General Esm W900

Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

Essential tools for hardening and securing Unix based Environments - System administrators are aware as how important their systems security is, not just the runtime of their servers. Intruders, spammers, DDOS attack, crackers, are all out there trying to get into people

Securing a Linux Web Server - With the significant prevalence of Linux web servers globally, security is often touted as a strength of the platform for such a purpose. However, a Linux based web server is only as secure as its configuration and very often many are quite vulnerable to compromise. While specific configurations vary wildly due to environments or specific use, there are various general steps that can be taken to insure basic security considerations are in place.


  Debian: DSA-3953-1: aodh security update (Aug 23)
 

Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an

  Debian: DSA-3952-1: libxml2 security update (Aug 23)
 

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause a denial-of-service against

  Debian: DSA-3951-1: smb4k security update (Aug 22)
 

Sebastian Krahmer discovered that a programming error in the mount helper binary of the Smb4k Samba network share browser may result in local privilege escalation.

  Debian: DSA-3950-1: libraw security update (Aug 21)
 

Hossein Lotfi and Jakub Jirasek from Secunia Research have discovered multiple vulnerabilities in LibRaw, a library for reading RAW images. An attacker could cause a memory corruption leading to a DoS (Denial of Service) with craft KDC or TIFF file.

  Debian: DSA-3949-1: augeas security update (Aug 21)
 

Han Han of Red Hat discovered that augeas, a configuration editing tool, improperly handled some escaped strings. A remote attacker could leverage this flaw by sending maliciously crafted strings, thus causing an augeas-enabled application to crash or potentially execute

  Debian: DSA-3948-1: ioquake3 security update (Aug 19)
 

A read buffer overflow was discovered in the idtech3 (Quake III Arena) family of game engines. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

  Debian: DSA-3947-1: newsbeuter security update (Aug 18)
 

Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an arbitrary shell command on the client machine.

  Debian: DSA-3946-1: libmspack security update (Aug 18)
 

It was discovered that libsmpack, a library used to handle Microsoft compression formats, did not properly validate its input. A remote attacker could craft malicious CAB or CHM files and use this flaw to cause a denial of service via application crash, or potentially

  Debian: DSA-3945-1: linux security update (Aug 17)
 

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

  Debian: DSA-3944-1: mariadb-10.0 security update (Aug 17)
 

Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.32. Please see the MariaDB 10.0 Release Notes for further details:

 
  (Aug 21)
 

CVE-2017-12756 Fix command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the

  Debian LTS: DLA-1062-1: curl security update (Aug 20)
 

CVE-2017-1000100 Wrong handling of very long filenames during TFTP might result in curl sending more than buffer size.

  Debian LTS: DLA-1061-1: newsbeuter security update (Aug 19)
 

Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an

  Debian LTS: DLA-1060-1: libxml2 security update (Aug 19)
 

CVE-2017-0663 Invalid casting of different structs could enable an attacker to

  Debian LTS: DLA-1059-1: strongswan security update (Aug 18)
 

It was discovered that there was a denial-of-service vulnerability in the Strongswan Virtual Private Network (VPN) software. Specific RSA signatures passed to the gmp plugin for verification could

 
  ArchLinux: 201708-18: thunderbird: multiple issues (Aug 24)
 

The package thunderbird before version 52.3.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, information disclosure, same-origin policy bypass and access restriction bypass.

  ArchLinux: 201708-17: salt: directory traversal (Aug 24)
 

The package salt before version 2017.7.1-1 is vulnerable to directory traversal.

  ArchLinux: 201708-16: curl: information disclosure (Aug 22)
 

The package curl before version 7.55-1 is vulnerable to information disclosure.

  ArchLinux: 201708-15: newsbeuter: arbitrary code execution (Aug 21)
 

The package newsbeuter before version 2.9-7 is vulnerable to arbitrary code execution.

 
  CentOS: CESA-2017-2485: Important CentOS 6 git (Aug 17)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2017:2485

 
  SciLinux: Important: thunderbird on SL6.x, SL7.x i386/x86_64 (Aug 24)
 

Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2017-7779, CVE-2017-7800, CVE-2017-7801, [More...]

  SciLinux: Moderate: git on SL7.x x86_64 (Aug 21)
 

It was found that the git-prompt.sh script shipped with git failed to correctly handle branch names containing special characters. A specially crafted git repository could use this flaw to execute arbitrary commands if a user working with the repository configured their shell to include [More...]

  SciLinux: Moderate: bash on SL7.x x86_64 (Aug 21)
 

An arbitrary command injection flaw was found in the way bash processed the hostname value. A malicious DHCP server could use this flaw to execute arbitrary commands on the DHCP client machines running bash under specific circumstances. (CVE-2016-0634) [More...]

  SciLinux: Moderate: pidgin on SL7.x x86_64 (Aug 21)
 

A denial of service flaw was found in the way Pidgin's Mxit plug-in handled emoticons. A malicious remote server or a man-in-the-middle attacker could potentially use this flaw to crash Pidgin by sending a specially crafted emoticon. (CVE-2014-3695) [More...]

  SciLinux: Moderate: postgresql on SL7.x x86_64 (Aug 21)
 

It was found that some selectivity estimation functions did not check user privileges before providing information from pg_statistic, possibly leaking information. A non-administrative database user could use this flaw to steal some information from tables they are otherwise not allowed [More...]

  SciLinux: Moderate: tigervnc and fltk on SL7.x x86_64 (Aug 21)
 

A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207) [More...]

  SciLinux: Moderate: python on SL7.x x86_64 (Aug 21)
 

The Python standard library HTTP client modules (such as httplib or urllib) did not perform verification of TLS/SSL certificates when connecting to HTTPS servers. A man-in-the-middle attacker could use this flaw to hijack connections and eavesdrop or modify transferred data. [More...]

  SciLinux: Moderate: golang on (Aug 21)
 

A carry propagation flaw was found in the implementation of the P-256 elliptic curve in golang. An attacker could possibly use this flaw to extract private keys when static ECDH was used. (CVE-2017-8932) -- [More...]

  SciLinux: Moderate: openldap on SL7.x x86_64 (Aug 21)
 

A double-free flaw was found in the way OpenLDAP's slapd server using the MDB backend handled LDAP searches. A remote attacker with access to search the directory could potentially use this flaw to crash slapd by issuing a specially crafted LDAP search query. (CVE-2017-9287) [More...]

  SciLinux: Moderate: mariadb on SL7.x x86_64 (Aug 21)
 

It was discovered that the mysql and mysqldump tools did not correctly handle database and table names containing newline characters. A database user with privileges to create databases or tables could cause the mysql command to execute arbitrary shell or SQL commands while restoring [More...]

  SciLinux: Important: kernel on SL7.x x86_64 (Aug 21)
 

An use-after-free flaw was found in the Linux kernel which enables a race condition in the L2TPv3 IP Encapsulation feature. A local user could use this flaw to escalate their privileges or crash the system. (CVE-2016-10200, Important) [More...]

  SciLinux: Moderate: gtk-vnc on SL7.x x86_64 (Aug 21)
 

It was found that gtk-vnc lacked proper bounds checking while processing messages using RRE, hextile, or copyrect encodings. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library. (CVE-2017-5884) [More...]

  SciLinux: Moderate: openssh on SL7.x x86_64 (Aug 21)
 

A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses. (CVE-2016-6210) [More...]

  SciLinux: Moderate: glibc on SL7.x x86_64 (Aug 21)
 

functions that could cause applications, which process long strings with the nan function, to crash or, potentially, execute arbitrary code. (CVE-2014-9761) [More...]

  SciLinux: Low: samba on SL7.x x86_64 (Aug 21)
 

A flaw was found in the way Samba handled dangling symlinks. An authenticated malicious Samba client could use this flaw to cause the smbd daemon to enter an infinite loop and use an excessive amount of CPU and memory. (CVE-2017-9461) [More...]

  SciLinux: Moderate: qemu-kvm on SL7.x x86_64 (Aug 21)
 

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process. (CVE-2017-2633) [More...]

  SciLinux: Moderate: libreoffice on SL7.x x86_64 (Aug 21)
 

An out-of-bounds write flaw was found in the way Libreoffice rendered certain documents containing Polygon images. By tricking a user into opening a specially crafted LibreOffice file, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user [More...]

  SciLinux: Moderate: NetworkManager and libnl3 on SL7.x x86_64 (Aug 21)
   
  SciLinux: Moderate: tcpdump on SL7.x x86_64 (Aug 21)
 

Multiple out of bounds read and integer overflow vulnerabilities were found in tcpdump affecting the decoding of various protocols. An attacker could create a crafted pcap file or send specially crafted packets to the network segment where tcpdump is running in live capture mode (without -w) [More...]

  SciLinux: Moderate: gnutls on SL7.x x86_64 (Aug 21)
 

A double-free flaw was found in the way GnuTLS parsed certain X.509 certificates with Proxy Certificate Information extension. An attacker could create a specially-crafted certificate which, when processed by an application compiled against GnuTLS, could cause that application to [More...]

  SciLinux: Moderate: pki-core on SL7.x x86_64 (Aug 21)
 

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates. [More...]

  SciLinux: Moderate: X.org X11 libraries on SL7.x x86_64 (Aug 21)
 

An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file. (CVE-2016-10164) [More...]

  SciLinux: Moderate: curl on SL7.x x86_64 (Aug 21)
 

Multiple integer overflow flaws leading to heap-based buffer overflows were found in the way curl handled escaping and unescaping of data. An attacker could potentially use these flaws to crash an application using libcurl by sending a specially crafted input to the affected libcurl [More...]

  SciLinux: Moderate: libtasn1 on SL7.x x86_64 (Aug 21)
 

A heap-based buffer overflow flaw was found in the way the libtasn1 library decoded certain DER-encoded inputs. A specially crafted DER- encoded input could cause an application using libtasn1 to perform an invalid read, causing the application to crash. (CVE-2015-3622) [More...]

  SciLinux: Low: ghostscript on SL7.x x86_64 (Aug 21)
 

A NULL pointer dereference flaw was found in ghostscript's mem_get_bits_rectangle function. A specially crafted postscript document could cause a crash in the context of the gs process. (CVE-2017-7207) -- [More...]

  SciLinux: Important: freeradius on SL7.x x86_64 (Aug 21)
 

An out-of-bounds write flaw was found in the way FreeRADIUS server handled certain attributes in request packets. A remote attacker could use this flaw to crash the FreeRADIUS server or to execute arbitrary code in the context of the FreeRADIUS server process by sending a specially [More...]

  SciLinux: Important: evince on SL7.x x86_64 (Aug 21)
 

It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar (CBT) files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince- thumbnailer, could execute arbitrary commands in the context of the evince [More...]

  SciLinux: Moderate: GStreamer on SL7.x x86_64 (Aug 21)
 

Multiple flaws were found in gstreamer1, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-bad-free packages. An attacker could potentially use these flaws to crash applications which use the GStreamer framework. (CVE-2016-9446, CVE-2016-9810, CVE-2016-9811, [More...]

  SciLinux: Low: tomcat on SL7.x (noarch) (Aug 21)
 

The Realm implementations did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder. [More...]

  SciLinux: Moderate: authconfig on SL7.x x86_64 (Aug 21)
 

A flaw was found where authconfig could configure sssd in a way that treats existing and non-existing logins differently, leaking information on existence of a user. An attacker with physical or network access to the machine could enumerate users via a timing attack. (CVE-2017-7488) [More...]

  SciLinux: Important: spice on SL7.x x86_64 (Aug 21)
 

A vulnerability was discovered in spice server's protocol handling. An authenticated attacker could send specially crafted messages to the spice server, causing out-of-bounds memory accesses, leading to parts of server memory being leaked or a crash. (CVE-2017-7506) [More...]

  SciLinux: Critical: firefox on SL6.x, SL7.x i386/x86_64 (Aug 21)
 

Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2017-7779, CVE-2017-7798, CVE-2017-7800, [More...]

  SciLinux: Important: libsoup on SL7.x x86_64 (Aug 21)
 

A stack-based buffer overflow flaw was discovered within the HTTP processing of libsoup. A remote attacker could exploit this flaw to cause a crash or, potentially, execute arbitrary code by sending a specially crafted HTTP request to a server using the libsoup HTTP server [More...]

  SciLinux: Important: kernel on SL7.x x86_64 (Aug 21)
 

A race condition was found in the Linux kernel, present since v3.14-rc1 through v4.12. The race happens between threads of inotify_handle_event() and vfs_rename() while running the rename operation against the same file. As a result of the race the next slab data or the slab's free list pointer [More...]

  SciLinux: Important: httpd on SL7.x x86_64 (Aug 21)
 

It was discovered that the httpd's mod_auth_digest module did not properly initialize memory before using it when processing certain headers related to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd [More...]

  SciLinux: Critical: java-1.7.0-openjdk on SL6.x, SL7.x i386/x86_64 (Aug 21)
 

It was discovered that the DCG implementation in the RMI component of OpenJDK failed to correctly handle references. A remote attacker could possibly use this flaw to execute arbitrary code with the privileges of RMI registry or a Java RMI application. (CVE-2017-10102) [More...]

  SciLinux: Moderate: gdm and gnome-session on SL7.x x86_64 (Aug 21)
 

It was found that gdm could crash due to a signal handler dispatched to an invalid conversation. An attacker could crash gdm by holding the escape key when the screen is locked, possibly bypassing the locked screen. (CVE-2015-7496) [More...]

  SciLinux: Important: log4j on SL7.x (noarch) (Aug 21)
 

It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the [More...]

  SciLinux: Important: mercurial on SL7.x x86_64 (Aug 21)
 

A vulnerability was found in the way Mercurial handles path auditing and caches the results. An attacker could abuse a repository with a series of commits mixing symlinks and regular files/directories to trick Mercurial into writing outside of a given repository. (CVE-2017-1000115) [More...]

  SciLinux: Important: git on SL7.x x86_64 (Aug 21)
 

A shell command injection flaw related to the handling of "ssh" URLs has been discovered in Git. An attacker could use this flaw to execute shell commands with the privileges of the user running the Git client, for example, when performing a "clone" action on a malicious repository or a [More...]

  SciLinux: Moderate: qemu-kvm on SL7.x x86_64 (Aug 21)
 

Quick Emulator (QEMU) built with the Network Block Device (NBD) Server support is vulnerable to a crash via a SIGPIPE signal. The crash can occur if a client aborts a connection due to any failure during negotiation or read operation. A remote user/process could use this flaw to crash the [More...]

  SciLinux: Important: groovy on SL7.x (noarch) (Aug 21)
 

It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on [More...]

  SciLinux: Important: subversion on SL7.x x86_64 (Aug 21)
 

A shell command injection flaw related to the handling of "svn+ssh" URLs has been discovered in Subversion. An attacker could use this flaw to execute shell commands with the privileges of the user running the Subversion client, for example when performing a "checkout" or "update" [More...]

  SciLinux: Moderate: xmlsec1 on SL7.x x86_64 (Aug 21)
 

It was discovered xmlsec1's use of libxml2 inadvertently enabled external entity expansion (XXE) along with validation. An attacker could craft an XML file that would cause xmlsec1 to try and read local files or HTTP/FTP URLs, leading to information disclosure or denial of service. [More...]

  SciLinux: Important: git on SL6.x i386/x86_64 (Aug 17)
 

A shell command injection flaw related to the handling of "ssh" URLs has been discovered in Git. An attacker could use this flaw to execute shell commands with the privileges of the user running the Git client, for example, when performing a "clone" action on a malicious repository or a [More...]