<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Open Source Security</title>
    <link>http://seclists.org/#oss-sec</link>
    <atom:link href="http://seclists.org/rss/oss-sec.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Discussion of security flaws, concepts, and practices in the Open Source community</description>
    <pubDate>Fri, 20 Nov 2009 18:00:05 GMT</pubDate>
    <lastBuildDate>Fri, 20 Nov 2009 18:00:05 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: CVE request: php 5.3.1 update</title>
    <link>http://seclists.org/oss-sec/2009/q4/183</link>
    <description>&lt;p&gt;Posted by Eren Türkay on Nov 20&lt;/p&gt;Bogdan Calin disclosed the details about that vulnerability on full-disclosure &lt;br&gt;
mailing list. He didn't disclosed his script but I wrote a PoC that works like &lt;br&gt;
a charm. It makes DoS possible for any server that runs PHP within 1 minute &lt;br&gt;
with a few requests.&lt;br&gt;
&lt;br&gt;
Additionally, this vulnerability affects 5.2.11. I guess all products before &lt;br&gt;
PHP 5.3.1 are vulnerable.&lt;br&gt;
&lt;br&gt;
I think this deserves CVE Id. Any ideas?&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 17:48:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/183</guid>
  </item>
  <item>
    <title>CVE Assignment nginx</title>
    <link>http://seclists.org/oss-sec/2009/q4/182</link>
    <description>&lt;p&gt;Posted by Josh Bressers on Nov 20&lt;/p&gt;I've not seen a CVE id for this one anywhere:&lt;br&gt;
&lt;br&gt;
CVE-2009-3896&lt;br&gt;
&lt;br&gt;
engine x (nginx) contains a null pointer dereference flaw in versions&lt;br&gt;
0.1.0-0.8.13 before versions 0.8.14, 0.7.62, 0.6.39 and 0.5.38.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://nginx.net/&quot;&gt;http://nginx.net/&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://marc.info/?l=nginx&amp;amp;m=125692080328141&amp;amp;w=2&quot;&gt;http://marc.info/?l=nginx&amp;amp;m=125692080328141&amp;amp;w=2&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=552035&quot;&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=552035&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/2009/dsa-1920&quot;&gt;http://www.debian.org/security/2009/dsa-1920&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Thanks&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 15:36:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/182</guid>
  </item>
  <item>
    <title>Re: CVE request: php 5.3.1 update</title>
    <link>http://seclists.org/oss-sec/2009/q4/181</link>
    <description>&lt;p&gt;Posted by Tomas Hoger on Nov 20&lt;/p&gt;Link to announcement mail with CVEs:&lt;br&gt;
&lt;br&gt;
  &lt;a  rel=&quot;nofollow&quot; href=&quot;http://news.php.net/php.announce/79&quot;&gt;http://news.php.net/php.announce/79&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Reading the upstream bug &lt;a  rel=&quot;nofollow&quot; href=&quot;http://bugs.php.net/bug.php?id=50063&quot;&gt;http://bugs.php.net/bug.php?id=50063&lt;/a&gt; , this is&lt;br&gt;
not a security flaw, rather a safe_mode regression causing uid check to&lt;br&gt;
happen where it should not resulting in over-restrictive safe_mode.&lt;br&gt;
&lt;br&gt;
Some links for the other two issues:&lt;br&gt;
&lt;br&gt;
  &lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/securityalert/6601&quot;&gt;http://securityreason.com/securityalert/6601&lt;/a&gt;&lt;br&gt;
  &lt;a  rel=&quot;nofollow&quot; href=&quot;http://svn.php.net/viewvc?view=revision&amp;amp;revision=288945&quot;&gt;http://svn.php.net/viewvc?view=revision&amp;amp;revision=288945&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 14:04:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/181</guid>
  </item>
  <item>
    <title>CVE request: v1.2.8 released to fix the 0777 base_dir creation issue</title>
    <link>http://seclists.org/oss-sec/2009/q4/180</link>
    <description>&lt;p&gt;Posted by Thomas Biege on Nov 20&lt;/p&gt;Hello.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.dovecot.org/list/dovecot-news/2009-November/000143.html&quot;&gt;http://www.dovecot.org/list/dovecot-news/2009-November/000143.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://dovecot.org/releases/1.2/dovecot-1.2.8.tar.gz&quot;&gt;http://dovecot.org/releases/1.2/dovecot-1.2.8.tar.gz&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://dovecot.org/releases/1.2/dovecot-1.2.8.tar.gz.sig&quot;&gt;http://dovecot.org/releases/1.2/dovecot-1.2.8.tar.gz.sig&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
This is mainly to fix the 0777 base_dir creation issue, which could be&lt;br&gt;
considered a security hole, exploitable by local users. An attacker&lt;br&gt;
could for example replace Dovecot's auth socket and log in as other&lt;br&gt;
users. Gaining root privileges isn't possible though....&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 11:41:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/180</guid>
  </item>
  <item>
    <title>Re: CVE request: php 5.3.1 update</title>
    <link>http://seclists.org/oss-sec/2009/q4/179</link>
    <description>&lt;p&gt;Posted by Joe Orton on Nov 20&lt;/p&gt;We assigned some CVE names for the new issues here; two correspond to &lt;br&gt;
existing issues fixed earlier in 5.2.11.  The CVE names have not made it &lt;br&gt;
to the web site but were used in the e-mail announcement text:&lt;br&gt;
&lt;br&gt;
- Added missing sanity checks around exif processing. (CVE-2009-3292, Ilia)&lt;br&gt;
- Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak.&lt;br&gt;
  (CVE-2009-3557, Rasmus)&lt;br&gt;
- Fixed a open_basedir bypass in posix_mkfifo() identified by...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 10:48:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/179</guid>
  </item>
  <item>
    <title>CVE request: php 5.3.1 update</title>
    <link>http://seclists.org/oss-sec/2009/q4/178</link>
    <description>&lt;p&gt;Posted by Thomas Biege on Nov 20&lt;/p&gt;Hello,&lt;br&gt;
&lt;br&gt;
PHP was updated to version 5.3.1 and did also address security&lt;br&gt;
issues: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.php.net/releases/5_3_1.php&quot;&gt;http://www.php.net/releases/5_3_1.php&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Security Enhancements and Fixes in PHP 5.3.1:&lt;br&gt;
&lt;br&gt;
    * Added &amp;quot;max_file_uploads&amp;quot; INI directive, which can be set to limit the number of file uploads per-request to 20 by &lt;br&gt;
default, to prevent possible DOS via temporary file exhaustion.&lt;br&gt;
    * Added missing sanity checks around exif processing.&lt;br&gt;
    * Fixed a safe_mode bypass...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 10:42:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/178</guid>
  </item>
  <item>
    <title>CVEs for nginx</title>
    <link>http://seclists.org/oss-sec/2009/q4/177</link>
    <description>&lt;p&gt;Posted by Craig on Nov 19&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
are the CVEs for&lt;br&gt;
&lt;br&gt;
1.) nginx webdav: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://secunia.com/advisories/36818/&quot;&gt;http://secunia.com/advisories/36818/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
2.) nginx Null Pointer dereference:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://sysoev.ru/nginx/patch.null.pointer.txt&quot;&gt;http://sysoev.ru/nginx/patch.null.pointer.txt&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
3.) nginx SSL Renegotiation: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://sysoev.ru/nginx/patch.cve-2009-3555.txt&quot;&gt;http://sysoev.ru/nginx/patch.cve-2009-3555.txt&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
I know the last one contains a CVE number, nginx uses openssl and the&lt;br&gt;
patch will disable renegotiation, maybe this deserves an own CVE?&lt;br&gt;
&lt;br&gt;
Best regards,&lt;br&gt;
&lt;br&gt;
Craig&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 01:36:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/177</guid>
  </item>


  <item>
    <title>mysql-5.1.41</title>
    <link>http://seclists.org/oss-sec/2009/q4/176</link>
    <description>&lt;p&gt;Posted by Oden Eriksson on Nov 19&lt;/p&gt;Hello.&lt;br&gt;
&lt;br&gt;
The new mysql release mentions two security issues that has been addressed, &lt;br&gt;
anyone knows more about that? I guess it would need some CVE assignment as &lt;br&gt;
well.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html&quot;&gt;http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 21:08:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/176</guid>
  </item>
  <item>
    <title>CVE assignment (libexif)</title>
    <link>http://seclists.org/oss-sec/2009/q4/175</link>
    <description>&lt;p&gt;Posted by Josh Bressers on Nov 19&lt;/p&gt;I'm giving libexif CVE-2009-3895. I've not seen an ID for this yet.&lt;br&gt;
&lt;br&gt;
Only libexif version 0.6.18 is affected, all other versions are safe.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://article.gmane.org/gmane.comp.graphics.libexif.devel/806&quot;&gt;http://article.gmane.org/gmane.comp.graphics.libexif.devel/806&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://bugs.gentoo.org/show_bug.cgi?id=293190&quot;&gt;http://bugs.gentoo.org/show_bug.cgi?id=293190&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Thanks.&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:06:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/175</guid>
  </item>
  <item>
    <title>CVE request: kernel: fuse: prevent fuse_put_request on invalid pointer</title>
    <link>http://seclists.org/oss-sec/2009/q4/174</link>
    <description>&lt;p&gt;Posted by Eugene Teo on Nov 19&lt;/p&gt;&amp;quot;fuse_direct_io() has a loop where requests are allocated in each &lt;br&gt;
iteration. if allocation fails, the loop is broken out and follows into &lt;br&gt;
an unconditional fuse_put_request() on that invalid pointer.&amp;quot;&lt;br&gt;
&lt;br&gt;
Upstream commit:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://git.kernel.org/linus/f60311d5f7670d9539b424e4ed8b5c0872fc9e83&quot;&gt;http://git.kernel.org/linus/f60311d5f7670d9539b424e4ed8b5c0872fc9e83&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
This can be triggered when the system is low on memory, and when the &lt;br&gt;
fuse_request_alloc() function called from fuse_get_req() fails. The...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 09:05:44 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/174</guid>
  </item>


  <item>
    <title>Re: CVE request: libpoppler4: buffer overflow in the Abiword backend</title>
    <link>http://seclists.org/oss-sec/2009/q4/173</link>
    <description>&lt;p&gt;Posted by Josh Bressers on Nov 18&lt;/p&gt;----- &amp;quot;Thomas Biege&amp;quot; &amp;lt;thomas () suse de&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
As an FYI, MITRE assigned this CVE-2009-3938.&lt;br&gt;
&lt;br&gt;
Thanks.&lt;br&gt;</description>
    <pubDate>Wed, 18 Nov 2009 18:26:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/173</guid>
  </item>
  <item>
    <title>Re: CVE request: virtualbox-ose guest can trigger denial of service at host, mem consumption</title>
    <link>http://seclists.org/oss-sec/2009/q4/172</link>
    <description>&lt;p&gt;Posted by Josh Bressers on Nov 18&lt;/p&gt;Use CVE-2009-3893 for this.&lt;br&gt;
&lt;br&gt;
Thanks.&lt;br&gt;</description>
    <pubDate>Wed, 18 Nov 2009 15:16:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/172</guid>
  </item>
  <item>
    <title>Re: CVE request: libpoppler4: buffer overflow in the Abiword backend</title>
    <link>http://seclists.org/oss-sec/2009/q4/171</link>
    <description>&lt;p&gt;Posted by Thomas Biege on Nov 17&lt;/p&gt;Our maintainer told me that version 3 and 5 are vulnerable too.&lt;br&gt;</description>
    <pubDate>Wed, 18 Nov 2009 07:08:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/171</guid>
  </item>


  <item>
    <title>Re: CVE request: oping allows the disclosure of  arbitrary file contents</title>
    <link>http://seclists.org/oss-sec/2009/q4/170</link>
    <description>&lt;p&gt;Posted by Tomas Hoger on Nov 17&lt;/p&gt;My previous web search did find that one.  Though set_user() doing&lt;br&gt;
NPROC check is only called when new uid differs from current real uid&lt;br&gt;
(so not called in setuid(getuid()) case).&lt;br&gt;</description>
    <pubDate>Tue, 17 Nov 2009 19:48:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/170</guid>
  </item>
  <item>
    <title>Re: CVE request: libpoppler4: buffer overflow in the Abiword backend</title>
    <link>http://seclists.org/oss-sec/2009/q4/169</link>
    <description>&lt;p&gt;Posted by Thomas Biege on Nov 17&lt;/p&gt;AFAICS it just affects libpoppler. But version 4 may not be the only&lt;br&gt;
one with the bug.&lt;br&gt;
&lt;br&gt;
Bye,&lt;br&gt;
     Thomas&lt;br&gt;</description>
    <pubDate>Tue, 17 Nov 2009 08:27:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/oss-sec/2009/q4/169</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
