org/MailingLists/
  131. http://www.openbsd.org/mail.html
  132. http://www.redhat.com/mailing-lists/
  133. http://www.slackware.com/lists/
  134. http://www.stampede.org/mailinglists.php3
  135. http://www.suse.com/en/support/mailinglists/index.html
  136. http://www.trustix.net/support/
  137. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  138. http://lists.yellowdoglinux.com/ydl_updates.shtml
  139. http://munitions.vipul.net/
  140. http://www.zedz.net/
  141. http://www.cert.org/nav/alerts.html
  142. http://ciac.llnl.gov/ciac/
  143. http://www.MountainWave.com/
  144. http://www.counterpane.com/crypto-gram.html
  145. http://linuxlock.org/
  146. http://linuxsecurity.com/
  147. http://www.securityfocus.com/
  148. http://www.securityportal.com/
  149. http://lwn.net/2002/0404/kernel.php3
  150. http://www.eklektix.com/
  151. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://www.lwn.net/2002/0404/security.php3   Sergey Lentsov   06 Apr 2002 00:34:22 
Архивное /ru.linux/19861f22ba1a5.html, оценка 2 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional