Two patches from Cisco

Opinion
Aug 24, 20064 mins

* Patches from Cisco, Microsoft, Mandriva, others * Beware new Sdbot variant that spreads through network shares by exploiting known Windows flaws * Experts divided over rootkit detection and removal, and other interesting reading

Today’s bug patches and security alerts:

Cisco patches security appliances

A flaw in Cisco’s PIX 500 Series Security Appliances, the ASA 5500 Series Adaptive Security Appliances (ASA), and the Firewall Services Module could allow passwords to be changed without user intervention. An attacker could exploit this to gain access to an affected device. A patch is available.

Cisco fixes VPN 3000 Concentrator FTP Management flaws

According to a Cisco advisory, “The Cisco VPN 3000 series concentrators are affected by two vulnerabilities when file management via File Transfer Protocol (FTP) is enabled that could allow authenticated or unauthenticated attackers to execute certain FTP commands and delete files on the concentrator.” A fix is available.

**********

Microsoft delays re-issue of IE patch

Microsoft has pushed back the re-release of a buggy Internet Explorer (IE) security update, saying that the quality of its software is still not up to snuff. IDG News Service, 08/22/06.

Microsoft’s August IE patch contains security bug

Instead of making the browser more secure, Microsoft’s August Internet Explorer security update introduced a critical security bug, according to researchers at eEye Digital Security. IDG News Service, 08/22/06.

**********

New updates for Mandriva:

php (code execution)

Firefox for Corporate 3 users (upgrade/security fixes)

Thunderbird for Corporate 3 users (upgrade/security fixes)

squirrelmail (cross scripting vulnerability)

**********

New patches for Gentoo:

fbida (command execution)

Heimdal (local privilege escalation)

**********

Today’s roundup of virus alerts:

W32/Sdbot-DTM — A new Sdbot variant that spreads through network shares by exploiting known Windows flaws. It drops “lsass.exe” in the Windows folder and allows backdoor access through IRC. (Sophos)

W32/Brontok-BH — A Windows worm that tries to overwrite certain file types, including images, audio and video. It installs a number of files on the infected system, including “4k51k4.exe” in the root folder. (Sophos)

W32/Brontok-BJ — A Brontok variant that spreads through an e-mail message with an attachment called “Picture.zip”. It drops a number of randomly named files on the infected host, including “yesbron.com” in the folder off the Application Data directory. (Sophos)

W32/Virut-A — A backdoor IRC worm that also infects any running exe process on the infected host. (Sophos)

W32/Poebot-HV — Another IRC backdoor worm that spreads by exploiting known Windows vulnerabilities. It installs “explorer.exe” in the System folder. (Sophos)

W32/Cuebot-M — A Trojan that spreads through AOL Instant Messenger and the Windows Server Service vulnerability. It installs “wgavm.exe” in the System directory. (Sophos)

Troj/Zlob-QV — A virus that changes Internet Explorer’s search settings. It drops “isaddon.dll” and “isamini.exe” in the Current folder of the infected host. (Sophos)

Troj/Goldun-DV — This Trojan is installed as a Browser Helper Object called “msdeco.dll”. (Sophos)

W32/Tilebot-GH — A new Tilebot variant that allows backdoor access to the infected host through an IRC channel. It spreads through network shares by exploiting known Windows flaws and drops “servicemon.exe” in the System directory. (Sophos)

Troj/SpyDldr-J — A spyware downloader that displays fake error messages on the affected host. It installs a number of files in the Windows System directory, including “qjrkvy.exe”. (Sophos)

From the interesting reading department:

Experts divided over rootkit detection and removal

The detection and eradication of rootkits — the software code increasingly used to hide malware or adware — is either fairly simple or nearly impossible, depending on which security expert is bringing up the topic. NetworkWorld.com, 08/22/06.

IBM to acquire ISS for $1.3 billion

IBM Wednesday announced its intent to acquire Internet Security Systems for $1.3 billion in an all-cash deal expected to be completed by year-end. NetworkWorld.com, 08/23/06.

Sophos offers free rootkit detection tool

Called Sophos Anti-Rootkit, the software will detect and remove both known and unknown rootkits, and it will also warn system administrators if removing the software might harm operating system integrity. IDG News Service, 08/23/06.