Two updates from Cisco

Opinion
Jun 29, 20065 mins

* Patches from Cisco, Apple, Ubuntu, others * Beware latest Bagle variants spreading via e-mail * Researcher publishes details of Amazon.com, MSN holes, and other interesting reading

Editor’s note: With the 4th of July holiday upon us, we will not be publishing Monday’s edition of this newsletter. We’ll be back at it on Thursday, July 6th after we’ve had our fill of hot dogs and fireworks.

Happy 4th of July!

Today’s bug patches and security alerts:

Cisco warns of flaws Web browser interface for access points

According to a Cisco advisory, “The Cisco web-browser interface for Cisco access points contains a vulnerability that could, under certain circumstances, remove the default security configuration from the managed access point and allow administrative access without validation of administrative user credentials.”

Cisco patches multiple flaws in Wireless Control System

Multiple vulnerabilities in Cisco Wireless Control System could be exploited execute script on the system or reveal sensitive configuration information. An update is available from Cisco.

**********

Microsoft warns of exploit code for dial-up bug

Microsoft is warning users of malicious software that could be used to attack Windows systems that lack the company’s latest security updates. IDG News Service, 06/26/06.

Microsoft advisory

**********

New security update from Apple

The latest update from Apple fixes flaws in Mac OS X 10.4.x. Among the applications patched: AFP, ClamAV, ImageIO, launchd and OpenLDAP.

**********

New updates from Ubuntu

mutt (code execution)

MySQL 4.1 (denial of service)

OpenLDAP (buffer overflow)

GnuPG (buffer overflow, code execution)

**********

New patches from OpenPKG:

png (buffer overflow)

gnupg (denial of service)

**********

New fixes from Gentoo:

Mutt (buffer overflow)

EnergyMech (denial of service)

Hashcash (heap overflow)

**********

New patches from Mandriva:

libwmf (integer overflow)

tetex (integer overflow)

GD (denial of service)

MySQL (denial of service)

gnupg (denial of service)

wv2 (integer overflow)

xine-lib (buffer overflow)

arts (root privileges)

**********

Today’s roundup of virus alerts:

W32/Bagle-KJ — A Bagle variant that spreads through e-mail messages titled “To the beloved” or “I love you” and has an attachment with a person’s name. It drops “hidn2.exe” in the Application Datahidn directory. (Sophos)

W32/Bagle-JJ — Another Bagle variant that spreads through e-mail attachments. It’s main purpose is to harvest e-mail addresses. (Sophos)

W32/Tilebot-FR — An IRC backdoor worm that spreads through network shares by exploiting known Windows flaws and weak passwords. It drops “winlogon.exe” in the Windows folder. (Sophos)

W32/Tilebot-FA — A second Tilebot variant that spreads in the same manner, but drops “services.exe” in the Windows folder. It can be used to setup a proxy server, steal information and sniff packets. (Sophos)

W32/Rbot-EMO — Another Rbot variant that allows backdoor access to the infected host through IRC. The Trojan can be used to sniff packets, start an FTP or Web server and log key presses. It drops “HIMENSYST.EXE” in the Windows System folder. (Sophos)

W32/Rbot-EHK — A second new Rbot variant that looks to setup shop on a host and allow access through IRC. It drops “gamo.exe” in the Windows System folder. (Sophos)

W32/Rbot-EMH — Our third Rbot variant of the day uses a randomly named file to infect the host. It too spreads via network shares and allows backdoor access through IRC. (Sophos)

W32/Brontok-AZ — A new Brontok variant that spreads through an e-mail message titled “Fotoku yg Paling Cantik” or “My Best Photo” and the attachment “Photo.zip”. It drops a number of files on the infected host, including “c_32142k.com” in the System folder, and tries to disable certain processes running on the machine. (Sophos)

WM97/Kukudro-A — A Trojan that spreads through an infected Word document. The virus is spammed out through a message claiming to have a price list and comes with a zip file called “prices.zip”, “apple_prices.zip” or “sony_prices.zip”. (Sophos)

Troj/LdPinch-LL — A password stealing Trojan that targets certain applications, including Total commander, Windows commander, Far FTP. (Sophos)

Troj/Bancban-OJ — A Trojan that is installed as “taskmam.exe” in the Windows System folder and can communicate with remote hosts via HTTP. (Sophos)

Troj/LdPinc-LZ — This Trojan is designed to steal all sorts of information from the infected host, including IP address, drive information and more. It can also log keystrokes, sending the data to a remote site via HTTP. It installs “mssync20.exe” in the System directory. (Sophos)

Troj/Opnis-E — A Trojan that seems to install itself and do nothing else. It drops numerous files on the host, including “cswiz.dll” in the System directory. (Sophos)

Troj/Opnis-F — A second Opnis variant that does not seem to do much. This one drops “smwiz32.cmd” in the System directory. (Sophos)

Troj/Banker-CLQ — A virus that targets Internet banking information by monitoring Web activity on the infected host and putting up fake login screens when certain bank sites are accessed. The data is sent via a built-in SMTP engine to a remote site. (Sophos)

Troj/Backdr-D — A backdoor Trojan that can also act as a Web proxy server. It drops “svrmsg.dll” in the Windows System folder. (Sophos)

**********

From the interesting reading department:

Researcher publishes details of Amazon.com, MSN holes

Frustrated with what he calls a lack of response from Microsoft and Amazon.com, a security researcher has gone public with details of flaws on the two companies’ Web sites. IDG News Service, 06/28/06.

How to destroy a hard drive in five seconds

The Guard Dog destroys all the data on a drive, even in parts that computers cannot access, and it can erase any magnetic media — VHS tapes, DAT tapes, ZIP disks and the like — in the same way that it erases hard drives. NetworkWorld.com, 06/27/06.

Research center takes aim at ID theft

A group of schools, vendors and government agencies are banding together to fight identity fraud and theft through the creation of a research center at Utica College in New York. NetworkWorld.com, 06/28/06.

For spammers, a picture is better than 1,000 words

Spam is again on the rise, led by a flood of junk images that spammers have crafted over the past few months to trick e-mail filters, according to security vendors. IDG News Service, 06/27/06.