* Patches from Debian, Gentoo, Mandriva, others * Beware latest Bagle variants
Today’s bug patches and security alerts:
New updates from Debian:
Kernel 2.4.27 (multiple flaws)
horde3 (cross-scripting attack)
horde2 (cross-scripting attack)
**********
New patches from Gentoo:
Cscope (multiple buffer overflows)
JPEG library (denial of service)
Mozilla Firefox (multiple flaws)
Asterisk (buffer overflow, code execution)
OpenLDAP (buffer overflow, code execution)
**********
New fixes from Mandriva:
libtiff (buffer overflow, code execution)
**********
New patches from Ubuntu:
**********
Today’s roundup of virus alerts:
Troj/Haxdoor-HM — A backdoor Trojan that disables security related applications running on the infected host. It drops multiple files in the Windows System folder, including “pptp24.sys” and “qz.sys”. (Sophos)
Troj/Doctrix-A — A Windows Trojan that spreads through a file called “My Documents.exe”. No word on any permanent damage caused. (Sophos)
W32/Bagle-KH — A new Bagle variant that is installed as “hldrrr.exe” and can communicate with remote sites via HTTP. (Sophos)
W32/Bagle-KF — A second Bagle variant that drops “hldrrr.exe” in the System folder and connects with sites via HTTP. (Sophos)
W32/Bagle-KG — A mass-mailing Bagle variant that spreads through message with an infected ZIP file. It drops “elist.xpt” in the Windows folder. (Sophos)
Troj/Repkill-A — A virus that drops “svchost.exe” in the Windows folder and attempts to terminate certain system processes. (Sophos)
W32/Mytob-HY — A mass-mailing worm that spreads through a message titled “Account alert” and contains a link to the worm code. It drops “taskgmr.exe” in on the target host and allows backdoor access via IRC. (Sophos)
Troj/Stinx-W — An IRC backdoor Trojan that spreads through an e-mail message claiming to have TV footage of a violent crime. It drops “svchon32.exe” in the Windows System folder. (Sophos)
Troj/Zlob-RT — A downloader Trojan that injects code into the winlogon.exe process. It can also hijack a browser session. (Sophos)
Troj/Zlob-OS — This Zlob variant spreads by claiming to be an application for accessing pornographic Web sites. It drops a number of files in the System folder, including “ishost.exe” and “ismon.exe”. (Sophos)
W32/Tilebot-FK — This new Tilebot variant spreads through network shares by exploiting known Windows flaws. It is installed as “winscntrl.exe” in the System directory and allows backdoor access through IRC. (Sophos)




