* Patches from Debian, Ubuntu, OpenPKG, others * Beware virus that spreads through an e-mail claiming to be an order confirmation
endif; ?>Today’s bug patches and security alerts:
Cisco warns of VPN client flaw
According to a Cisco advisory, “The Cisco VPN Client for Windows is affected by a local privilege escalation vulnerability that allows non-privileged users to gain administrative privileges. A user needs to authenticate and start an interactive Windows session to be able to exploit this vulnerability.” A free update is available.
**********
US-CERT warns of Mozilla vulnerabilities
US-CERT has issued a warning regarding multiple flaws in Mozilla-based products. The vulnerabilities could be exploited to run malicious code on an affected system. Users should upgrade to Firefox 1.5.0.5, Thunderbird 1.5.05 and SeaMonkey 1.0.3.
**********
New updates for Debian:
Asterisk (buffer overflow, denial of service)
orisis (format string, code execution)
**********
New patches for Ubuntu:
freetype (integer overflow, code execution)
**********
New fixes for OpenPKG:
freetype (integer overflow, code execution)
**********
New patches for Mandriva:
perl-Net-Server (format string flaw)
**********
Today’s roundup of virus alerts:
Troj/Zlob-PV — A Trojan that is installed a Browser Helper Object. It drops a number of files in the Windows System folder, including “hp100.tmp”. (Sophos)
Troj/LegMir-YY — A virus that tries to harvest user information for the Legends of Mir game, sending the bounty to a remote site via an HTTP connection. (Sophos)
Troj/FakeVNC-A — This is a hacked version of VNC, which allows remote access to a computer. The malicious version claims to be “System Kernel Check for Win32”. (Sophos)
Troj/Haxdoor-CP — A virus that spreads through an e-mail claiming to be an order confirmation. The subject line is “Confirmation for Order WC2905036” and the attachment is “WC2905036.zip”. A number of files are dumped in the Windows System folder, including “yvsvga.dll”. (Sophos)
Troj/Bancos-ARD — An Internet banking Trojan that targets customers of Brazilian banks. It monitors for user login information and sends the data via e-mail to a remote site. The virus is installed as “tasklist32.exe” in the System folder. (Sophos)
Troj/Keylog-HD — A Trojan that starts with a three-picture slide show titled “Victoria Stasova”. It drops “svchst.exe” in the Windows folder and can communicate with a remote server via HTTP. (Sophos)
W32/Puce-H — A virus that seems to infect RAR and ZIP files found on the infected host. It initially drops “svchost.exe” in the Temp folder. (Sophos)
Troj/Agent-CIO — A backdoor Trojan that can access remote sites through an HTTP connection. It is installed as “mcvswin.exe” in the Windows directory. (Sophos)
Troj/Agent-CIQ — This Agent variant is installed as “VKTServ.exe” in the System folder and may also attempt to delete files. (Sophos)
W32/Looked-E — A backdoor Trojan that also tries to infect EXE files on the target host. It is installed as “rundl132.exe” in the Windows directory and may disable anti-virus applications. (Sophos)
Troj/Delf-EDE — A Windows Trojan that copies itself to the System folder as “svchoxt.exe”. No word on any permanent damage caused by Delf-EDE. (Sophos)
Troj/Opnis-C — A backdoor Trojan that is installed as three files in the Windows System folder: “vsre446EC7DB.exe” and a randomly-named EXE and DLL. (Sophos)
W32/Spybot-LA — This Trojan provides backdoor access to the infected host through an IRC channel. It is installed as “wns.exe” in the System directory. (Sophos)
W32/Tilebot-GD — A new Tilebot variant that exploits known Windows flaws as it spreads through network shares. It drops “smsc.exe” in the System folder and allows backdoor access via IRC. (Sophos)




