A dozen patches coming from Microsoft

Opinion
Jun 12, 20063 mins

* Patches from Ubuntu, Mandriva, Debian, others * Beware new Sdbot variant that exploits known Windows flaws as it spreads through network shares

Today’s bug patches and security alerts:

Microsoft to issue 12 patches on Patch Tuesday

Windows administrators are going to be busy next week, as Microsoft plans to release a whopping 12 security patches for its products. The updates will include a fix for a widely reported vulnerability in Microsoft Word, as well as changes to the way Internet Explorer (IE) handles ActiveX that might cause headaches for some. IDG News Service, 06/08/06.

**********

New ‘multi’ from Trustix

Trustix has released yet another “multi” update that fixes problems in binutils, mysql and spamassassin. The most serious of the flaws could be exploited to run malicious code on an affected system.

**********

New updates from Ubuntu:

PostgreSQL client/server (multiple flaws)

PostgreSQL client (multiple flaws)

Tiff (buffer overflow)

FreeType (multiple flaws)

binutils (buffer overflow, code execution)

gdm (password bypass)

courier (denial of service)

xine-lib (buffer overflow)

firefox (multiple flaws)

**********

Debian releases new fixes:

tiff (buffer overflows)

MySQL 4.1 (SQL injection)

xine-ui (format string, DoS)

gforge (cross-scripting vulnerability)

freetype (multiple flaws)

**********

New patches from Mandriva:

postgresql (SQL injection)

MySQL (SQL injection)

openldap (buffer overflow)

**********

New updates from Gentoo:

WordPress (command execution)

Vixie Cron (root privileges)

AWStats (code execution)

**********

Today’s roundup of virus alerts:

W32/Tilebot-FD — This IRC backdoor drops “smss.exe” in the Windows folder after spreading through network shares by exploiting known Windows flaws. It can communicate with remote sites via HTTP. (Sophos)

Troj/Spyjack-O — A virus that changes the Windows wallpaper to a message claiming the infected host has spyware. It drops a number of files on the target machine, including “intell32.exe” in the System folder. It can communicate with remotes sites via HTTP. (Sophos)

W32/Sdbot-BUK — A new Sdbot variant that exploits known Windows flaws as it spreads through network shares. It allows backdoor access via IRC after dropping a randomly-named .exe file in the System directory. (Sophos)

W32/Rbot-ECQ — This Rbot variant spreads through network shares by exploiting weak passwords. It drops “p2pnetworking.exe” in the Windows System folder, allows backdoor access through IRC and can upload files to an FTP server. (Sophos)

Troj/Banker-BWC — This Trojan monitors Web activity until it comes upon a banksite, then it displays a fake login page in an effort to steal user credentials. It drops “lsass32.exe” in the System and Startup folders. (Sophos)

Troj/Zlob-MW — A Trojan that is installed as “media codec” and drops “regperf.exe” and other files in the Windows System folder. (Sophos)

Troj/Zapchas-BL — A backdoor worm that drops its own mIRC application on the infected host. A key file that is dropped: “You Have Been HaCkeD By Me.jpg” in the Window System folder. (Sophos)

W32/Opanki-BT — A backdoor IRC worm that spreads through AOL instant messaging and by exploiting known Windows flaws. It installs “scvhost.exe” in the Windows folder. (Sophos)