|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 06 Apr 2002 00:34:22 To : All Subject : URL: http://www.lwn.net/2002/0404/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo]
[LWN.net]
Sections:
[2]Main page
Security
[3]Kernel
[4]Distributions
[5]Development
[6]Commerce
[7]Linux in the news
[8]Announcements
[9]Letters
[10]All in one big page
See also: [11]last week's Security page.
Security
News and Editorials
Stores find security in Linux (ZDNet). ZDNet has a [12]very short
article, trying to give an overview of the superiority of Linux's
security over DOS (No, that's not a typo). "The inherent security of
the Linux environment was a key motivation for Burlington Coat Factory
in choosing the operating system for a large retail point-of-sale
environment." There is a [13]companion article that gives a little
more detail.
Introduction to msec (MandrakeSecure). Here's [14]an article that
provides insight into what exactly msec is, what it does, and how it
can be customized to suit your tastes and environment. "The
Mandrake-Security package, more commonly known as msec, has been one
of the base packages in Mandrake Linux since it was first introduced
in version 7.0. Since that time, msec has undergone a lot of changes,
most notably the transformation from being a series of shell scripts
in 8.1 to the python-based system it is currently in 8.2."
Caldera International - Updated Caldera Public Keys. Caldera generated
[15]new security keys. Now that the new key is out, Caldera seems to
be getting caught up with security alerts.
Security Reports
Debian update for analog. Debian has issued a security for the
[16]analog web log analyzer that addresses a cross-site scripting
vulnerability. Updates are highly recommended.
Caldera update to XFree86. This update to [17]XFree86, fixes a problem
in which any user with local X access can exploit the MIT-SHM
extension and gain read/write access to any shared memory segment on
the system. Packages prior to XFree86-4.1-12 are vulnerable.
Security advisory for the Name Service Cache Daemon (nscd). Caldera
issued [18]an advisory that nscd has a default behavior that does not
allow applications to validate DNS "PTR" records against "A" records.
"Caldera recommends that this problem be worked around by disabling
the hosts cache in the nscd configuration file."
Caldera OpenLinux 3.1.1, startkde script vulnerability. startkde sets
the [19]LD_LIBRARY_PATH environment variable to "/opt/kde2/lib:" which
includes the current working directory in the library search path.
This exposes users to shared library attacks.
Caldera fix for packages previous to cups-1.1.10-5. This [20]CUPS
update fixes a buffer overflow vulnerability when reading names of
attributes in versions prior to 1.1.10-5. It does not appear to fix
the more recent buffer overflow vulnerability found in versions prior
to 1.1.14 described below under "Updates".
web scripts.
The following web scripts were reported to contain vulnerabilities:
* phpBB 1.4.4 [21]still suffers from a variation of the cross site
scripting vulnerability discovered in phpBB 1.4.2.
Proprietary products.
The following proprietary products were reported to contain
vulnerabilities:
* wwwisis has a reported [22]remote command execution vulnerability.
Updates
Apache mod_ssl buffer overflow vulnerability. According to [23]this
announcement "modssl versions prior to 2.8.7-1.3.23 (Feb 23, 2002)
make use of the underlying OpenSSL routines in a manner which could
overflow a buffer within the implementation. This situation appears
difficult to exploit in a production environment[...]." (First LWN
report: [24]March 7).
This week's updates:
* [25]Caldera (March 18, 2002)
Previous updates:
* [26]Conectiva (March 4, 2002)
* [27]Debian (March 10, 2002)
* [28]EnGarde (March 1, 2002)
* [29]Eridani (March 7, 2002)
* [30]Mandrake (March 7, 2002)
* [31]Red Hat (March 13, 2002) (Red Hat Secure Web Server)
* [32]Red Hat (March 6, 2002) (Red Hat 7, 7.1 & 7.2)
* [33]Trustix (February 28, 2002)
Buffer overflow in CUPS. Versions of the Common Unix Print System
prior to 1.1.14 have a buffer overflow vulnerability. (First LWN
report: [34]February 14).
This week's updates:
* [35]Conectiva (April 3, 2002)
Previous updates:
* [36]Debian (February 13, 2002)
* [37]Mandrake (February 15, 2002)
* [38]Red Hat (March 13, 2002) (Red Hat Powertools)
* [39]SuSE (February 27, 2002)
* [40]SuSE (February 23, 2002) ([41]withdrawn; it introduced an
unrelated bug)
Problem loading untrusted images in imlib. Versions of imlib prior to
1.9.13 used the NetPBM package in ways which "make it possible for
attackers to create image files such that when loaded via software
which uses Imlib, could crash the program or potentially allow
arbitrary code to be executed." (First LWN report: [42]March 28).
This week's updates:
* [43]Conectiva (March 28, 2002)
* [44]Eridani (March 27, 2002)
Previous updates:
* [45]Red Hat (March 20, 2002)
An off-by-one error in the channel code of OpenSSH versions 2.0 to
3.0.2 [46]has been found. Users are advised to upgrade to OpenSSH 3.1,
or to apply the relevant security update. "This bug can be exploited
locally by an authenticated user logging into a vulnerable OpenSSH
server or by a malicious SSH server attacking a vulnerable OpenSSH
client." (First LWN report: [47]March 14).
Also see the [48]the advisory from Pine for this vulnerability.
This week's updates:
* [49]Caldera (March 28, 2002)
Previous updates:
* [50]Conectiva (March 7, 2002)
* [51]Debian (March 7, 2002)
* [52]EnGarde (March 7, 2002)
* [53]Eridani (March 7, 2002)
* [54]Mandrake (March 7, 2002)
* [55]OpenPKG (March 8, 2002)
* [56]Trustix (March 7, 2002)
* [57]Red Hat (March 8, 2002)
* [58]Slackware (March 8, 2002)
* [59]SuSE (March 7, 2002)
* [60]Yellow Dog (March 9, 2002)
Denial of service vulnerability in squid-2.4STABLE1. The squid server
can be out of service for a few seconds when it reloads after a crash
caused by a burst of certain FTP requests. See the [61]September 18th
bug report for details.
This week's updates:
* [62]Caldera (March 18, 2002)
Previous updates:
* [63]Mandrake (November 21, 2001)
* [64]Turbolinux (January 24, 2002)
Resources
The Common Vulnerabilities and Exposures (CVE) [65]dictionary achieved
a [66]major milestone with over 2,000 official entries. MITRE's CVE
Lexicon of Information Security Vulnerabilities aims to standardize
the names for all publicly known vulnerabilities and security
exposures.
Linux security week. The [67]Linux Security Week and [68]Linux
Advisory Watch publications from LinuxSecurity.com are available.
Pierre-Alain Fayolle and Vincent Glaume have written a study on buffer
overflows and the existing protections a Linux system may use against
them;
[69]A Buffer Overflow Study Attacks & Defenses. The authors are
Computer Science students at Ecole Nationale Superieure
d'Electronique, d'Informatique et de Radiocommunications de Bordeaux.
A [70]similar paper was published in 2000 by researchers at the Oregon
Graduate Institute of Science & Technology.
Events
Upcoming Security Events.
Date Event Location
April 4 - 7, 2002 [71]SANS 2002 Orlando, FL., USA
April 5 - 7, 2002 [72]Rubicon Detroit, Michigan, USA
April 7 - 10, 2002 [73]Techno-Security 2002 Conference Myrtle Beach,
SC
April 14 - 15, 2002 [74]Workshop on Privacy Enhancing Technologies
2002 (Cathedral Hill Hotel)San Francisco, California, USA
April 15 - 19, 2002 [75]InfoSec 2002 UniNet IRC network
(irc.uninet.edu) - channel #infosec
April 16 - 19, 2002 [76]The Twelfth Conference on Computers, Freedom &
Privacy (Cathedral Hill Hotel)San Francisco, California, USA
April 23 - 25, 2002 [77]Infosecurity Europe 2002 Olympia, London, UK
May 1 - 3, 2002 [78]cansecwest/core02 Vancouver, Canada
May 4 - 5, 2002 [79]DallasCon Dallas, TX., USA
May 12 - 15, 2002 [80]2002 IEEE Symposium on Security and Privacy (The
Claremont Resort)Oakland, California, USA
May 13 - 14, 2002 [81]3rd International Common Criteria
Conference(ICCC) Ottawa, Ont., Canada
May 13 - 17, 2002 14th Annual Canadian Information Technology Security
Symposium(CITSS) (Ottawa Congress Centre)Ottawa, Ontario, Canada
May 27 - 31, 2002 [82]3rd International SANE Conference(SANE 2002)
Maastricht, The Netherlands
May 29 - 30, 2002 [83]RSA Conference 2002 Japan (Akasaka Prince
Hotel)Tokyo, Japan
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [84]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [85]lwn@lwn.net.
Section Editor: [86]Dennis Tenney
April 4, 2002
Sponsored Link
[87]Ghostscript
The Ghostscript project is proud to sponsor the good work of LWN.
LWN Resources
[88]Security alerts archive
Secured Distributions:
[89]Astaro Security
[90]Blue Linux
[91]Castle
[92]Engarde Secure Linux
[93]Immunix
[94]Kaladix Linux
[95]NSA Security Enhanced
[96]Openwall GNU/Linux
[97]Trustix
Security Projects
[98]Bastille
[99]Linux Security Audit Project
[100]Linux Security Module
[101]OpenSSH
Security List Archives
[102]Bugtraq Archive
[103]Firewall Wizards Archive
[104]ISN Archive
Distribution-specific links
[105]Caldera Advisories
[106]Conectiva Updates
[107]Debian Alerts
[108]Kondara Advisories
[109]Esware Alerts
[110]LinuxPPC Security Updates
[111]Mandrake Updates
[112]Red Hat Errata
[113]SuSE Announcements
[114]Turbolinux
[115]Yellow Dog Errata
BSD-specific links
[116]BSDi
[117]FreeBSD
[118]NetBSD
[119]OpenBSD
Security mailing lists
[120]Caldera
[121]Cobalt
[122]Conectiva
[123]Debian
[124]Esware
[125]FreeBSD
[126]Kondara
[127]LASER5
[128]Linux From Scratch
[129]Linux-Mandrake
[130]NetBSD
[131]OpenBSD
[132]Red Hat
[133]Slackware
[134]Stampede
[135]SuSE
[136]Trustix
[137]turboLinux
[138]Yellow Dog
Security Software Archives
[139]munitions
[140]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[141]CERT
[142]CIAC
[143]Comp Sec News Daily
[144]Crypto-GRAM
[145]LinuxLock.org
[146]LinuxSecurity.com
[147]Security Focus
[148]SecurityPortal
[149]Next: Kernel
[150]Eklektix, Inc. Linux powered! Copyright Л 2002 [151]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://lwn.net/2002/0404/
3. http://lwn.net/2002/0404/kernel.php3
4. http://lwn.net/2002/0404/dists.php3
5. http://lwn.net/2002/0404/devel.php3
6. http://lwn.net/2002/0404/commerce.php3
7. http://lwn.net/2002/0404/press.php3
8. http://lwn.net/2002/0404/announce.php3
9. http://lwn.net/2002/0404/letters.php3
10. http://lwn.net/2002/0404/bigpage.php3
11. http://lwn.net/2002/0328/security.php3
12. http://www.zdnet.com/techupdate/stories/main/0,14179,2859688,00.html
13.
http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2859671,00.html
14. http://www.mandrakesecure.net/en/docs/msec.php
15. http://lwn.net/alerts/Caldera/CSSA-2002-007.0.php3
16. http://lwn.net/alerts/Debian/DSA-125-1.php3
17. http://lwn.net/alerts/Caldera/CSSA-2002-009.0.php3
18. http://lwn.net/alerts/Caldera/CSSA-2002-013.0.php3
19. http://lwn.net/alerts/Caldera/CSSA-2002-005.0.php3
20. http://lwn.net/alerts/Caldera/CSSA-2002-008.0.php3
21. http://lwn.net/2002/0404/a/phpbb.php3
22. http://lwn.net/2002/0404/a/wwwisis.php3
23. http://online.securityfocus.com/archive/1/258646
24. http://lwn.net/2002/0307/security.php3#apachemodssl
25. http://lwn.net/alerts/Caldera/CSSA-2002-011.0.php3
26. http://lwn.net/alerts/Conectiva/CLA-2002:465.php3
27. http://lwn.net/alerts/Debian/DSA-120-1.php3
28. http://lwn.net/alerts/EnGarde/ESA-20020301-005.php3
29. http://lwn.net/alerts/Eridani/ERISA-2002:006.php3
30. http://lwn.net/alerts/Mandrake/MDKSA-2002:020.php3
31. http://lwn.net/alerts/RedHat/RHSA-2002:042-12.php3
32. http://lwn.net/alerts/RedHat/RHSA-2002:041-08.php3
33. http://lwn.net/alerts/Trustix/2002-0034.php3
34. http://lwn.net/2002/0214/security.php3#cups
35. http://lwn.net/alerts/Conectiva/CLA-2002:471.php3
36. http://lwn.net/alerts/Debian/DSA-110-1.php3
37. http://lwn.net/alerts/Mandrake/MDKSA-2002:015.php3
38. http://lwn.net/alerts/RedHat/RHSA-2002:032-12.php3
39. http://lwn.net/alerts/SuSE/SuSE-SA:2002:006.php3
40. http://lwn.net/alerts/SuSE/SuSE-SA:2002:005.php3
41. http://lwn.net/2002/0228/a/suse-cups.php3
42. http://lwn.net/2002/0328/security.php3#imlib
43. http://lwn.net/alerts/Conectiva/CLA-2002:470.php3
44. http://lwn.net/alerts/Eridani/ERISA-2002:011.php3
45. http://lwn.net/alerts/RedHat/RHSA-2002:048-06.php3
46. http://lwn.net/2002/0314/a/opensshoffby1.php3
47. http://lwn.net/2002/0314/security.php3#openss
48. http://www.pine.nl/advisories/pine-cert-20020301.txt
49. http://lwn.net/alerts/Caldera/CSSA-2002-012.0.php3
50. http://lwn.net/alerts/Conectiva/CLA-2002:467.php3
51. http://lwn.net/alerts/Debian/DSA-119-1.php3
52. http://lwn.net/alerts/EnGarde/ESA-20020307-007.php3
53. http://lwn.net/alerts/Eridani/ERISA-2002:007.php3
54. http://lwn.net/alerts/Mandrake/MDKSA-2002:019.php3
55. http://lwn.net/alerts/OpenPKG/OpenPKG-SA-2002.001.php3
56. http://lwn.net/alerts/Trustix/2002-0039.php3
57. http://lwn.net/alerts/RedHat/RHSA-2002:043-10.php3
58. http://lwn.net/alerts/Slackware/sl-1015606633.php3
59. http://lwn.net/alerts/SuSE/SuSE-SA:2002:009.php3
60. http://lwn.net/alerts/YellowDog/YDU-20020309-1.php3
61. http://www.squid-cache.org/bugs/show_bug.cgi?id=233
62. http://lwn.net/alerts/Caldera/CSSA-2002-010.0.php3
63. http://lwn.net/alerts/Mandrake/MDKSA-2001:088.php3
64. http://lwn.net/alerts/Turbolinux/TLSA2002003.php3
65. http://cve.mitre.org/
66. http://lwn.net/2002/0404/a/mitrecve.php3
67. http://lwn.net/2002/0404/a/security-week.php3
68. http://lwn.net/2002/0404/a/advisory-watch.php3
69. http://lwn.net/2002/0404/a/bufferoverflowstudy.php3
70. http://lwn.net/2002/0404/a/bufferoverflowstudy2.php3
71. http://www.sans.org/SANS2002.php
72. http://www.rubi-con.org/
73. http://www.TECHSEC.com/
74. http://www.pet2002.org/
75. http://infosec.uninet.edu/
76. http://www.cfp2002.org/
77. http://www.infosec.co.uk/
78. http://cansecwest.com/
79. http://www.dallascon.com/
80. http://www.ieee-security.org/TC/SP02/sp02index.html
81. http://www.cse-cst.gc.ca/en/iccc/iccc.html
82. http://www.nluug.nl/sane/
83. http://www.rsaconference.net/
84. http://securityfocus.com/calendar
85. mailto:lwn@lwn.net
86. mailto:lwn@lwn.net
87.
http://oasis.lwn.net/oasisc.php?s=4&c=18&cb=1331823632&url=http%3A%2F%2Fwww.ghos
tscript.com%2F
88. http://lwn.net/alerts/
89. http://www.astaro.com/products/index.html
90. http://bluelinux.sourceforge.net/
91. http://castle.altlinux.ru/
92. http://www.engardelinux.org/
93. http://www.immunix.org/
94. http://www.kaladix.org/
95. http://www.nsa.gov/selinux/
96. http://www.openwall.com/Owl/
97. http://www.trustix.com/
98. http://www.bastille-linux.org/
99. http://lsap.org/
100. http://lsm.immunix.org/
101. http://www.openssh.com/
102. http://www.securityfocus.com/archive/1
103. http://www.nfr.net/firewall-wizards/
104. http://www.jammed.com/Lists/ISN/
105. http://www.calderasystems.com/support/security/
106. http://www.conectiva.com.br/atualizacoes/
107. http://www.debian.org/security/
108. http://www.kondara.org/errata/k12-security.html
109. http://www.esware.com/actualizaciones.html
110. http://linuxppc.org/security/advisories/
111. http://www.linux-mandrake.com/en/fupdates.php3
112. http://www.redhat.com/support/errata/index.html
113. http://www.suse.de/security/index.html
114. http://www.turbolinux.com/security/
115. http://www.yellowdoglinux.com/resources/
116. http://www.BSDI.COM/services/support/patches/
117. http://www.freebsd.org/security/security.html
118. http://www.NetBSD.ORG/Security/
119. http://www.openbsd.org/security.html
120. http://www.calderasystems.com/support/forums/announce.html
121. http://www.cobalt.com/support/resources/usergroups.html
122. http://distro.conectiva.com.br/atualizacoes/
123. http://www.debian.org/MailingLists/subscribe
124. http://www.esware.com/lista_correo.html
125. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
126. http://www.kondara.org/mailinglist.html.en
127. http://l5web.laser5.co.jp/ml/ml.html
128. http://www.linuxfromscratch.org/services/mailinglistinfo.php
129. http://www.linux-mandrake.com/en/flists.php3
130. http://www.netbsd.org/MailingLists/
131. http://www.openbsd.org/mail.html
132. http://www.redhat.com/mailing-lists/
133. http://www.slackware.com/lists/
134. http://www.stampede.org/mailinglists.php3
135. http://www.suse.com/en/support/mailinglists/index.html
136. http://www.trustix.net/support/
137. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
138. http://lists.yellowdoglinux.com/ydl_updates.shtml
139. http://munitions.vipul.net/
140. http://www.zedz.net/
141. http://www.cert.org/nav/alerts.html
142. http://ciac.llnl.gov/ciac/
143. http://www.MountainWave.com/
144. http://www.counterpane.com/crypto-gram.html
145. http://linuxlock.org/
146. http://linuxsecurity.com/
147. http://www.securityfocus.com/
148. http://www.securityportal.com/
149. http://lwn.net/2002/0404/kernel.php3
150. http://www.eklektix.com/
151. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/19861f22ba1a5.html, оценка из 5, голосов 10
|