* Patches from Debian, OpenPKG, Ubuntu, Mandriva and others * New PowerPoint flaw used in attacks
endif; ?>Today’s bug patches and security alerts:
EEye warns of flaw in McAfee ePolicy Orchestrator
A flaw in the way the McAfee ePolicy Orchestrator accepts remote configuration information over port 8081 could be exploited by an attacker to run malicious code with System privileges. An update is available from McAfee.
**********
New PowerPoint flaw used in attacks
Attackers have found another hole in Microsoft’s Office products. On Thursday, Symantec reported that it has discovered a targeted attack that takes advantage of an unpatched vulnerability in Microsoft’s PowerPoint software. IDG News Service, 07/13/06.
**********
Debian, OpenPKG release fixes for mutt
According to the Debian advisory, “The mutt mail reader performs insufficient validation of values returned from an IMAP server, which might overflow a buffer and potentially lead to the injection of arbitrary code.”
**********
New updates for Ubuntu:
libtunepimp (multiple buffer overflows)
zope2.8 (privilege escalation)
**********
New patches for Mandriva:
php (multiple flaws, code execution)
xine-lib (buffer overflow, code execution)
libmms (buffer overflow, code execution)
**********
Today’s roundup of virus alerts:
W32/Tilebot-FY — A new Tilebot variant that spreads through network shares by exploiting known Windows flaws. It drops “smsc.exe” in the Windows System folder and allows backdoor access through IRC. (Sophos)
Troj/Vanity-A — A virus that injects code in other processes in an effort to evade detection. It initially drops “wowexecl.exe” in the System folder and can communicate with remote sites via HTTP. (Sophos)
Troj/Harnig-AH — A downloader Trojan that initially installs itself as “nt_system
W32/Feebs-AW — A virus that spreads through peer-to-peer networks and e-mail. The infected e-mail message will claim to have a username and password. The virus drops “ms??.exe” (?s are random characters) in the System directory. (Sophos)
Troj/WowPWS-O — Another virus with the main task of stealing passwords for the game “World of Warcraft”. It drops a number of files on the infected host, including “LSASS.exe” in the Windows directory. (Sophos)
W32/Bagle-JJ — An e-mail worm designed to harvest e-mail addresses from the infected host. The infected attachment will have ZIP extension. (Sophos)
W32/Rbot-CSC — A new Rbot variant that allows backdoor access to the infected Windows host through IRC. It installs “vmmon32.exe” in the System folder. (Sophos)
Troj/DownLd-AAG — A generic downloader Trojan that is used to copy additional malicious code from remote sites via HTTP. It is initially installed as a randomly named .exe file in the Windows System folder. (Sophos)
Troj/Edepol-C — A Trojan that can be dropped through infected PowerPoint files. Edepol-C can log keystrokes and send the captured data to pre-configured IP address. It installs “rtfmsv.exe” and “regvrt.exe” in the Windows System folder. (Sophos)
Trj/Semsy.B — This virus spreads through MSN Messenger by getting would-be recipients to click on a link. If installed, the virus tries to steal password data for the Orkut community. (Panda Software)
Troj/SpyDldr-L — Another downloader application that tries to install additional malware on the infected host. It drops “reger.exe” and “qjrkvy.exe” in the Windows system folder as well as many fake infected files on the host. (Sophos)
Troj/Squatbot-A — An interesting little Trojan that downloads a list of German IP addresses and begins scanning them looking for expired domains. The virus drops “remotewatch.exe” in the Program Files/remotewatch folder. (Sophos)
W32/Alcra-E — A Trojan that comes disguised as a Windows Media file. It drops “MsMoviesMsMovies.exe” in the Program Files folder and can be used to download/install additional malicious code. (Sophos)
Troj/Riler-T — This Trojan can be used to spy on Internet traffic. It is installed as “SNootern.dll” and “uidmngr.ini” in the Windows System directory. (Sophos)
**********
From the interesting reading department:
Researcher to show code for ‘wormable’ Windows flaw
With security vendors worrying that a recently patched Windows bug may lead to a major worm outbreak, the researcher who discovered the flaw said Wednesday that he is weeks away from releasing code that exploits the problem. IDG News Service, 07/12/06.
Phishers try to beat banks’ strong authentication
Scammers have found a way around new token-based authentication systems that have been adopted by some banks. IDG News Service, 07/13/06.
Consortium builds super firewall to stop DDOS
Computer researchers in Europe are developing a new prototype architecture for halting distributed denial-of-service attacks, where a barrage of traffic is directed at a Web site or server to shut it down. IDG News Service, 07/17/06.
IBM unveils security management software
Company debuts Tivoli security information management product developed from technology acquired with Micromuse and GuardedNet. NetworkWorld.com, 07/17/06.




