More bugs as Linux is targeted by fake security e-mail
Gaim and libtiff the latest in a slew of vulnerabilities.
By Matthew Broersma, Techworld
Linux vendors have been hit by two fresh security bugs, affecting a widely used graphics decoder and the Gaim instant-messaging client.
Separately, Red Hat, the biggest Linux developer, said attackers have begun targeting Red Hat users with an email-based scam similar to methods commonly used to target Windows.
The flaws in Gaim and libtiff, used by many Linux graphics programs to decode tiff images, follow a series of serious bugs patched last week. The earlier flaws affected Linux\'s libpng, Xpdf and Cups components.
Researcher Chris Evans uncovered a series of boundary errors affecting the RLE-decoding components of libtiff, which could be exploited to cause heap-based buffer overflows. A malicious user could exploit these flaws by tricking a user into viewing a maliciously crafted tiff image with an application that uses libtiff, researchers said; such an image could crash the application and execute malicious code on the user\'s computer.
Evans said the specific flaws he publicised are likely to be only the tip of the iceberg. \"Unfortunately, due to the size of libtiff, only a limited scan for flaws was possible. These flaws are likely to typify others present,\" he said in an [url=\"http://scary.beasts.org/security/CESA-2004-006.txt\"]advisory[/url].
A second flaw in libtiff, a division-by-zero bug discovered by Matthias Claasen, could crash libtiff-linked applications. Finally, auditing by Dmitry Levin uncovered integer overflows which could also be used to execute arbitrary code on a user\'s PC, according to an [url=\"http://secunia.com/advisories/12818/\"]advisory[/url] from Danish security firm Secunia.
[url=\"http://www.suse.de/de/security/2004_38_libtiff.html\"]Suse[/url] and [url=\"http://rhn.redhat.com/errata/RHSA-2004-577.html\"]Red Hat[/url] issued advisories on the libtiff flaw late last week, along with patches for the component.
The bug in Gaim, also publicised last week, can be exploited by sending a specially crafted message using the MSN SLP protocol. A boundary error within the handling of such messages can be exploited to cause a buffer overflow, crash the application and execute arbitrary code, Secunia said.
MandrakeSoft [url=\"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:110\"]said[/url] bugs affecting version 0.75 of Gaim, which ships with Mandrake Linux 10.0, included the way the application handles smiley themes and very long URLs. Both bugs could allow malicious code execution, MandrakeSoft said. MandrakeSoft, [url=\"http://www.gentoo.org/security/en/glsa/glsa-200410-23.xml\"]Gentoo[/url], [url=\"http://secunia.com/advisories/12910/\"]Red Hat[/url], [url=\"http://secunia.com/advisories/12964/\"]Slackware[/url] and others are issuing patches for Gaim.
The Gaim client is widely used on Linux systems to simulate third-party instant messaging clients such as those from Yahoo, AOL and MSN.
Red Hat said on Saturday that users have been targeted by an authentic-looking security notification message which attempts to trick users into downloading and executing malicious code.
\"These emails tell users to download and run an update from a users home directory. This fake update appears to contain malicious code,\" Red Hat said in a warning posted on the front page of its security [url=\"http://www.redhat.com/security/\"]site[/url]. The company urged users to ensure that any security upates appearing to come from Red Hat are safe by validating the messages\' digital [url=\"http://www.techworld.com/security/news/www.redhat.com/security/team/key.html\"]signature[/url].
The message was made more authentic-looking by the use of a seemingly official website, fedora-redhat.com - which was unavailable as of Monday morning. Before the site disappeared, it contained a message urging users to apply a \"critical-critical\" update.
\"Redhat found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker to execute arbitrary code with root privileges,\" the site said. \"The RedHat Security Team strongly advises you to immediately apply the fileutils-1.0.6 patch. This is a critical-critical update.\"
Windows users are frequently bombarded by authentic-seeming malicious messages appearing to come from Microsoft, but the technique is a novelty for Linux. Until recently, Linux was rarely used as a desktop platform, but has now gained some ground and, by some counts, is more widely used on the desktop than the Mac OS.
[url=\"http://www.techworld.com/security/news/index.cfm?NewsID=2483\"]source[/url]
More bugs as Linux targeted by fake security email
Moderators: Moderator, Global Moderator
Jump to
- General Category
- ↳ KillaNet Country
- ↳ 2D Graphics
- ↳ KillaNet News
- ↳ 3D & Animation
- ↳ Chatroom
- ↳ Flash
- ↳ Help & Suggestions
- ↳ Game Dev
- ↳ Audio & Video
- ↳ Introductions
- ↳ Journalism
- ↳ Phoenix Lounge
- ↳ Application Dev
- ↳ Toga Toga Toga!!!
- ↳ Photography
- ↳ Main Street Archives
- ↳ Web Design
- ↳ Fonts Icons Cursors & Screensavers
- ↳ Book Reviews
- ↳ General
- ↳ Tech Industry News
- ↳ Legal Resources
- ↳ Industry Contests
- ↳ Graphix Battle Arena
- ↳ KillaNet Contests
- ↳ Competition Archives
- ↳ Education Information
- ↳ Careers
- ↳ Game Studies
- ↳ Motivation
- ↳ Conferences & Seminars
- ↳ KillaDesign
- ↳ Animation & Film
- ↳ The Studio
- ↳ Game Development
- ↳ 2D Graphics
- ↳ Audio & Video
- ↳ 3D Graphics
- ↳ Flash
- ↳ Fonts, Icons & Emoticons
- ↳ Design Requests
- ↳ PhotoShop
- ↳ Cinema 4D
- ↳ Bryce
- ↳ Flash
- ↳ Paint Shop Pro
- ↳ Blender
- ↳ Poser
- ↳ The Darkroom
- ↳ Photo & Camera Discussion
- ↳ Photo Journalism
- ↳ Web Design Principles
- ↳ PHP & MySQL
- ↳ Designing For Print
- ↳ Writer\'s Desk
- ↳ Fiction Writing
- ↳ News Journalism
- ↳ Poetry
- ↳ Technical Writing
- ↳ Biographical Writing
- ↳ General Writing Resources
- ↳ Promotional Writing
- ↳ Film & Television
- ↳ VideoGames
- ↳ Computer Department
- ↳ General Discussion
- ↳ Windows Help
- ↳ Linux Help
- ↳ Builds & Mods
- ↳ Geek Gadgets
- ↳ Security
- ↳ Dev Discussion
- ↳ C++
- ↳ Visual Basic
- ↳ Java
- ↳ Application Skinning
- ↳ IRC Scripting
- ↳ Gaming Centre
- ↳ Guild Wars
- ↳ Aion
- ↳ Computer
- ↳ World of Warcraft
- ↳ Nintendo
- ↳ General RPG & MMORPG
- ↳ PlayStation
- ↳ XBox
- ↳ Other Consoles
- ↳ All Action
- ↳ Racers
- ↳ Sports
- ↳ FPS
- ↳ RTS
- ↳ Sim
- ↳ Casual Games
- ↳ Kids' Games
- ↳ Mobile Games
- ↳ Retro Games
- ↳ Challenges, Friendly Taunts & Discussion
- ↳ Game Requests & Bug Reports
- ↳ Open Source Games
- ↳ Puzzle Games
- ↳ HeadQuarters
- ↳ Uber Coffee Room
- ↳ KillaNet
- ↳ Coffee Room
- ↳ KillaNet
- ↳ KillaGraphix
- ↳ KillaHosting
- ↳ Marketing etc.
- ↳ Staff Issues
- ↳ Reference & Software
- ↳ Archives
- ↳ KillaBlogs
- ↳ Journalism
- ↳ Trash Can

