[LWN Logo]
[LWN.net]

Sections:
 Main page
 Security
 Kernel
 Distributions
 Development
 Commerce
 Linux in the news
 Announcements
 Linux History
 Letters
All in one big page

See also: last week's Security page.

Security


News and Editorials

World Governments Choosing Linux for National Security (GovTech). Government Technology has an article on how security conscious governments are looking at Linux. "Security experts tend to agree that computers are less prone to hacking and viruses when running open-source software like Linux or the Web server Apache. When vulnerabilities are found, programmers can fix them by tinkering with the code and publishing the results." (Thanks to Robert K. Nelson).

Is Open-Source Security Software Safe? (BusinessWeek). Business Week considers Guardent's firewall box and whether companies will trust it. "Most important, removing the cost of software licenses makes a huge difference in the competitive field of managed security services, where Guardent hopes to make a big splash. Co-founder McCall thinks he can maintain profit margins in the 60% to 70% range with the open-source appliance. All of this might sound familiar to those who have watched Red Hat's struggle to create a workable model, one in which software is free and service revenues generate the profit." (Thanks to David A. Wheeler).

Guardent announces security appliance. Guardent has announced the availability of its "Security Defense Appliance," which is built on Linux. Along with the appliance customers are expected to buy a range of security monitoring and response services.

Security Reports

OpenSSH restricted command vulnerability clarification. Last week LWN reported that Red Hat issued the first update we had seen for the OpenSSH restricted command vulnerability first reported in the September 27 LWN security page. In fact, Immunix issued an alert in October and Debian fixed the vunerabilty in unstable on November 30th (Debian stable is not vulnerable). (Thanks to Seth Arnold and Matt Zimmerman).

Conectiva security update to mailman. Conectiva has issued a security update to mailman which fixes the cross-site scripting problem in that package.

Debian security update to wmtv. The Debian Project has issued a security update to wmtv fixing a really silly local root compromise vulnerability in that package.

web scripts. The following web scripts were reported to contain vulnerabilities:

Updates

Postfix session log memory exhaustion. Postfix 20010228, and some earlier verions, have a denial of service vulnerability. The SMTP session log could grow to an unreasonable size. (First LWN report: November 29, 2001).

This week's updates:

Previous updates:

Cyrus SASL format string vulnerability. A format string bug in the Cyrus SASL authentication API for mail clients and servers may be remotely exploitable. (First LWN report: November 29, 2001).

This week's updates:

Previous updates:

Directory indexing and path discovery in Apache. Versions of Apache prior to version 1.3.19 are vulnerable to a custom crafted request that can cause modules to misbehave and return a listing of the directory contents by avoiding the error page. (First LWN report: September 20, 2001).

This week's updates:

Previous updates:

Resources

Web Security, Privacy, and Commerce, Second Edition. O'Reilly has announced the release of the second edition of Web Security, Privacy, and Commerce by Gene Spafford and Simson Garfinkel.

Advanced Encryption Standard (AES) is a US cryptographic standard described in this government publication (PDF format). which was announced on December 4th. "AES was developed to replace the Data Encryption Standard (DES) in a multi-year effort that began in 1997. The AES specifies a cryptographic algorithm that can be used to protect electronic data by encrypting (enciphering) and decrypting (deciphering) information."

Events

CERT Conference 2002 has issued a call for papers. This fourth annual CERT Conference will be held in Omaha, Nebraska, USA August 6 - 9, 2002.

CodeCon 2002 is scheduled for February 15, 16, and 17 in San Francisco, California, USA. Those who would like to participate have until January 1st to answer the call for presentations.

Upcoming Security Events.
Date Event Location
December 13 - 14, 2001Annual Computer Security Applications ConferenceNew Orleans, LA
December 27 - 29, 200118th Chaos Communication CongressBerlin, Germany
January 30 - February 2, 2002Second Annual Privacy and Data Protection SummitWashington D.C., USA
February 15 - 17, 2002CODECON 2002San Francisco, California, USA

For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.

Section Editor: Dennis Tenney


December 13, 2001

LWN Resources


Secured Distributions:
Astaro Security
Castle
Engarde Secure Linux
Immunix
Kaladix Linux
NSA Security Enhanced
Openwall GNU/Linux
Trustix

Security Projects
Bastille
Linux Security Audit Project
Linux Security Module
OpenSSH

Security List Archives
Bugtraq Archive
Firewall Wizards Archive
ISN Archive

Distribution-specific links
Caldera Advisories
Conectiva Updates
Debian Alerts
Kondara Advisories
Esware Alerts
LinuxPPC Security Updates
Mandrake Updates
Red Hat Errata
SuSE Announcements
Turbolinux
Yellow Dog Errata

BSD-specific links
BSDi
FreeBSD
NetBSD
OpenBSD

Security mailing lists
Caldera
Cobalt
Conectiva
Debian
Esware
FreeBSD
Kondara
LASER5
Linux From Scratch
Linux-Mandrake
NetBSD
OpenBSD
Red Hat
Slackware
Stampede
SuSE
Trustix
turboLinux
Yellow Dog

Security Software Archives
munitions
ZedZ.net (formerly replay.com)

Miscellaneous Resources
CERT
CIAC
Comp Sec News Daily
Crypto-GRAM
LinuxLock.org
LinuxSecurity.com
Security Focus
SecurityPortal

 

Next: Kernel

 
Eklektix, Inc. Linux powered! Copyright © 2001 Eklektix, Inc., all rights reserved
Linux ® is a registered trademark of Linus Torvalds