New updates from Apple

Opinion
Jul 6, 20065 mins

* Patches from Apple, Debian, Gentoo, others * Beware latest Clagger variants * After feud, researcher promises daily browser bugs, and other interesting reading

Today’s bug patches and security alerts:

Apple patches iTunes

A denial-of-service vulnerability has been found in Apple’s iTunes, the popular music/podcast aggregation application. The flaw is in the way AAC files are handled and could be exploited with a specially crafted AAC file. iTunes Version 6.0.5 fixes the problem.

iTunes download page

Apple releases revised Mac OS X 10.4.7 update

A previous 10.4.7 update for Intel-based systems did not include certain files related to OpenGL performance. This new update fixes that issue.

**********

OpenOffice.org warns of three vulnerabilities

OpenOffice.org is warning users of security vulnerabilities that can crash the OpenOffice.org productivity software and give malicious hackers access to full system resources. IDG News Service, 07/03/06.

OpenOffice advisory

Related fix from Debian

**********

New patches from Debian:

pinball (privilege escalation)

kernel-source-2.6.8 (multiple flaws)

**********

New updates from Gentoo:

Horde Web Application Framework (cross scripting flaw)

Tikiwiki (multiple flaws)

Kiax (code execution)

mpg123 (heap overflow, code execution)

**********

New patches from Mandriva:

libwmf (multiple overflows)

mutt (buffer overflow)

**********

Today’s roundup of virus alerts:

Troj/Clagger-U — A Clagger variant that spreads through an e-mail written in German and a title containing the word “eBay”. It drops “ipf.exe” in the Windows System folder and attempts to download additional malicious code from remote sites. (Sophos)

Troj/Clagger-V — A second variant of the Clagger worm. This one drops “new.exe” in the System folder. (Sophos)

Troj/Zlob-PH — A Windows Trojan that attempts to download additional malware from remote sites. It is initially installed as “regperf.exe” in the System directory. (Sophos)

Troj/Zlob-PI — A second Zlob variant that drops multiple files on the target host, including “regperf.exe” in the Windows System folder. (Sophos)

Troj/Zlob-PK — A third Zlob variant that is similar to the previous two. This one drops “Media-Codecuninst.exe” on the infected host. (Sophos)

Troj/Banker-CLP — A Trojan that targets customers of Brazilian banking sites. It drops “wcntfy.exe” in the System and Startup folders. (Sophos)

Troj/Banker-CSX — Another Trojan targeting user credentials for various banking sites. It drops “nvcpll.exe” in the Windows System folder and uses its own SMTP engine to e-mail its harvest. (Sophos)

Troj/ConHook-K — Another Trojan with the main task of downloading malicious code from the ‘Net. It drops “RunDll32.exe” in the System folder. (Sophos)

W32/Akbot-AB — A backdoor worm that spreads through network shares by exploiting known Windows buffer overflow flaws. It drops “utasvc.dll” in the Windows System directory and modifies the HOSTS file to prevent access to certain security Web sites. (Sophos)

Kelvir.EO — A new Kelvir variant that spreads by exploiting known Windows flaws. It starts its own FTP server and installs a rootkit on the infected host. (Panda Software)

W32/Cuebot-K — A virus that spreads through AOL Instant Messenger. It drops “wgavn.exe” in the Windows System folder and can be used to provide backdoor access to the infected host. (Sophos)

Troj/Lineage-VJ — A password stealing Trojan that drops “pdll.dll” in the System folder and “svchost.exe” in the Windows directory. (Sophos)

Troj/SpyDldr-J — A virus that places a number of files on the infected host to make it appear to be filled with malware. It initially drops a number of files on the host, including “qjrkvy.exe” in the System folder. (Sophos)

W32/Brontok-BB — A Brontok variant that spreads through an e-mail titled “Fotoku yg Paling Cantik” or “My Best Photo” and comes with the attachment named “Photo.zip”. The virus will try to terminate a number of security-related applications that may be running on the infected host. (Sophos)

W32/Tilebot-FR — A new Tilebot variant that spreads through network shares by exploiting known Windows vulnerabilities. It drops “winlogon.exe” in the System folder and allows backdoor access through IRC. (Sophos)

Troj/Cimuz-AO — An information stealing Trojan that targets e-mail usernames and passwords, screenshot captures and more. It drops “ipv6mons.dll” in the Windows System folder. (Sophos)

Troj/Cimuz-AP — A second version of the information stealing that uses the same file (ipv6mons.dll) as its infection point. (Sophos)

Troj/Ogre-A — A password stealing Trojan that targets Orkut credentials. The virus displays a fake login page to steal in the info. (Sophos)

W32/Looked-B — A Windows worm that drops “rundl132.exe” on the infected host in the Windows System folder. No word on what damage can be caused by this worm. (Sophos)

Troj/Agent-CDK — Another backdoor Trojan that can be used to download additional malicious code. It registers “cosvcx.exe” in the Windows Registry. (Sophos)

Troj/Dloadr-YT — This virus can be used to download and install additional malicious file on the infected host. It is initially installed as “upnp.exe” in the System folder. (Sophos)

**********

From the interesting reading department:

After feud, researcher promises daily browser bugs

The creator of a widely used hacking tool has promised to publish details on one browser vulnerability per day for the month of July. HD Moore, the hacker behind the Metasploit toolkit, began publishing software that demonstrates bugs in a variety of Web browsers on July 1. He has dubbed his effort the Month of Browser Bugs. IDG News Service, 07/05/06.

Ransomware, other Trojans dominate in 2006

Ransomware, or software that takes control of a computer and demands money in exchange for access to files, is one type of Trojan Horse program growing in popularity, according to Sophos’ mid-year security report issued on Wednesday. NetworkWorld.com, 07/05/06.

McAfee sees 400,000 virus definitions by 2008

Although widespread virus outbreaks may be a thing of the past, the total amount of malicious software being written is on the rise, according to McAfee. IDG News Service, 07/05/06.