* Patches from Microsoft, Cisco, Ubuntu, others * Beware latest Clagger variant that installs itself as "suhoy336.exe" and can bypass the Windows firewall * Forget phishing, first 'vishing' attack surfaces, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Microsoft patches Excel, Office bugs
Microsoft Tuesday released its monthly round of security patches, fixing a number of widely reported bugs in its Excel and Office products. The July security updates include seven sets of patches. Four of the updates address bugs in the Windows operating system, while the other three fix problems in Office and Excel. More information on the updates can be found here. IDG News Service, 07/11/06.
Microsoft advisories:
Vulnerability in Server Service Could Allow Remote Code Execution
Vulnerability in DHCP Client Service Could Allow Remote Code Execution
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution
Vulnerability in ASP.NET Could Allow Information Disclosure
Related advisories:
ISS: DHCP Client vulnerability
3Com Zero Day Initiative advisory
**********
Cisco patches Intrusion Prevention System DoS flaw
According to a Cisco advisory, “Cisco Intrusion Prevention System (IPS) software Version 5.1 is vulnerable to a denial of service condition caused by a malformed packet, which may result in an IPS device becoming inaccessible remotely or via the console and fail to process packets. A power reset is required to recover the IPS device. There are no workarounds for this vulnerability.” A free update is available.
Cisco warns of insecure default IOS configuration
Cisco routers running IOS and shipped with the Cisco Router Web Setup (CRWS) application could be accessed without any user credentials. A new update to CRWS is available to close the hole.
Cisco patches multiple flaws in Unified CallManager
According to a Cisco alert, “Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) and Session Initiation Protocol (SIP) related vulnerabilities. There are potential privilege escalation vulnerabilities in the CLI which may allow an authenticated administrator to access the base operating system with root privileges. There is also a buffer overflow vulnerability in the processing of hostnames contained in a SIP request which may result in arbitrary code execution or cause a denial of service. These vulnerabilities only affect Cisco Unified CallManager 5.0.” A free update is available.
**********
New updates from Ubuntu:
installer (blank root password)
libmms, xine-lib (multiple flaws)
OpenOffice.org (multiple flaws)
**********
New patches from Debian:
**********
New update from Mandriva:
**********
New patches from Gentoo:
FreeType (buffer overflow, code execution)
SHOUTcast server (multiple flaws)
**********
Today’s roundup of virus alerts:
Troj/Riler-S — A backdoor Trojan that can spy on network connections. It can spread through an infected Word document or other “dropper application. “SNootern.dll” is dropped in the Windows System folder. (Sophos)
W32/Kassbot-T — An IRC backdoor worm that spreads through network shares. It installs itself as “svchosts.exe” in the Windows System folder. (Sophos)
W32/Puce-H — A virus that initially installs as “svchost.exe” in the Temp folder and then tries to infect RAR and ZIP files found on the infected host. (Sophos)
W32/Tilebot-FW — A new Tilebot variant that exploits known Windows flaws as it spreads between network shares. It drops “services.exe” in the System folder, allows backdoor access through IRC and signals its presence through an HTTP connection. (Sophos)
W32/Tilebot-FY — Another new Tilebot variant that uses known Windows flaws to spread. It drops “smsc.exe” in the System directory. (Sophos)
W32/Forbot-GK — A backdoor worm that is installed as “jebote.exe” in the System directory. (Sophos)
Troj/Clagger-W — This latest Clagger variant installs itself as “suhoy336.exe” in the Windows folder and can bypass the Windows firewall. It can be used to download and install additional malicious code from remote sites. (Sophos)
W32/Dozic-A — A new virus that tries to spread through AOL Instant Messenger. It drops on the infected host: “WinZod32.exe” in the Startup folder and “zod32.exe” in the System folder. (Sophos)
W32/LimpNet-A — A Windows worm that tries to copy itself to floppy disks and specific drive letters. It drops “plus.exe” in the Startup directory and “orawin.exe” in the Windows folder. (Sophos)
W32/Sality-I — A Trojan used for logging keystrokes and sending the captured data via e-mail to a specific address. It drops “wmimgr32.dll” in the Windows system folder. (Sophos)
W32/Rbot-CJY — A new Rbot variant that allows backdoor access to the infected host through IRC. It is installed as “uvselglip.EXE” in the Windows System folder. (Sophos)
Troj/Haxdoor-CO — A new backdoor variant that drops a number of files in the Windows System folder, including “dvb03a.dll”. (Sophos)
**********
From the interesting reading department:
Forget phishing, first ‘vishing’ attack surfaces
Secure Computing has reported an ingenious new type of phishing scam that uses VoIP telephony to entrap its victims. Dubbed “vishing”, the fraud involves a randomly dialed user being phoned by an automated system and told that their credit card has been used illegally. TechWorld, 07/12/06.
Mobile users face knotty security issues
High-profile security breaches may indicate that network executives are using trial and error to sort out the best ways to secure the brave new world of mobile computing. Network World, 07/12/06.
Retailers fail to pass security test
A full year after the deadline, a majority of large merchants face potential fines because they still aren’t in compliance with a data security standard created by major credit card companies including American Express, Discover, MasterCard and Visa. Network World, 07/10/06.
Google’s binary search helps dig up malware
A little-known capability in Google’s search engine has helped security vendor Websense uncover thousands of malicious Websites as well as several legitimate sites that have been hacked, the company said Friday. IDG News Service, 07/07/06.




