Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > April 2006 > Four Gentoo Linux Security Advisories

April 2006

Four Gentoo Linux Security Advisories

ID: 00313
Ref: 308/2006
Date: 26 April 2006:13:46:28
Version: 1

Title: Four Gentoo Linux Security Advisories
Abstract:
Vendors affected: Gentoo
Operating systems affected: Gentoo
Applications affected: Gentoo

Title
=====


-----BEGIN PGP SIGNED MESSAGE-----

Four Gentoo Linux Security Advisories:

1. GLSA 200604-11 - Crossfire server: Denial of Service and potential arbitrary
code execution

2. GLSA 200604-12 - Mozilla Firefox: Multiple vulnerabilities

3. GLSA 200604-13 - fbida: Insecure temporary file creation

4. GLSA 200604-14 - Dia: Arbitrary code execution through XFig import

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQCVAwUBRE9rOYpao72zK539AQET4wP/bPLsMm6/2i3/qSk+XreePg2xcQi5sYOQ
6ezMfRH3bv6XMfXEwzMKeLJTc6TyOMDBq7OELdT5RRCOWEvgLyQKOhlZgul1eL1y
nM5+SDFESGJJ8xdJhnIyksrCQXUOngg8BRSqyD30Tn85gGyU8WUGGOkv6WhRmS34
pGhKg4r/wTQ=
=XNJ5
-----END PGP SIGNATURE-----

Detail
======

1. Luigi Auriemma discovered a vulnerability in the Crossfire game server,
in the handling of the "oldsocketmode" option when processing overly
large requests.

2. Several vulnerabilities were found in Mozilla Firefox. Versions 1.0.8
and 1.5.0.2 were released to fix them.

3. Jan Braun has discovered that the "fbgs" script provided by fbida
insecurely creates temporary files in the "/var/tmp" directory.

4. infamous41md discovered multiple buffer overflows in Dia's XFig file
import plugin.



1.



- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Crossfire server: Denial of Service and potential arbitrary
code execution
Date: April 22, 2006
Bugs: #126169
ID: 200604-11

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

The Crossfire game server is vulnerable to a Denial of Service and
potentially to the execution of arbitrary code.

Background
==========

Crossfire is a cooperative multiplayer graphical adventure and
role-playing game. The Crossfire game server allows various compatible
clients to connect to participate in a cooperative game.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 games-server/crossfire-server < 1.9.0 >= 1.9.0

Description
===========

Luigi Auriemma discovered a vulnerability in the Crossfire game server,
in the handling of the "oldsocketmode" option when processing overly
large requests.

Impact
======

An attacker can set up a malicious Crossfire client that would send a
large request in "oldsocketmode", resulting in a Denial of Service on
the Crossfire server and potentially in the execution of arbitrary code
on the server with the rights of the game server.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Crossfire server users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose
">=games-server/crossfire-server-1.9.0"

References
==========

[ 1 ] CVE-2006-1010
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1010

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-11.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



2.



- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla Firefox: Multiple vulnerabilities
Date: April 23, 2006
Bugs: #129924
ID: 200604-12

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Several vulnerabilities in Mozilla Firefox allow attacks ranging from
execution of script code with elevated privileges to information
leaks.

Background
==========

Mozilla Firefox is the next-generation web browser from the Mozilla
project.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-client/mozilla-firefox < 1.0.8 >= 1.0.8
2 www-client/mozilla-firefox-bin < 1.0.8 >= 1.0.8
-------------------------------------------------------------------
2 affected packages on all of their supported architectures.
-------------------------------------------------------------------

Description
===========

Several vulnerabilities were found in Mozilla Firefox. Versions 1.0.8
and 1.5.0.2 were released to fix them.

Impact
======

A remote attacker could craft malicious web pages that would leverage
these issues to inject and execute arbitrary script code with elevated
privileges, steal local files, cookies or other information from web
pages, and spoof content. Some of these vulnerabilities might even be
exploited to execute arbitrary code with the rights of the browser
user.

Workaround
==========

There are no known workarounds for all the issues at this time.

Resolution
==========

All Mozilla Firefox users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.8"

All Mozilla Firefox binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose
">=www-client/mozilla-firefox-bin-1.0.8"

References
==========

[ 1 ] CVE-2005-4134
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134
[ 2 ] CVE-2006-0292
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0292
[ 3 ] CVE-2006-0296
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0296
[ 4 ] CVE-2006-0748
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748
[ 5 ] CVE-2006-0749
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749
[ 6 ] CVE-2006-1727
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727
[ 7 ] CVE-2006-1728
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728
[ 8 ] CVE-2006-1729
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729
[ 9 ] CVE-2006-1730
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730
[ 10 ] CVE-2006-1731
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731
[ 11 ] CVE-2006-1732
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732
[ 12 ] CVE-2006-1733
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733
[ 13 ] CVE-2006-1734
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734
[ 14 ] CVE-2006-1735
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735
[ 15 ] CVE-2006-1736
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1736
[ 16 ] CVE-2006-1737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737
[ 17 ] CVE-2006-1738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738
[ 18 ] CVE-2006-1739
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739
[ 19 ] CVE-2006-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740
[ 20 ] CVE-2006-1741
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741
[ 21 ] CVE-2006-1742
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742
[ 22 ] CVE-2006-1790
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790
[ 23 ] Mozilla Foundation Security Advisories

http://www.mozilla.org/projects/security/known-vulnerabilities.html#Firefox

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-12.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



3.


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-13
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: fbida: Insecure temporary file creation
Date: April 23, 2006
Bugs: #129470
ID: 200604-13

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

fbida is vulnerable to linking attacks, potentially allowing a local
user to overwrite arbitrary files.

Background
==========

fbida is a collection of image viewers and editors for the framebuffer
console and X11.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 media-gfx/fbida < 2.03-r3 >= 2.03-r3

Description
===========

Jan Braun has discovered that the "fbgs" script provided by fbida
insecurely creates temporary files in the "/var/tmp" directory.

Impact
======

A local attacker could create links in the temporary file directory,
pointing to a valid file somewhere on the filesystem. When an affected
script is called, this could result in the file being overwritten with
the rights of the user running the script.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All fbida users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/fbida-2.03-r3"

References
==========

[ 1 ] CVE-2006-1695
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1695

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-13.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0



4.


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200604-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Dia: Arbitrary code execution through XFig import
Date: April 23, 2006
Bugs: #128107
ID: 200604-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Buffer overflows in Dia's XFig import could allow remote attackers to
execute arbitrary code.

Background
==========

Dia is a GTK+ based diagram creation program.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-office/dia < 0.94-r5 >= 0.94-r5

Description
===========

infamous41md discovered multiple buffer overflows in Dia's XFig file
import plugin.

Impact
======

By enticing a user to import a specially crafted XFig file into Dia, an
attacker could exploit this issue to execute arbitrary code with the
rights of the user running Dia.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Dia users should upgrade to the latest available version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=app-office/dia-0.94-r5"

References
==========

[ 1 ] CVE-2006-1550
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1550

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200604-14.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |