May 2006
Five Mandriva Linux Security Advisories
ID: 00378
Ref: 370/2006
Date: 26 May 2006:11:39:33
Version: 1
Title: Five Mandriva Linux Security Advisories
Abstract:
Vendors affected: Mandriva
Operating systems affected: Mandriva
Applications affected: Mandriva
Title
=====
Five Mandriva Linux Security Advisories:
1. MDKSA-2006:087 - Updated kernel packages fixes netfilter SNMP NAT memory corruption
2. MDKSA-2006:088 - Updated hostapd package to address DoS vulnerability
3. MDKSA-2006:089 - Updated kphone packages fixes permissions issue with .qt/kphonerc
4. MDKSA-2006:090 - Updated shadow-utils packages fix mailbox creation vulnerability
5. MDKSA-2006:091 - Updated php packages fix vulnerabilities
Detail
======
1. Memory corruption can be triggered remotely when the ip_nat_snmp_basic
module is loaded and traffic on port 161 or 162 is NATed.
2. Hostapd 0.3.7 allows remote attackers to cause a denial of service
(segmentation fault) via an unspecified value in the key_data_length
field of an EAPoL frame.
3. Kphone creates .qt/kphonerc with world-readable permissions, which
allows local users to read usernames and SIP passwords.
4. A potential security problem was found in the useradd tool when it
creates a new user's mailbox due to a missing argument to the open()
call, resulting in the first permissions of the file being some random
garbage found on the stack, which could possibly be held open for
reading or writing before the proper fchmod() call is executed.
5. An integer overflow in the wordwrap() function could allow attackers
to execute arbitrary code via certain long arguments that cause a small
buffer to be allocated, triggering a heap-based buffer overflow
(CVE-2006-1990).
1.
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:087
http://www.mandriva.com/security/
_______________________________________________________________________
Package : kernel
Date : May 24, 2006
Affected: 2006.0
_______________________________________________________________________
Problem Description:
Memory corruption can be triggered remotely when the ip_nat_snmp_basic
module is loaded and traffic on port 161 or 162 is NATed.
The provided packages are patched to fix this vulnerability. Users
who may be running netfilter on important servers are encouraged to
upgrade to these updated kernels.
To update your kernel, please follow the directions located at:
http://www.mandriva.com/en/security/kernelupdate
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2444
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2006.0:
4dc3aebce01743d22ccfdcf2d7e6be1c 2006.0/RPMS/kernel-2.6.12.22mdk-1-1mdk.i586.rpm
4df75974100f1d867b227f83aac9bc2e 2006.0/RPMS/kernel-BOOT-2.6.12.22mdk-1-1mdk.i586.rpm
7ad9ef00021f9e0938932014f22e4bba 2006.0/RPMS/kernel-i586-up-1GB-2.6.12.22mdk-1-1mdk.i586.rpm
44eae16e32239f239346e620cd0f7b15 2006.0/RPMS/kernel-i686-up-4GB-2.6.12.22mdk-1-1mdk.i586.rpm
e01abef21d8d14e6d6c879f56ebe684b 2006.0/RPMS/kernel-smp-2.6.12.22mdk-1-1mdk.i586.rpm
5d3826385c72a86a3ebcf564529d85b1 2006.0/RPMS/kernel-source-2.6-2.6.12-22mdk.i586.rpm
79586cea137b4d36658d3fd7b313ef8b 2006.0/RPMS/kernel-source-stripped-2.6-2.6.12-22mdk.i586.rpm
883243ea22ad7eb494b1546a4a390507 2006.0/RPMS/kernel-xbox-2.6.12.22mdk-1-1mdk.i586.rpm
4283b2f1fefe78b8459ffb3611fb1273 2006.0/RPMS/kernel-xen0-2.6.12.22mdk-1-1mdk.i586.rpm
eb25ea2db1336906f145cf20a84f29a6 2006.0/RPMS/kernel-xenU-2.6.12.22mdk-1-1mdk.i586.rpm
f34885d9d75928e9371f1ca3dd620fd3 2006.0/SRPMS/kernel-2.6.12.22mdk-1-1mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
94fc9062208f2bc8010f64070f505133 x86_64/2006.0/RPMS/kernel-2.6.12.22mdk-1-1mdk.x86_64.rpm
fad1ee518ba360420a9dc7f544ace3ee x86_64/2006.0/RPMS/kernel-BOOT-2.6.12.22mdk-1-1mdk.x86_64.rpm
88d61abf3296793a136cc8c662030b34 x86_64/2006.0/RPMS/kernel-smp-2.6.12.22mdk-1-1mdk.x86_64.rpm
d57c2d28a28e66b2eafe716d22971619 x86_64/2006.0/RPMS/kernel-source-2.6-2.6.12-22mdk.x86_64.rpm
6c0ff6667a79390e8260d30ff7f2faa5 x86_64/2006.0/RPMS/kernel-source-stripped-2.6-2.6.12-22mdk.x86_64.rpm
f34885d9d75928e9371f1ca3dd620fd3 x86_64/2006.0/SRPMS/kernel-2.6.12.22mdk-1-1mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEdG6amqjQ0CJFipgRAlIZAJ9VNo3owfm29R6Bwwz/hEb3Fnj1+gCgoLvU
Xgr8zIydmU2uUC1TH2wbbCo=
=yoXm
- -----END PGP SIGNATURE-----
2.
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:088
http://www.mandriva.com/security/
_______________________________________________________________________
Package : hostapd
Date : May 24, 2006
Affected: 10.2, 2006.0
_______________________________________________________________________
Problem Description:
Hostapd 0.3.7 allows remote attackers to cause a denial of service
(segmentation fault) via an unspecified value in the key_data_length
field of an EAPoL frame.
Packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2213
_______________________________________________________________________
Updated Packages:
Mandriva Linux 10.2:
9154a5005bc66dae4528cd3008dbca09 10.2/RPMS/hostapd-0.3.7-2.1.102dk.i586.rpm
699e613fea4270c79ee1849d96f1ee03 10.2/SRPMS/hostapd-0.3.7-2.1.102dk.src.rpm
Mandriva Linux 10.2/X86_64:
810b867b9562b11ce4ecb6ab7e3bd352 x86_64/10.2/RPMS/hostapd-0.3.7-2.1.102dk.x86_64.rpm
699e613fea4270c79ee1849d96f1ee03 x86_64/10.2/SRPMS/hostapd-0.3.7-2.1.102dk.src.rpm
Mandriva Linux 2006.0:
4d85ab25bff640f3176c5bb55ddcc214 2006.0/RPMS/hostapd-0.3.7-2.1.20060mdk.i586.rpm
fe727611379d2f48798361d8d2be4bc1 2006.0/SRPMS/hostapd-0.3.7-2.1.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
a1952ce345775472df1aa7636fd7b5cc x86_64/2006.0/RPMS/hostapd-0.3.7-2.1.20060mdk.x86_64.rpm
fe727611379d2f48798361d8d2be4bc1 x86_64/2006.0/SRPMS/hostapd-0.3.7-2.1.20060mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEdHxdmqjQ0CJFipgRAmsqAKDSJ4QWyAHesEm8MG/L4EKESWrqGQCfXU32
vM/ImdapUkRz008VJuK9B4k=
=VLLi
- -----END PGP SIGNATURE-----
3.
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:089
http://www.mandriva.com/security/
_______________________________________________________________________
Package : kphone
Date : May 24, 2006
Affected: 2006.0
_______________________________________________________________________
Problem Description:
Kphone creates .qt/kphonerc with world-readable permissions, which
allows local users to read usernames and SIP passwords.
Packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2442
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2006.0:
fca945c8a4e1237ab7b684256ee00f63 2006.0/RPMS/kphone-4.2-5.1.20060mdk.i586.rpm
bd5080d59632c0ae685376bfe2084b76 2006.0/SRPMS/kphone-4.2-5.1.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
e109b023b0d240cead8eee2db6d3dcf1 x86_64/2006.0/RPMS/kphone-4.2-5.1.20060mdk.x86_64.rpm
bd5080d59632c0ae685376bfe2084b76 x86_64/2006.0/SRPMS/kphone-4.2-5.1.20060mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEdIHumqjQ0CJFipgRAj7ZAJ93pI0MbLZDIHjZRh/fOKGvcsBdZQCgtqBM
TIU5+9zC3iKfe3GowtdwBfM=
=cjpS
- -----END PGP SIGNATURE-----
4.
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:090
http://www.mandriva.com/security/
_______________________________________________________________________
Package : shadow-utils
Date : May 24, 2006
Affected: 10.2, Corporate 3.0, Multi Network Firewall 2.0
_______________________________________________________________________
Problem Description:
A potential security problem was found in the useradd tool when it
creates a new user's mailbox due to a missing argument to the open()
call, resulting in the first permissions of the file being some random
garbage found on the stack, which could possibly be held open for
reading or writing before the proper fchmod() call is executed.
Packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1174
_______________________________________________________________________
Updated Packages:
Mandriva Linux 10.2:
825d79682662b8a0fd0d1d4074df467c 10.2/RPMS/shadow-utils-4.0.3-9.1.102mdk.i586.rpm
611b3e5406342f3a005a91f5398c0f6e 10.2/SRPMS/shadow-utils-4.0.3-9.1.102mdk.src.rpm
Mandriva Linux 10.2/X86_64:
eb14eb3e3ad02685d0f979af3ca9ff8c x86_64/10.2/RPMS/shadow-utils-4.0.3-9.1.102mdk.x86_64.rpm
611b3e5406342f3a005a91f5398c0f6e x86_64/10.2/SRPMS/shadow-utils-4.0.3-9.1.102mdk.src.rpm
Corporate 3.0:
cd201b43668ffac7541855917452ed27 corporate/3.0/RPMS/shadow-utils-4.0.3-8.2.C30mdk.i586.rpm
275c41183422953389e9ea5fcb59fba5 corporate/3.0/SRPMS/shadow-utils-4.0.3-8.2.C30mdk.src.rpm
Corporate 3.0/X86_64:
7d1950aca0c535b23cc4d2697e0b9c98 x86_64/corporate/3.0/RPMS/shadow-utils-4.0.3-8.2.C30mdk.x86_64.rpm
275c41183422953389e9ea5fcb59fba5 x86_64/corporate/3.0/SRPMS/shadow-utils-4.0.3-8.2.C30mdk.src.rpm
Multi Network Firewall 2.0:
f666b2bb0f409216642756a9318ecf34 mnf/2.0/RPMS/shadow-utils-4.0.3-8.2.M20mdk.i586.rpm
3624267601a9263555d713cac566ab15 mnf/2.0/SRPMS/shadow-utils-4.0.3-8.2.M20mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEdIuumqjQ0CJFipgRAqhhAKCc5pAQXcsoqk1Dz3sd+PikgsSeMwCdGj7E
E2LakbxTgywlba5CaNmJWMU=
=tyLV
- -----END PGP SIGNATURE-----
5.
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:091
http://www.mandriva.com/security/
_______________________________________________________________________
Package : php
Date : May 24, 2006
Affected: 10.2, 2006.0, Corporate 3.0, Multi Network Firewall 2.0
_______________________________________________________________________
Problem Description:
An integer overflow in the wordwrap() function could allow attackers
to execute arbitrary code via certain long arguments that cause a small
buffer to be allocated, triggering a heap-based buffer overflow
(CVE-2006-1990).
The substr_compare() function in PHP 5.x and 4.4.2 could allow
attackers to cause a Denial of Service (memory access violation)
via an out-of-bounds offset argument (CVE-2006-1991).
The second vulnerability only affects Mandriva Linux 2006; earlier
versions shipped with older versions of PHP that do not contain the
substr_compare() function.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1990
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1991
_______________________________________________________________________
Updated Packages:
Mandriva Linux 10.2:
463d4dd124e7e161159703976b35344d 10.2/RPMS/libphp_common432-4.3.10-7.12.102mdk.i586.rpm
0a71e94de99b08ba787b23ef64c10357 10.2/RPMS/php432-devel-4.3.10-7.12.102mdk.i586.rpm
cfcaf5c400bd4d7ca64a2ae25eccb0b7 10.2/RPMS/php-cgi-4.3.10-7.12.102mdk.i586.rpm
321b4cad92d82d9bcd1f18170390f8ae 10.2/RPMS/php-cli-4.3.10-7.12.102mdk.i586.rpm
1bf084222c4f33676432bfb516d71582 10.2/SRPMS/php-4.3.10-7.12.102mdk.src.rpm
Mandriva Linux 10.2/X86_64:
54243bc33bd55e326aa05f321f767442 x86_64/10.2/RPMS/lib64php_common432-4.3.10-7.12.102mdk.x86_64.rpm
c1a6b0c185e4b39404493290cb80f86f x86_64/10.2/RPMS/php432-devel-4.3.10-7.12.102mdk.x86_64.rpm
b643924edc6d25dfeecdbb1cef532341 x86_64/10.2/RPMS/php-cgi-4.3.10-7.12.102mdk.x86_64.rpm
d393dc26dadaadf34fc6b7b44ee46399 x86_64/10.2/RPMS/php-cli-4.3.10-7.12.102mdk.x86_64.rpm
1bf084222c4f33676432bfb516d71582 x86_64/10.2/SRPMS/php-4.3.10-7.12.102mdk.src.rpm
Mandriva Linux 2006.0:
cbb4891a5ab88238d462a66e7363119e 2006.0/RPMS/libphp5_common5-5.0.4-9.9.20060mdk.i586.rpm
dd77930acc185da44c6946252d445438 2006.0/RPMS/php-cgi-5.0.4-9.9.20060mdk.i586.rpm
5de2486af340d1fe387f7ecafdf85df1 2006.0/RPMS/php-cli-5.0.4-9.9.20060mdk.i586.rpm
6dd3b49d29cc28508ea3efdb69e72a79 2006.0/RPMS/php-devel-5.0.4-9.9.20060mdk.i586.rpm
8e074aedcbd3126797bbe11c93e5bd04 2006.0/RPMS/php-fcgi-5.0.4-9.9.20060mdk.i586.rpm
f144d3a41b04047b9d8c536a37aa94e1 2006.0/SRPMS/php-5.0.4-9.9.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
2e0821b3b925cc9c37391b061045c303 x86_64/2006.0/RPMS/lib64php5_common5-5.0.4-9.9.20060mdk.x86_64.rpm
c0ad86b0b332c058a9a18f5a41aca912 x86_64/2006.0/RPMS/php-cgi-5.0.4-9.9.20060mdk.x86_64.rpm
3c1ed4a2f1063fc53aec7a776af24939 x86_64/2006.0/RPMS/php-cli-5.0.4-9.9.20060mdk.x86_64.rpm
855bd247b561da4284eacbab95432123 x86_64/2006.0/RPMS/php-devel-5.0.4-9.9.20060mdk.x86_64.rpm
c504785298c305fd107ea6fdeff52211 x86_64/2006.0/RPMS/php-fcgi-5.0.4-9.9.20060mdk.x86_64.rpm
f144d3a41b04047b9d8c536a37aa94e1 x86_64/2006.0/SRPMS/php-5.0.4-9.9.20060mdk.src.rpm
Corporate 3.0:
bb6a0d81b011c1f859fb741544154b07 corporate/3.0/RPMS/libphp_common432-4.3.4-4.16.C30mdk.i586.rpm
e2d7f6bc462561ade323f97558491e8a corporate/3.0/RPMS/php432-devel-4.3.4-4.16.C30mdk.i586.rpm
61f46043b662e05c6eb33ab9ca28661a corporate/3.0/RPMS/php-cgi-4.3.4-4.16.C30mdk.i586.rpm
8ca7582e4edab0bf77f260247401d94d corporate/3.0/RPMS/php-cli-4.3.4-4.16.C30mdk.i586.rpm
b411e308d530cc2879b3087eb3f0f016 corporate/3.0/SRPMS/php-4.3.4-4.16.C30mdk.src.rpm
Corporate 3.0/X86_64:
9cdb80932f1e0a551fe6e494b4fe7436 x86_64/corporate/3.0/RPMS/lib64php_common432-4.3.4-4.16.C30mdk.x86_64.rpm
9027c979fa2b6b05917941f51c621a0a x86_64/corporate/3.0/RPMS/php432-devel-4.3.4-4.16.C30mdk.x86_64.rpm
b1fad86cb60c067daebba9383d033c84 x86_64/corporate/3.0/RPMS/php-cgi-4.3.4-4.16.C30mdk.x86_64.rpm
d43daff0afa35122d1dfa29291b94fd3 x86_64/corporate/3.0/RPMS/php-cli-4.3.4-4.16.C30mdk.x86_64.rpm
b411e308d530cc2879b3087eb3f0f016 x86_64/corporate/3.0/SRPMS/php-4.3.4-4.16.C30mdk.src.rpm
Multi Network Firewall 2.0:
9bb29e292e0f7612bd3ca38762262c85 mnf/2.0/RPMS/libphp_common432-4.3.4-4.16.M20mdk.i586.rpm
9ad22ab66b3523d634dad69e126f7f44 mnf/2.0/RPMS/php432-devel-4.3.4-4.16.M20mdk.i586.rpm
6d130a0f45e5a23b1134a2ef5a721995 mnf/2.0/RPMS/php-cgi-4.3.4-4.16.M20mdk.i586.rpm
725f1e0d0fa61e2a912f2899225b6f87 mnf/2.0/RPMS/php-cli-4.3.4-4.16.M20mdk.i586.rpm
29c7cfe26747e0fcd9168448e47dbc75 mnf/2.0/SRPMS/php-4.3.4-4.16.M20mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEdJpOmqjQ0CJFipgRAvVuAJ9pXmScwuAXOfpLdFlGV7Juqw0h0ACfel1e
qWITtbmSuMA8sBfFscgwXrg=
=/EmR
- -----END PGP SIGNATURE-----