Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
91

Gentoo: GLSA-200701-28 Low: thttpd Unauthenticated Remote Access

The default configuration of the Gentoo thttpd package potentially allows unauthenticated access to system files when used with newer versions of baselayout. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: thttpd: Unauthenticated remote file access Date: January 31, 2007 Bugs: #142047 ID: 200701-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The default configuration of the Gentoo thttpd package potentially allows unauthenticated access to system files when used with newer versions of baselayout. Background ========= thttpd is a webserver designed to be simple, small, and fast. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/thttpd < 2.25b-r6 > = 2.25b-r6 Description ========== thttpd is vulnerable to an underlying change made to the start-stop-daemon command in the current stable Gentoo baselayout package (version 1.12.6). In the new version, the start-stop-daemon command performs a "chdir /" command just before starting the thttpd process. In the Gentoo default configuration, this causes thttpd to start with the document root set to "/", the sytem root directory. Impact ===== When thttpd starts with the document root set to the system root directory, all files on the system that are readable by the thttpd process can be remotely accessed by unauthenticated users. Workaround ========= Alter the THTTPD_OPTS variable in /etc/conf.d/thttpd to includethe "-d" option to specify the document root. Alternatively, modify the THTTPD_OPTS variable in /etc/conf.d/thttpd to specify a thttpd.conf file using the "-C" option, and then configure the "dir=" directive in that thttpd.conf file. Resolution ========= All thttpd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-servers/thttpd-2.25b-r5" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200701-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo thttpd Security Advisory GLSA 202101-15 outlines a vulnerability that may allow improper access to sensitive system resources.. Gentoo, thttpd, remote access, security advisory, low severity. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jan 31, 2007 Low Gentoo
87

Debian Sarge: DSA 1205-2 Moderate: Thttpd Symlink Vulnerability

Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack. The original advisory for this issue didn't contain fixed packages for all supported architectures which are corrected in this update. . - --------------------------------------------------------------------------Debian Security Advisory DSA 1205-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp December 1sd, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : thttpd Vulnerability : insecure temporary files Problem-Type : local Debian-specific: yes CVE ID : CVE-2006-4248 Debian Bug : 396277 Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack. The original advisory for this issue didn't contain fixed packages for all supported architectures which are corrected in this update. For the stable distribution (sarge) this problem has been fixed in version 2.23beta1-3sarge2 For the unstable distribution (sid) this problem has been fixed in version 2.23beta1-5 We recommend that you upgrade your thttpd package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 614 0f9a3730f341fa0151596a3b9f20764d Size/MD5 checksum: 14313 8545dd3d0f7a2083ecca36e53e72bd6b Size/MD5 checksum: 128712 d3d91f6596f53d5e2b27cea8607d5bba Alpha architecture: Size/MD5 checksum: 59270 d4076615e782deb79cabae37733de534 Size/MD5 checksum: 28056 ee6e6ccccb7619755da6478e349d03fd AMD64 architecture: Size/MD5 checksum: 56090 59ab35cd4a12c7a010229e793d3d031b Size/MD5 checksum: 26518 76286320653018389937886b1e6b2cfa ARM architecture: Size/MD5 checksum: 53230 cf8a02a2f0f3bd64522f79111f079642 Size/MD5 checksum: 24694 88d75dcab4fa8bca63f48afb04ded258 HP Precision architecture: Size/MD5 checksum: 57420 0104f76c6a50be56598ecb7ebb6317a4 Size/MD5 checksum: 26984 46a6908e5e1a0c02bb6b065ed6fab80d Intel IA-32 architecture: Size/MD5 checksum: 51180 991b1072ebd903b6a9ee316b1bfdc8c6 Size/MD5 checksum: 24776 fd3dddb60d160a6245da4c7efd5dcfe4 Intel IA-64 architecture: Size/MD5 checksum: 71992 3ae1510acb0dad29743795678058e467 Size/MD5 checksum: 30360 d1b09a54ddb43b6cf5b080e59dbb9792 Motorola 680x0 architecture: Size/MD5 checksum: 50170 58f820e0cc1ff0921d641fc4f340d4ae Size/MD5 checksum: 24834 fd383afb658a319f594056f14107c6f7 Big endian MIPS architecture: Size/MD5 checksum: 57060 d42bd66e806d204f9b01559148cbbbea Size/MD5 checksum: 31062 b2fedfffe04d03b9d4d7d2316669735e Little endian MIPS architecture: Size/MD5 checksum: 57168 4407a2da69e31159642973201900f64e Size/MD5 checksum: 31188 3a9282003d6785a05ef91a17c646eb1b PowerPC architecture: Size/MD5 checksum: 53466 24b0524b9944d1bb9e2d8451035be5a0 Size/MD5 checksum: 25232 8686e26fba64af5040a2484e1c626f06 IBM S/390 architecture: Size/MD5checksum: 56264 6b018396fae8f11be8d6dc2ddae99762 Size/MD5 checksum: 26344 f7c45e7292b79e9e047982519ed7717b Sun Sparc architecture: Size/MD5 checksum: 53338 3d5315a2b44da8acd151bc714ca45efc Size/MD5 checksum: 24796 a64846770af6a96a1ae30d0b02fda299 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . To fix insecure temporary file creation in thttpd on Debian, update your package list, upgrade thttpd, secure temp directories, and restart the service. Debian thttpd update, security fix, temporary file issue, DoS threat, symlink attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 01, 2006 Important Debian
87

Debian: DSA-1205-1 Critical: Thttpd Insecure Temporary File Handling

Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1205-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp November 2rd, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : thttpd Vulnerability : insecure temporary files Problem-Type : local Debian-specific: yes CVE ID : CVE-2006-4248 Debian Bug : 396277 Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack. For the stable distribution (sarge) this problem has been fixed in version 2.23beta1-3sarge2 For the unstable distribution (sid) this problem has been fixed in version 2.23beta1-5 We recommend that you upgrade your thttpd package. Upgrade Instructions - - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - - -------------------------------- Source archives: Size/MD5 checksum: 614 0f9a3730f341fa0151596a3b9f20764d Size/MD5 checksum: 14313 8545dd3d0f7a2083ecca36e53e72bd6b Size/MD5 checksum: 128712 d3d91f6596f53d5e2b27cea8607d5bba Alpha architecture: Size/MD5 checksum: 59240 f6854853b290fe2ce1a925cbbea3856a Size/MD5 checksum: 27978 6b4680363644b459e0e47222985f749f AMD64 architecture: Size/MD5 checksum: 56034 9848065d7700f2f6e0a036ee76e8fcf7 Size/MD5 checksum: 26456 befb78e032aa654e5fcfcc7c9fdff21b ARM architecture: Size/MD5 checksum: 53198 6a9c1e8afaa60a7b4b7787729dd97b9b Size/MD5 checksum: 24610 f35f8b0a749694fea536296d2a41e1f0 HP Precision architecture: Size/MD5 checksum: 57374 4755b42efc9a48b59b1e745862e01098 Size/MD5 checksum: 26912 557472d5a3e182b86999baa0b89846ba Intel IA-32 architecture: Size/MD5 checksum: 51180 991b1072ebd903b6a9ee316b1bfdc8c6 Size/MD5 checksum: 24776 fd3dddb60d160a6245da4c7efd5dcfe4 Intel IA-64 architecture: Size/MD5 checksum: 71954 924db7bf3beb5ce3c0e5018759aef3d6 Size/MD5 checksum: 30276 530abc02e3c392a91bff06fe1d8ce7af Motorola 680x0 architecture: Size/MD5 checksum: 50132 bcb24b62afb868c5e04b8c1db66e6cc3 Size/MD5 checksum: 24756 4b30d87639b3d6b7ca58537cf16c6953 Big endian MIPS architecture: Size/MD5 checksum: 57044 410e480e061a3876b7ff01beaffb571e Size/MD5 checksum: 30980 2cda342ba6a04fdbe0a938359eeff813 Little endian MIPS architecture: Size/MD5 checksum: 57112 fe0268048af2940619a9380d7cd83626 Size/MD5 checksum: 31126 64e73613ca88afa3fd379b657c80a414 PowerPC architecture: Size/MD5 checksum: 53442 58c39568158a4c3da81efcaf6a0ab838 Size/MD5 checksum: 25160 a5ff28da9df6080438012db8014b0212 IBM S/390 architecture: Size/MD5 checksum: 56214 f39998665c2df9236d2902120eb977f9 Size/MD5 checksum: 26268 34e822b698803e3e0139430aea707f55 Sun Sparc architecture: Size/MD5 checksum: 53298 a8dcaf92cb41b607618b4a271927c250 Size/MD5 checksum: 2471854c4e9dac68c9b8472dc92fe6966f6e4 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. marco, d'itri, thttpd, small, secure, webserver, makes, insecure, tempo. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 03, 2006 Critical Debian
87

Debian: DSA 883-2 Critical: Rsync Insecure Directory Permissions Flaw

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 883-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze November 4th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : thttpd Vulnerability : insecure temporary file Problem type : local Debian-specific: no CVE ID : CVE-2005-3124 Javier Fernández-Sanguino Peña from the Debian Security Audit team discovered that the syslogtocern script from thttpd, a tiny webserver, uses a temporary file insecurely, allowing a local attacker to craft a symlink attack to overwrite arbitrary files. For the old stable distribution (woody) this problem has been fixed in version 2.21b-11.3. For the stable distribution (sarge) this problem has been fixed in version 2.23beta1-3sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.23beta1-4. We recommend that you upgrade your thttpd package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 545 ba3c0bb15f6212db97bcf6d6524d4780 Size/MD5 checksum: 12672 47c8093a645102ea2f328455195e763c Size/MD5 checksum: 127157 9c1512664cf70c286331243ab622173e Alpha architecture: Size/MD5 checksum: 67624 465efe17c6bf662b1b191b91c8cd8491 Size/MD5 checksum: 27940 3830272b2dae0993fa96b4bb014feb09 ARM architecture: Size/MD5 checksum: 54272 fd2de8fb819e11c5a0a91ad4546d3b07 Size/MD5 checksum: 23384 9a02e239a4d792547e088b2e7047d08a Intel IA-32 architecture: Size/MD5 checksum: 51996 5c6c5f4bda6ecf89c095595ae7d47e0a Size/MD5 checksum: 23732 b86b4669f89ea162f965430181004097 Intel IA-64 architecture: Size/MD5 checksum: 78060 ae4c37cfeb4bb00aabe86fb53ac8d320 Size/MD5 checksum: 29732 3f7102053a50f0c67edc8d566e3707e8 HP Precision architecture: Size/MD5 checksum: 59244 1b007a6734c854b6a313e3a48c59b5d3 Size/MD5 checksum: 25618 1c4087f8fa972c8ec9364fb422b1f399 Motorola 680x0 architecture: Size/MD5 checksum: 49632 f1cc7d708bbcf9fc34fe5382b8370bd3 Size/MD5 checksum: 23386 4b6af55203f640969e0ca8fadd3ebf7d Big endian MIPS architecture: Size/MD5 checksum: 58302 e6c7222513bd7b96a09fb53f16447552 Size/MD5 checksum: 24670 2f575c075a755b452ee27749cab8e72d Little endian MIPS architecture: Size/MD5 checksum: 58424 af4447af28817c182ffe85b2f1ddbaa4 Size/MD5 checksum: 24744 9b7b47b0e29e90a4805edfb960912db5 PowerPC architecture: Size/MD5 checksum: 56558 cd91f39ec6a4b76377fb62f93eb31f8d Size/MD5 checksum: 23992 7d582bab26cb31d3b9b109008cc5d493 IBM S/390 architecture: Size/MD5 checksum: 54762 72de109e9fd79a02ea9de27619a26923 Size/MD5 checksum: 24536 6bd0b8d4676a15c349905b0b70bb7c65 Sun Sparc architecture: Size/MD5 checksum: 58326 5e288c30abd19e26ed1121585e83c52c Size/MD5 checksum: 30104 dc9d39c3a3aa44f7cb120f1ab4fddc19 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 614 290db913568006f555f67c0529f2ad7c Size/MD5 checksum: 14109d0598767e42a34ad05c9df1c3962b140 Size/MD5 checksum: 128712 d3d91f6596f53d5e2b27cea8607d5bba Alpha architecture: Size/MD5 checksum: 59240 f6854853b290fe2ce1a925cbbea3856a Size/MD5 checksum: 27978 6b4680363644b459e0e47222985f749f AMD64 architecture: Size/MD5 checksum: 56034 9848065d7700f2f6e0a036ee76e8fcf7 Size/MD5 checksum: 26456 befb78e032aa654e5fcfcc7c9fdff21b ARM architecture: Size/MD5 checksum: 53198 6a9c1e8afaa60a7b4b7787729dd97b9b Size/MD5 checksum: 24610 f35f8b0a749694fea536296d2a41e1f0 Intel IA-32 architecture: Size/MD5 checksum: 51494 eeb422504ed7247f4bbfd5ed27a89bac Size/MD5 checksum: 24638 85147190249ea9d69c16d8f1dfdfb42e Intel IA-64 architecture: Size/MD5 checksum: 71954 924db7bf3beb5ce3c0e5018759aef3d6 Size/MD5 checksum: 30276 530abc02e3c392a91bff06fe1d8ce7af HP Precision architecture: Size/MD5 checksum: 57374 4755b42efc9a48b59b1e745862e01098 Size/MD5 checksum: 26912 557472d5a3e182b86999baa0b89846ba Motorola 680x0 architecture: Size/MD5 checksum: 50132 bcb24b62afb868c5e04b8c1db66e6cc3 Size/MD5 checksum: 24756 4b30d87639b3d6b7ca58537cf16c6953 Big endian MIPS architecture: Size/MD5 checksum: 57044 410e480e061a3876b7ff01beaffb571e Size/MD5 checksum: 30980 2cda342ba6a04fdbe0a938359eeff813 Little endian MIPS architecture: Size/MD5 checksum: 57112 fe0268048af2940619a9380d7cd83626 Size/MD5 checksum: 31126 64e73613ca88afa3fd379b657c80a414 PowerPC architecture: Size/MD5 checksum: 53442 58c39568158a4c3da81efcaf6a0ab838 Size/MD5 checksum: 25160 a5ff28da9df6080438012db8014b0212 IBM S/390 architecture: Size/MD5 checksum: 56214 f39998665c2df9236d2902120eb977f9 Size/MD5 checksum: 26268 34e822b698803e3e0139430aea707f55 Sun Sparc architecture: Size/MD5 checksum: 53298 a8dcaf92cb41b607618b4a271927c250 Size/MD5 checksum: 24718 54c4e9dac68c9b8472dc92fe6966f6e4 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian addresses thttpd security flaw by releasing package update, providing improved protection for system users. Update advised.. Debian Security, Insecure File Attack, thttpd Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 04, 2005 Critical Debian
100

SUSE 7.3-9.0: 2003-045 Moderate: nginx Network Vulnerability Assessment

Two vulnerabilities were found in the "tiny" web-server thttpd. Two vulnerabilities were found in the "tiny" web-server thttpd. The first bug is a buffer overflow that can be exploited remotely The first bug is a buffer overflow that can be exploited remotely to overwrite the EBP register of the stack. Due to memory-alignment of the stack done by gcc 3.x this bug can not be exploited. All th [More...]. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SUSE Security Announcement Package: thttpd Announcement-ID: SuSE-SA:2003:044 Date: Friday, Oct 31st 2003 13:04 MEST Affected products: 7.3, 8.0, 8.1, 8.2, 9.0 Vulnerability Type: remote privilege escalation/ information leak Severity (1-10): 5 SUSE default package: no Cross References: CAN-2003-0899 CAN-2002-1562 Content of this advisory: 1) security vulnerability resolved: - buffer overflow - information leak (virtual hosting) problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - libnids - KDE - postgresql - frox - sane - ircd - fileutils - mc - apache1/2 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information Two vulnerabilities were found in the "tiny" web-server thttpd. The first bug is a buffer overflow that can be exploited remotely to overwrite the EBP register of the stack. Due to memory-alignment of the stack done by gcc 3.x this bug can not be exploited. All thttpd versionsmentioned in this advisory are compiled with gcc 3.x and are therefore not exploitable. The other bug occurs in the virtual-hosting code of thttpd. A remote attacker can bypass the virtual-hosting mechanism to read arbitrary files. Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web. Intel i386 Platform: SuSE-9.0: e33f3897cac1e1fe117eff8ca252ec0f patch rpm(s): cd5c2aeb6d31d6a6781f392af17a4989 source rpm(s): c6e2446bc94c8c00d35b7741b67df678 SuSE-8.2: a491b55f562fa0f3b1679ee819140c72 patch rpm(s): bbb3dd624b19d8683223049a070d4cf2 source rpm(s): 2710751ff1ee8fbab3c2934c5cb09f3d SuSE-8.1: 428db4fb2eccebb5ed16cb28161ba2a5 patch rpm(s): b32fb0a87d8d7de3ed1953e64da89bc8 source rpm(s): e64bc1488747a414f6bd60735f82385f SuSE-8.0: 952dcca179b647afdeea02b987e3daf8 patch rpm(s): e596221f34a73ba6fdd29abcecb6e211 source rpm(s): 8500be9c635d1c5c9618ecca2a09a5e7 SuSE-7.3: 16ffc5238c1f57b8a1e6e02989524e82 source rpm(s): b5c4b9c65182fcd2a326e3edad7b2dfb PPC Power PC Platform: SuSE-7.3: e7aaff82bd90c459849dd78b1cc47515 source rpm(s): 8ac31eb38063a891e37ed327a5ddbc0c ______________________________________________________________________________ 2) Pending vulnerabilities in SUSE Distributions and Workarounds: - libnids New libnids packages were released to stop remote command execution due to a memory corruption in the TCP reassembly code. (CAN-2003-0850) Please download them from our FTP servers. - KDE New KDE packages are currentlybeing tested. These packages fixes several vulnerabilities: + remote root compromise (CAN-2003-0690) + weak cookies (CAN-2003-0692) + SSL man-in-the-middle attack + information leak through HTML-referrer (CAN-2003-0459) The packages will be release as soon as testing is finished. - postgresql Several buffer overflow problems were fixed in the pg_to_asci() function of postgresql server. New packages are available on our FTP servers. - frox A denial-of-service attack in frox can be trigger remotely. The packages are currently tested and will be release as soon as possible. - sane The scanner service sane of SuSE Linux 7.3-8.1 is vulnerable to a remote denial-of-service attack. This attack can even be triggered if the attackers host is not listed in the saned.conf file. The packages are currently tested and will be release as soon as possible. - ircd The Internet Relay Chat daemon is vulnerable to a remote denial-of- service attack. The attack can be triggered by irc clients directly connected to the daemon. The packages are currently tested and will be release as soon as possible. - fileutils A local denial-of-service attack can be triggered by abusing the -w option of ls(1). This attack can be turned into a remote denial-of- service by using network services, like wuftpd, that rely on the ls(1) command installed on the system. The packages are currently tested and will be release as soon as possible. - mc By using a special combination of links in archive-files it is possible to execute arbitrary commands while mc tries to open it in its VFS. The packages are currently tested and will be release as soon as possible. - apache1/2 The widely used HTTP server apache has several security vulnerabilities: - locally exploitable buffer overflow in the regular expression code. The attacker must be able to modify .htaccess or httpd.conf. (affects: mod_alias and mod_rewrite) - under some circumstances mod_cgid will output its data to the wrong client (affects: apache2) ______________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SUSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SUSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it.), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of thepackage, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verification can only target an un-installed rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SUSE in rpm packages for SUSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SUSE Linux distributions version 7.1 and thereafter install the key "This email address is being protected from spambots. You need JavaScript enabled to view it." upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at . - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Advisory outlines vulnerabilities inthttpd, associated updates, and potential remote exploit threats. Crucial information for system administrators.. thttpd Security, Remote Exploit, SUSE Updates. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2003 SuSE
87

Debian DSA 396-1 Critical: thttpd Information Leak And Remote Execution

An information leak and an arbitrary code execution vulnerability have been fixed.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 396-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze October 29th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : thttpd Vulnerability : missing input sanitizing, wrong calculation Problem-Type : remote Debian-specific: no CVE Id : CAN-2002-1562 CAN-2003-0899 Several vulnerabilities have been discovered in thttpd, a tiny HTTP server. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CAN-2002-1562: Information leak Marcus Breiing discovered that if thttpd it is used for virtual hosting, and an attacker supplies a specially crafted ``Host:' header with a pathname instead of a hostname, thttpd will reveal information about the host system. Hence, an attacker can browse the entire disk. CAN-2003-0899: Arbitrary code execution Joel Soderberg and Christer Oberg discovered a remote overflow which allows an attacker to partially overwrite the EBP register and hencely execute arbitrary code. For the stable distribution (woody) these problems have been fixed in version 2.21b-11.2. For the unstable distribution (sid) this problem has been fixed in version 2.23beta1-2.3. We recommend that you upgrade your thttpd package immediately. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the properconfiguration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 545 8a1acb90e6094f3fa72c6845c3053041 Size/MD5 checksum: 12319 2ac5366cf965d9fc492265d095c108a8 Size/MD5 checksum: 127157 9c1512664cf70c286331243ab622173e Alpha architecture: Size/MD5 checksum: 67512 4b98098b019e2b8d0b1ce1e9aeb617ec Size/MD5 checksum: 27794 9edd14ad49dad106626771543c106937 ARM architecture: Size/MD5 checksum: 54182 c191681665f0af7df0ee90136b3365ff Size/MD5 checksum: 23212 2103ca75c4ea13b97e5744d89949fe37 Intel IA-32 architecture: Size/MD5 checksum: 51914 d699b326d3ebc75476cafe31e91e45ec Size/MD5 checksum: 23570 157936de6bd22736b0aa63e2224d65ba Intel IA-64 architecture: Size/MD5 checksum: 77950 cc5e735539ad1c550b9af17c2388bc83 Size/MD5 checksum: 29562 954eaaa5f8c824cba7725921f65a3331 HP Precision architecture: Size/MD5 checksum: 59116 7f77611819d41bf76d5f835d970f3ed8 Size/MD5 checksum: 25448 cd644f20dcc58dfca543600a74dc95c8 Motorola 680x0 architecture: Size/MD5 checksum: 49552 72cca53687444bef03134030c6662511 Size/MD5 checksum: 23220 5677cb4faf6d7b586ba1268c2e35e65c Big endian MIPS architecture: Size/MD5 checksum: 58236 446d260842da0922cba728e2df11b56b Size/MD5 checksum: 24516 da2230823d6337e7665254f9700c02b8 Little endian MIPS architecture: Size/MD5 checksum: 58334 04df64db72249b74039f26e23f384f62 Size/MD5 checksum: 24598 451b2c66266919a2a45740336e157518 PowerPC architecture: Size/MD5 checksum: 56474 37163f189b04526056738e72514e0870 Size/MD5 checksum: 23836 fac814ed369bd38e7294d7190a8aad8a IBM S/390 architecture: Size/MD5 checksum: 54658 b05a18adb9af89e183846135ea272b2e Size/MD5 checksum: 24392 ea2d972ab7dc89df2c232c71c246bf30 Sun Sparc architecture: Size/MD5 checksum: 58226 5505dc14188fcd27a6ec7fee1f482a78 Size/MD5 checksum: 29954 85b41622907ece7edfc7d10f78a83946 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian DSA-396-1 has been released to fix vulnerabilities in thttpd, urging immediate updates for security protection against threats. thttpd Security, Debian Advisory, Execution Risk, Information Leak, Upgrade Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 29, 2003 Critical Debian
100

SuSE: thttpd 1.90a - 2.04 Critical Remote Code Execution Threat

The thttpd web server doesn't do proper bounds checking in the date parsing function tdate_parse(). . _____________________________________________________________________________ SuSE Security Announcement - thttpd Package: thttpd 1.90a - 2.04 Date: Tue Nov 16 19:44:14 CET 1999 Affected SuSE versions: 6.2 and 6.3 Vulnerability Type: remote compromise SuSE default package: no Other affected systems: all unix systems using the thttpd-server ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that that we provide this information on an "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. _____________________________________________________________________________ 1. Problem Description The thttpd web server doesn't do proper bounds checking in the date parsing function tdate_parse(). 2. Impact By overflowing a static buffer in tdate_parse() an attacker could remotely execute commands on the thttpd host with the permissions of thttpd. 3. Solution Updated the package from our FTP server. ______________________________________________________________________________ Please verify these md5 checksums of the updates before installing: 160a166713f186a61b2111c45786e26a thttpd-2.04-31.i386.rpm (6.2) 4eb85acb72a30873842257cd923f9332 thttpd-2.04-31.i386.rpm (6.3) ______________________________________________________________________________ You can find updates on our ftp-Server: or try the following webpages for a list of mirrors: https://www.suse.com/de-de/ Our webpage for patches: https://www.suse.com/de-de/ Our webpage for security announcements: https://www.suse.com/de-de/ If you want to report vulnerabilities, please contact This email address is being protected from spambots. You need JavaScript enabled to view it. ______________________________________________________________________________ . _____________________________________________________________________________ SuSE Security Announce. thttpd, server, doesn't, proper, bounds, checking, parsing, function, tdate_parse(). . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 1999 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200