Re: apache and CAN-2003-0020

2005-03-24 Thread Joey Hess
Geoff Crompton wrote: CAN-2003-0020 is a vulnerability in apache that mentions how apache allows escape sequences into the error logs, which might exploit a terminal program viewing them. More detail is at http://www.securityfocus.com/bid/9930. The securityfocus page lists Debian as being

apache and CAN-2003-0020

2005-03-22 Thread Geoff Crompton
CAN-2003-0020 is a vulnerability in apache that mentions how apache allows escape sequences into the error logs, which might exploit a terminal program viewing them. More detail is at http://www.securityfocus.com/bid/9930. The securityfocus page lists Debian as being vulnerable, and I can't

Re: apache and CAN-2003-0020

2005-03-22 Thread Christophe Chisogne
Geoff Crompton a écrit : I can't find a DSA that corresponds to CAN-2003-0020. Woody isnt affected[1] : CAN-2003-0020: Apache: Missing filter for terminal escape sequences from error logs Ch. [1] Non-Vulnerability Security Information for woody http://www.nl.debian.org/security/nonvulns-woody

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-20 Thread Giacomo Mulas
On Mon, 19 Apr 2004, Jan Minar wrote: On Mon, Apr 19, 2004 at 11:18:41AM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 07:51:27PM +0200, Jan Minar wrote: Come on, Matt: Virtually all terminal emulators are vulnerable, and the vulnerability is a common knowledge. The

Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be contained in the data. I've read this [1]analysis by by H D Moore. No matter how convenient the escape sequences that allow

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 06:08:51PM +0200, Jan Minar wrote: On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be contained in the data. I've read this [1]analysis by by H D Moore.

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 09:32:47AM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 06:08:51PM +0200, Jan Minar wrote: On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 07:51:27PM +0200, Jan Minar wrote: Come on, Matt: Virtually all terminal emulators are vulnerable, and the vulnerability is a common knowledge. The abovementioned paper was on Bugtraq 2003-02-24 21:02:52... Is the Security Team going to do something about it

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 11:18:41AM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 07:51:27PM +0200, Jan Minar wrote: Come on, Matt: Virtually all terminal emulators are vulnerable, and the vulnerability is a common knowledge. The abovementioned paper was on Bugtraq 2003-02-24

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: And as a part of this community, I am... [doing more pointing and whining] Did you miss the bit where I said that didn't help? Haha, I can feel the free spirit of the computer labs of the late sixties:

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Stephen Gran
This one time, at band camp, Matt Zimmerman said: On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: % ssh kh [EMAIL PROTECTED]'s password: Linux kontryhel 2.4.26-jan #3 SMP Mon Apr 19 05:00:00 CEST 2004 i686 unknown % echo 'Morning, Mister root, welcome to a jail 8-)' /dev/tty63

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
I believe that the permissions are changed to allow a logged in user to access that terminal. The permissions are handled and reset by the appropriate log in service. [EMAIL PROTECTED]:~$ ls -lh /dev/pts/3 crw---1 plhofmei tty 136, 3 Apr 19 16:47 /dev/pts/3 [EMAIL PROTECTED]:~$

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 01:07:59PM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: And as a part of this community, I am... [doing more pointing and whining] We are going astray. Maybe a time to rephrase... We have security issues in Debian stable

Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be contained in the data. I've read this [1]analysis by by H D Moore. No matter how convenient the escape sequences that allow

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 06:08:51PM +0200, Jan Minar wrote: On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be contained in the data. I've read this [1]analysis by by H D Moore.

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 09:32:47AM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 06:08:51PM +0200, Jan Minar wrote: On Sun, Apr 18, 2004 at 11:58:21AM -0700, Matt Zimmerman wrote: untrusted source. This is a fundamental Unix feature (or flaw). Terminal control sequences may be

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 07:51:27PM +0200, Jan Minar wrote: Come on, Matt: Virtually all terminal emulators are vulnerable, and the vulnerability is a common knowledge. The abovementioned paper was on Bugtraq 2003-02-24 21:02:52... Is the Security Team going to do something about it

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 11:18:41AM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 07:51:27PM +0200, Jan Minar wrote: Come on, Matt: Virtually all terminal emulators are vulnerable, and the vulnerability is a common knowledge. The abovementioned paper was on Bugtraq 2003-02-24

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: And as a part of this community, I am... [doing more pointing and whining] Did you miss the bit where I said that didn't help? Haha, I can feel the free spirit of the computer labs of the late sixties:

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Stephen Gran
This one time, at band camp, Matt Zimmerman said: On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: % ssh kh [EMAIL PROTECTED]'s password: Linux kontryhel 2.4.26-jan #3 SMP Mon Apr 19 05:00:00 CEST 2004 i686 unknown % echo 'Morning, Mister root, welcome to a jail 8-)' /dev/tty63

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
I believe that the permissions are changed to allow a logged in user to access that terminal. The permissions are handled and reset by the appropriate log in service. [EMAIL PROTECTED]:~$ ls -lh /dev/pts/3 crw---1 plhofmei tty 136, 3 Apr 19 16:47 /dev/pts/3 [EMAIL PROTECTED]:~$

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Jan Minar
On Mon, Apr 19, 2004 at 01:07:59PM -0700, Matt Zimmerman wrote: On Mon, Apr 19, 2004 at 09:31:27PM +0200, Jan Minar wrote: And as a part of this community, I am... [doing more pointing and whining] We are going astray. Maybe a time to rephrase... We have security issues in Debian stable

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Michael Stone
On Mon, Apr 19, 2004 at 11:18:51PM +0200, Jan Minar wrote: It's not about Eterm, or the console.c in Linux, or the tty permissions, it's about the bigger picture. The bigger picture is that there are security problems and there are security problems. The only specific problem you pointed out

Re: CAN-2003-0020?

2004-04-18 Thread Matt Zimmerman
On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? Current consensus between the security team and the Apache maintainers is that it is not necessary to fix this in woody

Re: CAN-2003-0020?

2004-04-18 Thread Jan Lühr
Greetings, Am Sonntag, 18. April 2004 18:56 schrieb Matt Zimmerman: On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? Current consensus between the security team

Re: CAN-2003-0020?

2004-04-18 Thread Matt Zimmerman
On Sun, Apr 18, 2004 at 08:47:16PM +0200, Jan L?hr wrote: Am Sonntag, 18. April 2004 18:56 schrieb Matt Zimmerman: On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix

Re: CAN-2003-0020?

2004-04-18 Thread Matt Zimmerman
On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? Current consensus between the security team and the Apache maintainers is that it is not necessary to fix this in woody

Re: CAN-2003-0020?

2004-04-18 Thread Jan Lühr
Greetings, Am Sonntag, 18. April 2004 18:56 schrieb Matt Zimmerman: On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? Current consensus between the security team

Re: CAN-2003-0020?

2004-04-18 Thread Matt Zimmerman
On Sun, Apr 18, 2004 at 08:47:16PM +0200, Jan L?hr wrote: Am Sonntag, 18. April 2004 18:56 schrieb Matt Zimmerman: On Sat, Apr 17, 2004 at 10:16:11PM +0200, Jan L??hr wrote: what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix

CAN-2003-0020?

2004-04-17 Thread Jan Lhr
Greetings, what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? keep smiling yanosz -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

CAN-2003-0020?

2004-04-17 Thread Jan Lühr
Greetings, what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? keep smiling yanosz