[LWN Logo]
[LWN.net]

Sections:
 Main page
 Security
 Kernel
 Distributions
 Development
 Commerce
 Linux in the news
 Announcements
 Linux History
 Letters
All in one big page

See also: last week's Security page.

Security


News and Editorials

Hal Burgiss Introduces Linux Security Quick-Start Guides. LinuxSecurity.com has published an interview with Hal Burgiss, who has just produced a couple of quick-start Linux security guides (linked from the interview). "While there is a wealth of security related information around, there is not so much addressed to the new user who might be coming from another platform. It's one thing to say 'turn off all unneeded services', but quite another if you don't know what's 'needed' and what's not. Or how to know what services are actually running, and where they are getting started."

OpenSSH 3.0.1 released. OpenSSH 3.0.1 has been released. It includes a fix for a couple of security problems; both appear to be minor and difficult (or impossible) to exploit, but an upgrade is probably a good idea anyway.

Security Reports

Memory exhaustion vulnerability in Postfix. The Postfix mailer has a vulnerability wherein an attacker could run the Postfix daemon out of memory, causing it to crash. A fix is included with the report; no distributor updates have been seen as of this writing.

Trouble with wu-ftpd? A vague message has gone out seeking vendors who ship the wu-ftpd FTP server daemon. It seems there's a remotely exploitable problem in that package, though no details are yet available.

SuSE to discontinue 6.3 support. SuSE has announced that support for its 6.3 distribution will end on December 10. Thereafter, security updates will no longer be available. SuSE Linux 6.4 is still supported for now, until it, too, reaches its two-year anniversary.

A Mandrake Linux update to gnupg. MandrakeSoft has issued an update to gnupg which removes the setgid root bit from the executable. This bit was unnecessary, and, it seems, useful for overwriting files owned by that group. This one appears to be a Mandrake-specific problem.

web scripts. The following web scripts were reported to contain vulnerabilities:

  • Cabezon Aurélien has found a couple of vulnerabilities in PhpNuke add-on packages. The Gallery package does not properly check filenames in URLs, allowing any file on the system to be read. And the Net Tool Add-on does not check for shell metacharacters, making it vulnerable to remote command execution exploits.

Proprietary products. The following proprietary products were reported to contain vulnerabilities:

Updates

Session hijacking vulnerability in IMP. Versions of the Horde IMP mail system prior to 2.2.7 have a session hijacking vulnerability that is well worth fixing. (First LWN report: November 15, 2001).

This week's updates:

Previous updates:

Procmail race conditions. See the July 26 Security page for the initial report.

This week's updates:

Previous updates:

Vulnerabilities in tetex. The tetex package has a temporary file handling vulnerability; this problem was first reported in the July 12, 2001 LWN security page.

This week's updates:

Previous updates:

Resources

CRYPTO-GRAM Newsletter. Bruce Schneier's CRYPTO-GRAM Newsletter for November 15 is available. The bulk of this issue is an extended version of Bruce's response to Microsoft on full disclosure. "Disclosure does not create security vulnerabilities; programmers create them, and they remain until other programmers find and remove them. Everyone makes mistakes; they are natural events in the sense that they inevitably happen. But that's no excuse for pretending that they are caused by forces out of our control, and mitigated when we get around to it."

Events

The 18th annual Chaos Communication Congress will be held in Berlin, Germany, on December 27 to 29. A call for papers is out for those who would like to participate.

Upcoming Security Events.
Date Event Location
November 21 - 23, 2001International Information Warfare SymposiumAAL, Lucerne, Swizerland.
November 21 - 22, 2001Black Hat BriefingsAmsterdam
November 24 - 30, 2001Computer Security MexicoMexico City
November 29 - 30, 2001International Cryptography InstituteWashington, DC
December 2 - 7, 2001Lisa 2001 15th Systems Administration ConferenceSan Diego, CA.
December 5 - 6, 2001InfoSecurity Conference & ExhibitionJacob K. Javits Center, New York, NY.
December 10 - 14, 2001Annual Computer Security Applications ConferenceNew Orleans, LA

For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.

Section Editor: Jonathan Corbet


November 22, 2001

LWN Resources


Secured Distributions:
Astaro Security
Castle
Engarde Secure Linux
Immunix
Kaladix Linux
NSA Security Enhanced
Openwall GNU/Linux
Trustix

Security Projects
Bastille
Linux Security Audit Project
Linux Security Module
OpenSSH

Security List Archives
Bugtraq Archive
Firewall Wizards Archive
ISN Archive

Distribution-specific links
Caldera Advisories
Conectiva Updates
Debian Alerts
Kondara Advisories
Esware Alerts
LinuxPPC Security Updates
Mandrake Updates
Red Hat Errata
SuSE Announcements
Turbolinux
Yellow Dog Errata

BSD-specific links
BSDi
FreeBSD
NetBSD
OpenBSD

Security mailing lists
Caldera
Cobalt
Conectiva
Debian
Esware
FreeBSD
Kondara
LASER5
Linux From Scratch
Linux-Mandrake
NetBSD
OpenBSD
Red Hat
Slackware
Stampede
SuSE
Trustix
turboLinux
Yellow Dog

Security Software Archives
munitions
ZedZ.net (formerly replay.com)

Miscellaneous Resources
CERT
CIAC
Comp Sec News Daily
Crypto-GRAM
LinuxLock.org
LinuxSecurity.com
Security Focus
SecurityPortal

 

Next: Kernel

 
Eklektix, Inc. Linux powered! Copyright © 2001 Eklektix, Inc., all rights reserved
Linux ® is a registered trademark of Linus Torvalds