[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

UNIRAS Brief - 308/06 - Four Gentoo Linux Security Advisories:



----------------------------------------------------------------------------------
   UNIRAS (UK Govt CERT) Briefing Notice - 308/06 dated 26.04.06  Time: 13:45  
  UNIRAS is part of NISCC (National Infrastructure Security Co-ordination Centre)
---------------------------------------------------------------------------------- 
  UNIRAS material is also available from its website at www.uniras.gov.uk and
         Information about NISCC is available from www.niscc.gov.uk
----------------------------------------------------------------------------------

Title
=====


-----BEGIN PGP SIGNED MESSAGE-----

Four Gentoo Linux Security Advisories:

1. GLSA 200604-11 - Crossfire server: Denial of Service and potential arbitrary
code execution

2. GLSA 200604-12 - Mozilla Firefox: Multiple vulnerabilities

3. GLSA 200604-13 - fbida: Insecure temporary file creation

4. GLSA 200604-14 - Dia: Arbitrary code execution through XFig import

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQCVAwUBRE9rOYpao72zK539AQET4wP/bPLsMm6/2i3/qSk+XreePg2xcQi5sYOQ
6ezMfRH3bv6XMfXEwzMKeLJTc6TyOMDBq7OELdT5RRCOWEvgLyQKOhlZgul1eL1y
nM5+SDFESGJJ8xdJhnIyksrCQXUOngg8BRSqyD30Tn85gGyU8WUGGOkv6WhRmS34
pGhKg4r/wTQ=
=XNJ5
-----END PGP SIGNATURE-----

Detail
====== 

1. Luigi Auriemma discovered a vulnerability in the Crossfire game server,
in the handling of the "oldsocketmode" option when processing overly
large requests. 

2. Several vulnerabilities were found in Mozilla Firefox. Versions 1.0.8
and 1.5.0.2 were released to fix them.

3. Jan Braun has discovered that the "fbgs" script provided by fbida
insecurely creates temporary files in the "/var/tmp" directory.

4. infamous41md discovered multiple buffer overflows in Dia's XFig file
import plugin.



1.



- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200604-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: Crossfire server: Denial of Service and potential arbitrary
            code execution
      Date: April 22, 2006
      Bugs: #126169
        ID: 200604-11

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

The Crossfire game server is vulnerable to a Denial of Service and
potentially to the execution of arbitrary code.

Background
==========

Crossfire is a cooperative multiplayer graphical adventure and
role-playing game. The Crossfire game server allows various compatible
clients to connect to participate in a cooperative game.

Affected packages
=================

    -------------------------------------------------------------------
     Package                        /  Vulnerable  /        Unaffected
    -------------------------------------------------------------------
  1  games-server/crossfire-server       < 1.9.0              >= 1.9.0

Description
===========

Luigi Auriemma discovered a vulnerability in the Crossfire game server,
in the handling of the "oldsocketmode" option when processing overly
large requests.

Impact
======

An attacker can set up a malicious Crossfire client that would send a
large request in "oldsocketmode", resulting in a Denial of Service on
the Crossfire server and potentially in the execution of arbitrary code
on the server with the rights of the game server.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Crossfire server users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose
">=games-server/crossfire-server-1.9.0"

References
==========

  [ 1 ] CVE-2006-1010
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1010

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200604-11.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@xxxxxxxxxx or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



2.



- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200604-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: Mozilla Firefox: Multiple vulnerabilities
      Date: April 23, 2006
      Bugs: #129924
        ID: 200604-12

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Several vulnerabilities in Mozilla Firefox allow attacks ranging from
execution of script code with elevated privileges to information
leaks.

Background
==========

Mozilla Firefox is the next-generation web browser from the Mozilla
project.

Affected packages
=================

    -------------------------------------------------------------------
     Package                         /  Vulnerable  /       Unaffected
    -------------------------------------------------------------------
  1  www-client/mozilla-firefox           < 1.0.8             >= 1.0.8
  2  www-client/mozilla-firefox-bin       < 1.0.8             >= 1.0.8
    -------------------------------------------------------------------
     2 affected packages on all of their supported architectures.
    -------------------------------------------------------------------

Description
===========

Several vulnerabilities were found in Mozilla Firefox. Versions 1.0.8
and 1.5.0.2 were released to fix them.

Impact
======

A remote attacker could craft malicious web pages that would leverage
these issues to inject and execute arbitrary script code with elevated
privileges, steal local files, cookies or other information from web
pages, and spoof content. Some of these vulnerabilities might even be
exploited to execute arbitrary code with the rights of the browser
user.

Workaround
==========

There are no known workarounds for all the issues at this time.

Resolution
==========

All Mozilla Firefox users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.8"

All Mozilla Firefox binary users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose
">=www-client/mozilla-firefox-bin-1.0.8"

References
==========

  [ 1 ] CVE-2005-4134
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134
  [ 2 ] CVE-2006-0292
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0292
  [ 3 ] CVE-2006-0296
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0296
  [ 4 ] CVE-2006-0748
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748
  [ 5 ] CVE-2006-0749
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749
  [ 6 ] CVE-2006-1727
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727
  [ 7 ] CVE-2006-1728
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728
  [ 8 ] CVE-2006-1729
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729
  [ 9 ] CVE-2006-1730
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730
  [ 10 ] CVE-2006-1731
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731
  [ 11 ] CVE-2006-1732
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732
  [ 12 ] CVE-2006-1733
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733
  [ 13 ] CVE-2006-1734
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734
  [ 14 ] CVE-2006-1735
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735
  [ 15 ] CVE-2006-1736
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1736
  [ 16 ] CVE-2006-1737
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737
  [ 17 ] CVE-2006-1738
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738
  [ 18 ] CVE-2006-1739
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739
  [ 19 ] CVE-2006-1740
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740
  [ 20 ] CVE-2006-1741
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741
  [ 21 ] CVE-2006-1742
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742
  [ 22 ] CVE-2006-1790
         http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790
  [ 23 ] Mozilla Foundation Security Advisories

http://www.mozilla.org/projects/security/known-vulnerabilities.html#Firefox

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200604-12.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@xxxxxxxxxx or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



3. 


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200604-13
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: fbida: Insecure temporary file creation
      Date: April 23, 2006
      Bugs: #129470
        ID: 200604-13

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

fbida is vulnerable to linking attacks, potentially allowing a local
user to overwrite arbitrary files.

Background
==========

fbida is a collection of image viewers and editors for the framebuffer
console and X11.

Affected packages
=================

    -------------------------------------------------------------------
     Package          /  Vulnerable  /                      Unaffected
    -------------------------------------------------------------------
  1  media-gfx/fbida      < 2.03-r3                         >= 2.03-r3

Description
===========

Jan Braun has discovered that the "fbgs" script provided by fbida
insecurely creates temporary files in the "/var/tmp" directory.

Impact
======

A local attacker could create links in the temporary file directory,
pointing to a valid file somewhere on the filesystem. When an affected
script is called, this could result in the file being overwritten with
the rights of the user running the script.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All fbida users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-gfx/fbida-2.03-r3"

References
==========

  [ 1 ] CVE-2006-1695
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1695

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200604-13.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@xxxxxxxxxx or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



4.


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200604-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: Dia: Arbitrary code execution through XFig import
      Date: April 23, 2006
      Bugs: #128107
        ID: 200604-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Buffer overflows in Dia's XFig import could allow remote attackers to
execute arbitrary code.

Background
==========

Dia is a GTK+ based diagram creation program.

Affected packages
=================

    -------------------------------------------------------------------
     Package         /  Vulnerable  /                       Unaffected
    -------------------------------------------------------------------
  1  app-office/dia      < 0.94-r5                          >= 0.94-r5

Description
===========

infamous41md discovered multiple buffer overflows in Dia's XFig file
import plugin.

Impact
======

By enticing a user to import a specially crafted XFig file into Dia, an
attacker could exploit this issue to execute arbitrary code with the
rights of the user running Dia.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Dia users should upgrade to the latest available version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-office/dia-0.94-r5"

References
==========

  [ 1 ] CVE-2006-1550
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1550

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200604-14.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@xxxxxxxxxx or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



----------------------------------------------------------------------------------

For additional information or assistance, please contact the HELP Desk by 
telephone or Not Protectively Marked information may be sent via 
EMail to: uniras@xxxxxxxxxxxx

Office Hours:
Mon - Fri: 08:30 - 17:00 Hrs
Tel: +44 (0) 870 487 0748 Ext 4511
Fax: +44 (0) 870 487 0749

Outside of Office Hours:
On Call Duty Officer:
Tel: +44 (0) 870 487 0748 and follow the prompts

----------------------------------------------------------------------------------
UNIRAS wishes to acknowledge the contributions of Gentoo for the information 
contained in this Briefing. 
----------------------------------------------------------------------------------
This Briefing contains the information released by the original author. Some 
of the information may have changed since it was released. If the vulnerability 
affects you, it may be prudent to retrieve the advisory from the site of the
original source to ensure that you receive the most current information concerning 
that problem.

Reference to any specific commercial product, process, or service by trade 
name, trademark manufacturer, or otherwise, does not constitute or imply 
its endorsement, recommendation, or favouring by UNIRAS or NISCC.  The views 
and opinions of authors expressed within this notice shall not be used for 
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors 
or omissions contained within this briefing notice. In particular, they shall 
not be liable for any loss or damage whatsoever, arising from or in connection 
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST) 
and has contacts with other international Incident Response Teams (IRTs) in 
order to foster cooperation and coordination in incident prevention, to prompt 
rapid reaction to incidents, and to promote information sharing amongst its 
members and the community at large. 
----------------------------------------------------------------------------------
<End of UNIRAS Briefing>


______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________