Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2011:008 Date: Tue, 03 May 2011 11:00:00 +0000 Cross-References: CVE-2008-3834, CVE-2009-1189, CVE-2009-3555 CVE-2009-5022, CVE-2010-1321, CVE-2010-3332 CVE-2010-3574, CVE-2010-4159, CVE-2010-4352 CVE-2010-4447, CVE-2010-4448, CVE-2010-4450 CVE-2010-4454, CVE-2010-4462, CVE-2010-4465 CVE-2010-4466, CVE-2010-4468, CVE-2010-4471 CVE-2010-4473, CVE-2010-4475, CVE-2010-4476 CVE-2010-4661, CVE-2010-4665, CVE-2011-0411 CVE-2011-0719, CVE-2011-0995, CVE-2011-0996 CVE-2011-0997, CVE-2011-1167, CVE-2011-1485 Content of this advisory: 1) Solved Security Vulnerabilities: - java-1_6_0-ibm - java-1_5_0-ibm - java-1_4_2-ibm - postfix - dhcp6 - dhcpcd - mono-addon-bytefx-data-mysql/bytefx-data-mysql - dbus-1 - libtiff/libtiff-devel - cifs-mount/libnetapi-devel - rubygem-sqlite3 - gnutls - libpolkit0 - udisks 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3)Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - java-1_6_0-ibm IBM Java 6 SR9 FP1 was updated to fix a critical security bug in float number handling. CVE-2010-4476: The Java Runtime Environment hangs forever when converting "2.2250738585072012e-308" to a binary floating-point number. Affected Products: SLE10-SP4 - java-1_5_0-ibm IBM Java 5 was updated to SR 12 FP 4 fixing various security issues. For more details, please check the IBM JDK Alerts page: Following CVE entries are referenced by this update: CVE-2010-4447, CVE-2010-4448, CVE-2010-4450, CVE-2010-4454, CVE-2010-4462, CVE-2010-4465, CVE-2010-4466, CVE-2010-4468, CVE-2010-4471, CVE-2010-4473, CVE-2010-4475 Affected Products: SLES9, SLE10-SP3, SLE10-SP4 - java-1_4_2-ibm IBM Java 1.4.2 SR13 was updated to FP8 to fix various bugs and security issues. Following security issues were fixed: - CVE-2010-1321: The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing. - CVE-2010-3574:Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests. - CVE-2010-4476: The Java Runtime Environment hangs forever when converting "2.2250738585072012e-308" to a binary floating-point number. Affected Products: SLE10-SP4 - postfix postfix did not clear the receive buffer after the STARTTLS command. A man-in-the middle could therefore inject commands in the unencrypted stream that get interpreted in the encrypted phase after STARTTLS (CVE-2011-0411). Affected Products: SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2, 11.3, 11.4 - dhcp6 A rogue dhcp server could instruct clients to use a host name that contains shell meta characters. Since many scripts in the system do not expect unusal characters in the system's host name the dhcp client needs to sanitize the host name offered by the server (CVE-2011-0997). Affected Products: SLES9, SLE10-SP2, SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2, 11.3, 11.4 - dhcpcd This update fixes the following security issue: A rogue DHCP server could instruct clients to use a host name that contains shell meta characters. Since many scripts in the system do not expect unusal characters in the system's host name the DHCP client needs to sanitize the host name offered by the server (CVE-2011-0996). Note this update is actually just a re-release of the previous one. The security fix made dhcpcd crash if the DHCP server sent a SIP option thatwas not decodable. This update also allows spaces in the domain name option again as some DHCP servers abuse the option as DNS search list. This update also fixes the following non-security issues: - 564441: e1000 and dhcpd hickup - 579438: endless loop after adding wlan usb stick (with dhcp ip lease time infinity) - 654649: dhcpcd ignores -G (--nogateway) option and sets default route - 657402: dhcpcd sends RENEWAL as ethernet broadcast instead of unicast - 668194: dhcp client not working properly in Xen domU due to partial checksum offload - 672038: dhcpcd sends RENEWAL as ethernet broadcast instead of unicast - mono-addon-bytefx-data-mysql/bytefx-data-mysql Mono had loaded shared libraries from the current directory (CVE-2010-4159) and was also vunerable to a padding oracle attack (CVE-2010-3332) Affected Products: SLE10-SP3, SLE10-SP4, SLE11, SLE11-SP1 - dbus-1 Local users could crash the D-Bus daemon by sending a specially crafted message (CVE-2010-4352). This update also properly fixes CVE-2008-3834 and CVE-2009-1189. Affected Products: SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2, 11.3 - libtiff/libtiff-devel Specially crafted tiff files could cause a heap-based buffer overflow in the thunder-decoder (CVE-2011-1167). Directories with a large number of files could cause an integer overflow in the tiffdump tool (CVE-2010-4665) Affected Products: SLES9, SLE10-SP3, SLE11-SP1, openSUSE 11.2, 11.3, 11.4 - cifs-mount/libnetapi-devel With this update samba is not prone to a remote denial of service attack anymore. (CVE-2011-0719) Additionally this update also fixes the following reliability bugs: - leaving childs in "zombie" state - adding new printers without restart - GSSAPI lock AD user account - printer drivers from Windows 64-bit failing - MIGRATE PRINTERS failing on 64-bit Affected Products:SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2, 11.3 - rubygem-sqlite3 The package contained some world-writable files. Local users could exploit that to inject arbitrary code into programs using rubygem-sqlite3 (CVE-2011-0995). Affected Products: SLE11-SP1 - gnutls The SSL-renegotiation "authentication gap" has been fixed in GnuTLS. (CVE-2009-3555) Also an integer size issue was fixed which lead to incorrectly accepted certificates. Affected Products: SLES9 - libpolkit0 A race condition exists in pkexec while trying to determine its caller which could lead to privilege escalation. CVE-2011-1485 has been assigned to this issue. Affected Products: openSUSE 11.3, 11.4 - udisks This update of udisks improves input validation. Before it was possible to load arbitrary LKMs. (CVE-2010-4661: CVSS v2 Base Score: 4.6) Affected Products: openSUSE 11.3, 11.4 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained inyour key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2011:007 Date: Tue, 19 Apr 2011 12:00:00 +0000 Cross-References: CVE-2009-5065, CVE-2010-1172, CVE-2010-1455 CVE-2010-2283, CVE-2010-2284, CVE-2010-2285 CVE-2010-2286, CVE-2010-2287, CVE-2010-2935 CVE-2010-2936, CVE-2010-2992, CVE-2010-2993 CVE-2010-2994, CVE-2010-2995, CVE-2010-3089 CVE-2010-3445, CVE-2010-3450, CVE-2010-3451 CVE-2010-3452, CVE-2010-3453, CVE-2010-3454 CVE-2010-3689, CVE-2010-3702, CVE-2010-3704 CVE-2010-3814, CVE-2010-3855, CVE-2010-4253 CVE-2010-4300, CVE-2010-4301, CVE-2010-4538 CVE-2010-4643, CVE-2011-0285, CVE-2011-0444 CVE-2011-0445, CVE-2011-0460, CVE-2011-0530 CVE-2011-0538, CVE-2011-0707, CVE-2011-0713 CVE-2011-0988, CVE-2011-0989, CVE-2011-0990 CVE-2011-0991, CVE-2011-0992, CVE-2011-0993 CVE-2011-0996, CVE-2011-0997, CVE-2011-1000 CVE-2011-1006, CVE-2011-1022, CVE-2011-1024 CVE-2011-1081,CVE-2011-1138, CVE-2011-1139 CVE-2011-1140, CVE-2011-1143, CVE-2011-1146 CVE-2011-1156, CVE-2011-1157, CVE-2011-1158 CVE-2011-1488, CVE-2011-1489, CVE-2011-1490 CVE-2011-1574 Content of this advisory: 1) Solved Security Vulnerabilities: - NetworkManager - OpenOffice_org - apache2-slms - dbus-1-glib - dhcp/dhcpcd/dhcp6 - freetype2 - kbd - krb5 - libcgroup - libmodplug - libvirt - mailman - moonlight-plugin - nbd - openldap2 - pure-ftpd - python-feedparser - rsyslog - telepathy-gabble - wireshark 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - NetworkManager dbus-glib allowed local users to write properties that were exported read-only via dbus (CVE-2010-1172). Affected Products: openSUSE 11.2-11.3 - OpenOffice_org Maintenance update to LibreOffice-3.3.1. It adds some interesting features, fixes many bugs, including several security vulnerabilities. The previous OpenOffice_org packages are also renamed to libreoffice. LibreOffice is continuation of the OpenOffice.org project. This update replaces the OpenOffice.org installation, including helper packages, e.g. dictionaries, templates. The new stuff is backward compatible. Together with the maintenance update, the following security issues have been fixed: - PowerPoint document processing (CVE-2010-2935, CVE-2010-2936) - extensions and filter package files (CVE-2010-3450) - RTF document processing (CVE-2010-3451, CVE-2010-3452) - Word document processing (CVE-2010-3453, CVE-2010-3454) - insecure LD_LIBRARY_PATH usage (CVE-2010-3689) - PDF Import extension resulting from 3rd party library XPD (CVE-2010-3702, CVE-2010-3704) - PNG file processing (CVE-2010-4253) - TGA file processing (CVE-2010-4643) Affected Products: openSUSE 11.2-11.3 - apache2-slms This cumulative maintenance update provides a several important bug fixes for SUSE Lifecycle Management Server 1.1. The update should be applied also in case of upgrade from SUSE Lifecycle Management Server 1.0, before reconfiguring the product for the new version. Together with the maintenance update, the following security issues have been fixed: - don't log password also if error happen (never inspect unfiltered parameters) (bnc#644855) - Fix world-readable postgres credentials (bnc#684499) (CVE-2011-0993) Affected Products: SUSE Lifecycle Management Server 1.1 - dbus-1-glib dbus-glib allowed local users to write properties that were exported read-only via dbus (CVE-2010-1172). Affected Products: openSUSE 11.2-11.3 - dhcp/dhcpcd/dhcp6 A rogue dhcp server could instruct clients to use a host name that contains shell meta characters. Since many scripts in the system do not expect unusal characters in the system's host name the dhcp client needs to sanitize the host name offered by the server (CVE-2011-0996, CVE-2011-0997). AffectedProducts: SLES9, POS9, OES, SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2-11.4 - freetype2 Specially crafted font files could crash applications that use freetype2 to render the fonts (CVE-2010-3814, CVE-2010-3855). Affected Products: SLE10-SP3, SLE10-SP4, openSUSE 11.2-11.3 - kbd The kbd init scripted wrote a file to /dev/shm during shut-down. Since local users may create symlinks there a malicious user could cause corruption of arbitrary files. CVE-2011-0460 has been assigned to this issue. Affected Products: SLE11-SP1, openSUSE 11.2-11.3 - krb5 A remote attacker may be able to make kadmind free an invalid pointer, leading to a crash of the service (CVE-2011-0285). Affected Products: openSUSE 11.2-11.4 - libcgroup libcgroup suffered from a heap based buffer overflow (CVE-2011-1006). The cgrulesengd daemon did not verify the origin of netlink messages, allowing local users to spoof events (CVE-2011-1022). Affected Products: SLE11-SP1, openSUSE 11.2-11.3 - libmodplug Libmodplug is vulnerable to a stack based buffer overflow when handling malicious S3M media files. CVE-2011-1574 has been assigned to this issue. Affected Products: openSUSE 11.2-11.4 - libvirt several API calls did not honor the read-only flag connections. Attackers could exploit that to modify the state of the system or potentially execute code (CVE-2011-1146). Affected Products: openSUSE 11.2-11.4 - mailman mailman was updated to version 2.1.14 to fix several cross-site-scripting (XSS) vulnerabilities (CVE-2011-0707, CVE-2010-3089). Affected Products: openSUSE 11.3 - moonlight-plugin Moonlight was prone to several security problems: - CVE-2011-0989: modification of read-only values via RuntimeHelpers.InitializeArray - CVE-2011-0990: buffer overflow due to race condition in Array.FastCopy - CVE-2011-0991: use-after-free due to DynamicMethodresurrection - CVE-2011-0992: information leak due to improper thread finalization Affected Products: SLE11-SP1, openSUSE 11.3-11.4 - nbd A buffer overflow in the mainloop function the nbd server could allow remote attackers to execute arbitrary code (CVE-2011-0530). Affected Products: SLE10-SP3, SLE10-SP4, openSUSE 11.2-11.4 - openldap2 Master/slave configurations with enabled "ppolicy_forward_updates" option potentially allowed users to log in with an invalid password (CVE-2011-1024). Unauthenticated users could crash the ldap server (CVE-2011-1081). Affected Products: SLE11-SP1, openSUSE 11.2-11.4 - pure-ftpd pure-ftpd was updated to fix a security issue with a Open Enterprise Server specific patch. - CVE-2011-0988: A worldwriteable directory created and used by the OES pure-ftpd Netware extensions could be used by local attackers to overwrite system files and so gain privileges. Affected Products: SLE10-SP3, SLE10-SP4 - python-feedparser Various issues in python-feedparser have been fixed, including fixes for crashes due to missing input sanitizaion and a XSS vulnerability. CVE-2011-1156, CVE-2011-1157, CVE-2011-1158 and CVE-2009-5065 have been assigned to these issues. Affected Products: openSUSE 11.2-11.4 - rsyslog rsyslog was updated to version 5.6.5 to fix a number of memory leaks that could crash the syslog daemon (CVE-2011-1488, CVE-2011-1489, CVE-2011-1490). Affected Products: openSUSE 11.4 - telepathy-gabble This update of telepathy-gabble is validating the origin of a google:jingleinfo update message now. Not validating the origin could be used to intercept calls. CVE-2011-1000: CVSS v2 Base Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N): Input Validation (CWE-20) Affected Products: openSUSE 11.2-11.3 - wireshark Wireshark was updated to version 1.4.4 to fix several security issues (CVE-2010-1455, CVE-2010-2283, CVE-2010-2284, CVE-2010-2285, CVE-2010-2286, CVE-2010-2287, CVE-2010-2992, CVE-2010-2993, CVE-2010-2994, CVE-2010-2995, CVE-2010-3445, CVE-2010-4300, CVE-2010-4301, CVE-2010-4538, CVE-2011-0444, CVE-2011-0445, CVE-2011-0538, CVE-2011-0713, CVE-2011-1138, CVE-2011-1139, CVE-2011-1140, CVE-2011-1143) Affected Products: SLE10-SP3, SLE10-SP4, SLE11-SP1, openSUSE 11.2-11.4 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. Theinternal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2010:007 Date: Tue, 30 Mar 2010 10:00:00 +0000 Cross-References: CVE-2008-6514, CVE-2008-7247, CVE-2009-1299 CVE-2009-2563, CVE-2009-2855, CVE-2009-3553 CVE-2009-4019, CVE-2009-4028, CVE-2009-4030 CVE-2009-4376, CVE-2009-4377, CVE-2009-4484 CVE-2010-0302, CVE-2010-0304, CVE-2010-0308 CVE-2010-0393, CVE-2010-0424, CVE-2010-0547 CVE-2010-0628, CVE-2010-0736, CVE-2010-0926 Content of this advisory: 1) Solved Security Vulnerabilities: - cifs-mount/samba - compiz-fusion-plugins-main - cron - cups - ethereal/wireshark - krb5 - mysql - pulseaudio - squid/squid3 - viewvc 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reportsdo not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - cifs-mount/samba With enabled "wide links" samba follows symbolic links on the server side, therefore allowing clients to overwrite arbitrary files (CVE-2010-0926). This update changes the default setting to have "wide links" disabled by default. The new default only works if "wide links" is not set explicitly in smb.conf. Due to a race condition in mount.cifs a local attacker could corrupt /etc/mtab if mount.cifs is installed setuid root. mount.cifs is not setuid root by default and it's not recommended to change that (CVE-2010-0547). Affected products: SLE 11, openSUSE 11.0-11.2 - compiz-fusion-plugins-main The expo plugin in Compiz Fusion allowed local users with physical access to bypass the screen-saver by just dragging it aside. (CVE-2008-6514: CVSS v2 Base Score: 6.2) Affected products: SLE 11, openSUSE 11.0-11.2 - cron This update of cron fixes a race condition in crontab that can be used to change the time-stamp of arbitrary files while editing the crontab entry. CVE-2010-0424: CVSS v2 Base Score: 3.6 Additionally the return value of initgroups() is verified now. Affected products: SLE 10 SP2+SP3 , SLE 11, openSUSE 11.0-11.2, Moblin 2.0-2.1 - cups lppasswd when running setuid or setgid still honors environment variables that specify the location of message files. Local attackers could exploit that to gather information by using crafted format strings (CVE-2010-0393). The previous fix for a use-after-free vulnerability (CVE-2009-3553) was incomplete (CVE-2010-0302). Affected products: SLE 11, openSUSE 11.0-11.2, Moblin 2.0-2.1 - ethereal/wireshark This update of ethereal fixes: -CVE-2009-4376: Remote attackers could potentially trigger a buffer overflow in the Daintree SNA file parser. - CVE-2009-4377: Specially crafted packets could cause the SMB and SMB2 dissector to crash wireshark. - CVE-2009-2563: Unspecified vulnerability in the Infiniband dissector allows remote attackers to cause a denial of service. - CVE-2010-0304: Several buffer overflows in the LWRES dissector. Affected products: SLES 9, SLE 10 SP2+SP3, SLE 11, openSUSE 11.0-11.2 - krb5 MITKRB5-SA-2010-002: unauthenticated remote attacker could cause a GSS-API application including the Kerberos administration daemon (kadmind) to crash. CVE-2010-0628 has been assigned to this issue. Affected products: openSUSE 11.2 - mysql - fixing various security issues (bnc#557669) - upstream #47320 - checking server certificates (CVE-2009-4028) - upstream #48291 - error handling in subqueries (CVE-2009-4019) - upstream #47780 - preserving null_value flag in GeomFromWKB() (CVE-2009-4019) - upstream #39277 - symlink behaviour fixed (CVE-2008-7247) - upstream #32167 - symlink behaviour refixed (CVE-2009-4030) - fixing remote buffer overflow (CVE-2009-4484) Affected products: SLE 10 SP2+SP3 - pulseaudio Due to a race condition in pulseaudio a local attacker could make pulseaudio change ownership and permissions of arbitrary files. The problem is only security relevant if pulseaudio is run in "system mode" which is not the case by default (CVE-2009-1299). Affected products: openSUSE 11.0-11.2 - squid/squid3 The following vulnerabilities have been fixed in squid: - CVE-2009-2855: DoS via special crafted auth header - CVE-2010-0308: DoS via invalid DoS header Affected products: SLES 9, SLE 10 SP2+SP3, SLE 11, openSUSE 11.0-11.2 - viewvc Query forms didn't escape user provided input, therefore allowing cross-site-scripting (XSS) attacks. CVE-2010-0736 has been assigned to this issue. Affected products: openSUSE 11.0-11.2 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2010:006 Date: Mon, 15 Mar 2010 11:11:00 +0000 Cross-References: CVE-2008-7248, CVE-2009-0547, CVE-2009-3736 CVE-2009-4214, CVE-2009-4274, CVE-2009-4565 CVE-2010-0013, CVE-2010-0186, CVE-2010-0187 CVE-2010-0188, CVE-2010-0277, CVE-2010-0409 CVE-2010-0420, CVE-2010-0423, CVE-2010-0426 CVE-2010-0427 Content of this advisory: 1) Solved Security Vulnerabilities: - acroread - evolution-data-server - finch/pidgin/libpurple - flash-player - gmime-2_4 - libnetpbm - libtool - rmail/sendmail/uucp - rubygem-actionpack-2_0 - sudo 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are releasedfor more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - acroread This update of acroread fixes: - CVE-2010-0186: CVSS v2 Base Score: 5.8 Cross-domain request vulnerability - CVE-2010-0188: CVSS v2 Base Score: 6.8 An unspecified vulnerability that possibly allowed remote code execution. Affected products: SLED 10 SP2 + SP3, SLE 11, openSUSE 11.0-11.2, Moblin 2.0 - evolution-data-server This update fixes one vulnerability: - evolution considered S/MIME signatures to be valid even for modified mails (CVE-2009-0547: CVSS v2 Base Score: 5.0). A POP3 server sending overly long lines could crash evolution. Affected products: SLE 11 - finch/pidgin/libpurple This update of pidgin fixes various security vulnerabilities - CVE-2010-0013: CVSS v2 Base Score: 4.3: Path Traversal (CWE-22) Remote file disclosure vulnerability by using the MSN protocol. - CVE-2010-0277: CVSS v2 Base Score: 4.9: Resource Management Errors (CWE-399) MSN protocol plugin in libpurple allowed remote attackers to cause a denial of service (memory corruption) at least. - CVE-2010-0420 Same nick names in XMPP MUC lead to a crash in finch. - CVE-2010-0423 A remote denial of service attack (resource consumption) is possible by sending an IM with a lot of smilies in it. Affected products: SLES 10 SP2 + SP3, SLE 11, openSUSE 11.0-11.2, Moblin 2.0-2.1 - flash-player Insufficient checks in flash-player allowed malicious flash applets to create illegal cross-domain requests (CVE-2010-0186). The update also fixes a denial of service condition (CVE-2010-0187). Affected products: Moblin 2.0-2.1 - gmime-2_4 This update of gmime fixes a buffer overflow in the GMIME_UUENCODE_LEN macro which allowed possible code execution while processing uuencoded data.(CVE-2010-0409: CVSS v2 Base Score: 5.8) Affected products: SLE 11, openSUSE 11.0-11.2 - libnetpbm This update of netpbm fxes a stack-based buffer overflow that could be triggered while processing the contents of XPM headers in image files. (CVE-2009-4274: CVSS v2 Base Score: 5.8 (moderate) (AV:N/AC:M/Au:N/C:N/I:P/A:P): Buffer Errors (CWE-119)) Affected products: SLES 9, OES, POS 9, SLE 10 SP2 + SP3, SLE 11, openSUSE 11.0-11.2 - libtool libtool: libltdl may load modules from the current working directory. CVE-2009-3736 has been assigned to this issue. Affected products: NLD 9, POS 9, OES, SLES 9 - rmail/sendmail/uucp This update of sendmail improves the handling of special-characters in the SSL certificate. (CVE-2009-4565: CVSS v2 Base Score: 7.5) Affected products: POS 9, SLES 9, OES, SLE 10 SP2 + SP3, SLE 11, openSUSE 11.0-11.2 - rubygem-actionpack-2_0 This update of rubygems fixes two vulnerabilities: - CVE-2008-7248: CVSS v2 Base Score: 4.3 Rails CSRF protection can be bypassed by using special content-types for a HTTP request. - CVE-2009-4214: CVSS v2 Base Score: 4.3 The method strip_tags does not completely protect agains XSS attacks. Affected products: SLE 10 SP2 + SP3, SLE 11, openSUSE 11.2 - sudo This update fixes the following security issue: - CVE-2010-0426:CVSS v2 Base Score: 6.6 A privilege escalation flaw was found in the way sudo used to check file paths for pseudocommands. If local, unprivileged user was authorized by sudoers file to edit one or more files, it could lead to execution of arbitrary code, with the privileges of privileged system user (root). - CVE-2010-0427:CVSS v2 Base Score: 6.6 Sudo failed to properly reset group permissions, when 'runas_default' option was used. If a local, unprivileged user was authorized by sudoers file to perform their sudocommands under default user account, it could lead to privilege escalation Affected products: SLE 10 SP2 + SP3, SLE 11, openSUSE 11.0-11.2 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodifiedif it contains a valid signature from
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2009:008 Date: Mon, 06 Apr 2009 15:00:00 +0000 Cross-References: CVE-2008-0928, CVE-2008-1945, CVE-2008-2025 CVE-2008-2382, CVE-2008-4311, CVE-2008-4539 CVE-2008-5498, CVE-2008-5557, CVE-2008-5714 CVE-2009-0021, CVE-2009-0115, CVE-2009-0186 CVE-2009-0754, CVE-2009-1148, CVE-2009-1149 CVE-2009-1150, CVE-2009-1151 Content of this advisory: 1) Solved Security Vulnerabilities: - multipath-tools - bluez - xntp - apache-mod_php4 - apache2-mod_php5 - struts - qemu - libsndfile - phpMyAdmin 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - multipath-tools Default permissions on the multipathd socket file were to generous and allowed any user to connect (CVE-2009-0115). Affected products: SLES9, OES, NLD9 - bluez The dbus package used a too permissive configuration. Therefore intended access control for some services was not applied (CVE-2008-4311). The new configuration denies access by default. Some dbus services may break due to this setting and need an updated configuration as well. Affected products: openSUSE 10.3 - xntp ntp didn't properly check the return value of the openssl function EVP_VerifyFinal (CVE-2009-0021). Additionally a problem where ntpd refused to use keys from /etc/ntp.keys has been fixed. Affected products: SLES10-SP2 - apache-mod_php4 Specially crafted strings could trigger a heap based buffer overflow in the php mbstring extension. Attackers could potenially exploit that to execute arbitrary code (CVE-2008-5557). Affected products: SLES9, OES - apache2-mod_php5 php 5.2.9 fixes among other things some security issues: + Missing bounds checks of an error in the imageRotate function of the gd extension potentially allowed attackers to read portions of memory (CVE-2008-5498). + the mbstring.func_overload in .htaccess was applied to other virtual hosts on th same machine (CVE-2009-0754) Affected products: openSUSE 10.3-11.1, SLES10, SLES11 - struts Insufficient quoting of parameters allowed attackers to conduct cross site scripting (XSS) attacks (CVE-2008-2025). Affected products: openSUSE 10.3-11.1, SLES10, SLES11 - qemu qemu update to version 0.10.1 fixes the following security issues: + CVE-2008-0928: problems with range checks of block devices + CVE-2008-1945: problems with removable media handling + CVE-2008-2382: vncserver DoS + CVE-2008-4539: fix a heap overflow in the cirrus VGA implementation + CVE-2008-5714: off by one error in vnc password handling Affected products: openSUSE 10.3-11.1, SLES10, SLES11 - libsndfile Specially crafted CAF files could cause an integer overflow in libsndfile (CVE-2009-0186). Affected products: openSUSE 10.3-11.1, SLES10, SLES11 - phpMyAdmin This update of phpMyAdmin fixes multiple vulnerabilities: + CVE-2009-1148: directory traversal + CVE-2009-1149: CRLF injection + CVE-2009-1150: cross-site scripting + CVE-2009-1151: static code injection Affected products: openSUSE 10.3-11.0 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
Get the latest Linux and open source security news straight to your inbox.