* Patches from Ubuntu, Mandriva, Debian, others * Beware new Sdbot variant that exploits known Windows flaws as it spreads through network shares
Today’s bug patches and security alerts:
Microsoft to issue 12 patches on Patch Tuesday
Windows administrators are going to be busy next week, as Microsoft plans to release a whopping 12 security patches for its products. The updates will include a fix for a widely reported vulnerability in Microsoft Word, as well as changes to the way Internet Explorer (IE) handles ActiveX that might cause headaches for some. IDG News Service, 06/08/06.
**********
Trustix has released yet another “multi” update that fixes problems in binutils, mysql and spamassassin. The most serious of the flaws could be exploited to run malicious code on an affected system.
**********
New updates from Ubuntu:
PostgreSQL client/server (multiple flaws)
PostgreSQL client (multiple flaws)
binutils (buffer overflow, code execution)
**********
Debian releases new fixes:
gforge (cross-scripting vulnerability)
**********
New patches from Mandriva:
**********
New updates from Gentoo:
**********
Today’s roundup of virus alerts:
W32/Tilebot-FD — This IRC backdoor drops “smss.exe” in the Windows folder after spreading through network shares by exploiting known Windows flaws. It can communicate with remote sites via HTTP. (Sophos)
Troj/Spyjack-O — A virus that changes the Windows wallpaper to a message claiming the infected host has spyware. It drops a number of files on the target machine, including “intell32.exe” in the System folder. It can communicate with remotes sites via HTTP. (Sophos)
W32/Sdbot-BUK — A new Sdbot variant that exploits known Windows flaws as it spreads through network shares. It allows backdoor access via IRC after dropping a randomly-named .exe file in the System directory. (Sophos)
W32/Rbot-ECQ — This Rbot variant spreads through network shares by exploiting weak passwords. It drops “p2pnetworking.exe” in the Windows System folder, allows backdoor access through IRC and can upload files to an FTP server. (Sophos)
Troj/Banker-BWC — This Trojan monitors Web activity until it comes upon a banksite, then it displays a fake login page in an effort to steal user credentials. It drops “lsass32.exe” in the System and Startup folders. (Sophos)
Troj/Zlob-MW — A Trojan that is installed as “media codec” and drops “regperf.exe” and other files in the Windows System folder. (Sophos)
Troj/Zapchas-BL — A backdoor worm that drops its own mIRC application on the infected host. A key file that is dropped: “You Have Been HaCkeD By Me.jpg” in the Window System folder. (Sophos)
W32/Opanki-BT — A backdoor IRC worm that spreads through AOL instant messaging and by exploiting known Windows flaws. It installs “scvhost.exe” in the Windows folder. (Sophos)




