21-patch salute from Microsoft

Opinion
Jun 15, 20065 mins

* Patches from Microsoft, KDE, others * Virus spreads between Yahoo Mail users

Today’s bug patches and security alerts:

Microsoft releases fixes for 21 vulnerabilities

In one of the largest security updates since moving to a monthly patch release cycle, Microsoft Tuesday issued 12 bulletins detailing fixes for 21 separate vulnerabilities in a wide range of products. Eight of the bulletins and 12 of the vulnerabilities were rated “critical” by the company. Three bulletins detailed fixes for “important” flaws, while one described a flaw of moderate severity. The vulnerabilities disclosed Tuesday affect several Microsoft products, including Internet Explorer (IE), Windows Media Player, Microsoft Outlook and PowerPoint. Computerworld, 06/13/06.

Microsoft advisories:

MS06-021: Cumulative Security Update for Internet Explorer

MS06-022: Vulnerability in ART Image Rendering Could Allow Remote Code Execution

MS06-023: Vulnerability in Microsoft JScript Could Allow Remote Code Execution

MS06-024: Vulnerability in Windows Media Player Could Allow Remote Code Execution

MS06-025: Vulnerability in Routing and Remote Access Could Allow Remote Code Execution

MS06-026: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

MS06-027: Vulnerability in Microsoft Word Could Allow Remote Code Execution

MS06-028: Vulnerability in Microsoft PowerPoint Could Allow Remote Code Execution

MS06-029: Vulnerability in Microsoft Exchange Server Running Outlook Web Access Could Allow Script Injection

MS06-030: Vulnerability in Server Message Block Could Allow Elevation of Privilege

MS06-032: Vulnerability in TCP/IP Could Allow Remote Code Execution

MS06-031: Vulnerability in RPC Mutual Authentication Could Allow Spoofing

Related advisories:

ISS: Vulnerability in Windows Media Player Could Allow Code Execution

US-CERT advisory: Microsoft Windows, Internet Explorer, Media Player, Word, PowerPoint and Exchange Vulnerabilities

Exploits for Microsoft flaws circulating

Security firms are warning about the availability of attack code targeting some of the flaws for which Microsoft released patches Tuesday. Most of the exploits target flaws that were previously known but for which patches became available only as part of Microsoft’s June monthly security update. But at least two publicly available exploits are directed at newly disclosed flaws in the company’s products. Computerworld, 06/14/06.

Microsoft leaves 98 to the hackers

Microsoft has defended its decision not to patch a critical security flaw in Windows 98. Support for the operating system officially ends next month on July 12. The vulnerability exists in Windows Explorer and the way it handles Component Object Model objects, whereby a malicious Website could force a connection to a remote server where Explorer could fail, executing arbitrary code and giving the attacker complete control of the operating system. Computerworld, 06/14/06.

**********

KDE releases update to fix flaws

KDE 3.2.0 up to including 3.5.3 ships with a flawed version of KDM, a tool for selecting login types. The setting for this could be exploited in a symlink attack.

**********

eEye warns of Symantec flaws

According to the eEye advisory, “eEye Digital Security has discovered a vulnerability in the remote management interface for Symantec AntiVirus 10.x and Symantec Client Security 3.x, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system.”

**********

FreeBSD patches sendmail

A flaw in sendmail could be exploited by a remote user to crash the affected system, halting e-mail delivery to an affected site. An update is available.

**********

Today’s roundup of virus alerts:

Troj/Small-BWB — A downloader Trojan that is initially installed as “svchw.exe” in the system32 folder. (Sophos)

JS.Yamanner@m — A virus that spreads between Yahoo Mail users. The message sender is listed as “av3@yahoo.com” and has a subject line of “New Graphic Site”. The message just needs to be open for the Trojan to activate. (Sophos)

Troj/Zapchas-BM — A backdoor worm that allows access to the infected host through IRC. It drops a number of files in the Windows System folder, including “svchost.exe”. (Sophos)

W32/Melo-E — A virus that spreads through network shares and attempts to delete top level files on the A: and C: drive. It also tries to spread by appending information to Hotmail messages. The virus kills security related processes running on the host. (Sophos)

Troj/Mailbot-AJ — A Trojan that can be used to send spam and acts as an Internet proxy. It drops “mnew6win.exe” in the Windows System folder. (Sophos)

Troj/Zlob-NW — A downloader Trojan that targets Windows machines. It drops “regperf.exe” in the Windows System directory. (Sophos)

W32/Sdbot-BVK — A new Sdbot variant that spreads through network shares by exploiting weak passwords and known Windows flaws. It installs “netbtd.exe” in the System folder. (Sophos)

Troj/Agent-CBA — Yet another downloader Trojan that can be used to install malicious code on an infected host. This variant drops “clcbt.exe” in the System folder. (Sophos)

Troj/LdPinch-LL — A password stealing Trojan that sends its bounty to a remote site via SMTP. (Sophos)

Troj/Adclick-CP — A virus that seems to be used to access advertising Web sites. It drops a number of files on the target host, including “536net.html” in the Temp folder. (Sophos)

BlackAngel.B — This virus spreads through MSN Messenger by posing a video called “Fantasma”. If clicked, an image is display and security settings are modified on the infected host. (Panda Software)

W32/Tilebot-FI — An IRC backdoor worm that spreads through network shares by exploiting known Windows flaws. It can be used to harvest information and start malicious services on the infected host. “netbtd.exe” is installed in the Windows System folder. (Sophos)

Troj/Agent-CBA — A stealth downloader Trojan that installs “clcbt.exe” in the Windows System folder. (Sophos)

**********