Patches for Debian, Gentoo, Mandriva and Ubuntu

Opinion
Jun 19, 20063 mins

* Patches from Debian, Gentoo, Mandriva, others * Beware latest Bagle variants

Today’s bug patches and security alerts:

New updates from Debian:

webcalendar (code execution)

Kernel 2.4.27 (multiple flaws)

horde3 (cross-scripting attack)

horde2 (cross-scripting attack)

wv2 (integer overflow)

**********

New patches from Gentoo:

SpamAssassin (code execution)

Cscope (multiple buffer overflows)

JPEG library (denial of service)

Mozilla Firefox (multiple flaws)

MySQL (SQL injection)

GDM (privilege escalation)

Asterisk (buffer overflow, code execution)

DokuWiki (code injection)

OpenLDAP (buffer overflow, code execution)

PAM-MySQL (multiple flaws)

Sendmail (denial of service)

**********

New fixes from Mandriva:

freetype2 (denial of service)

GDM (privilege escalation)

squirrelmail (code execution)

libtiff (buffer overflow, code execution)

spamassassin (code execution)

Sendmail (denial of service)

**********

New patches from Ubuntu:

libgd2 (denial of service)

Thunderbird (multiple flaws)

dhcdbd (denial of service)

wv2 (integer overflow)

kdm (information disclosure)

MySQL (SQL injection)

kernel (multiple flaws)

**********

Today’s roundup of virus alerts:

Troj/Haxdoor-HM — A backdoor Trojan that disables security related applications running on the infected host. It drops multiple files in the Windows System folder, including “pptp24.sys” and “qz.sys”. (Sophos)

Troj/Doctrix-A — A Windows Trojan that spreads through a file called “My Documents.exe”. No word on any permanent damage caused. (Sophos)

W32/Bagle-KH — A new Bagle variant that is installed as “hldrrr.exe” and can communicate with remote sites via HTTP. (Sophos)

W32/Bagle-KF — A second Bagle variant that drops “hldrrr.exe” in the System folder and connects with sites via HTTP. (Sophos)

W32/Bagle-KG — A mass-mailing Bagle variant that spreads through message with an infected ZIP file. It drops “elist.xpt” in the Windows folder. (Sophos)

Troj/Repkill-A — A virus that drops “svchost.exe” in the Windows folder and attempts to terminate certain system processes. (Sophos)

W32/Mytob-HY — A mass-mailing worm that spreads through a message titled “Account alert” and contains a link to the worm code. It drops “taskgmr.exe” in on the target host and allows backdoor access via IRC. (Sophos)

Troj/Stinx-W — An IRC backdoor Trojan that spreads through an e-mail message claiming to have TV footage of a violent crime. It drops “svchon32.exe” in the Windows System folder. (Sophos)

Troj/Zlob-RT — A downloader Trojan that injects code into the winlogon.exe process. It can also hijack a browser session. (Sophos)

Troj/Zlob-OS — This Zlob variant spreads by claiming to be an application for accessing pornographic Web sites. It drops a number of files in the System folder, including “ishost.exe” and “ismon.exe”. (Sophos)

W32/Tilebot-FK — This new Tilebot variant spreads through network shares by exploiting known Windows flaws. It is installed as “winscntrl.exe” in the System directory and allows backdoor access through IRC. (Sophos)