Microsoft, Intel re-release patches

Opinion
Aug 28, 20064 mins

* Patches from Microsoft, Intel, Trustix, others * Beware virus spreading through an e-mail message that looks like a failed sent message * IT execs feel the heat as security woes multiply, and other interesting reading

Today’s bug patches and security alerts:

Microsoft finally re-issues botched IE patch

Two days later than expected, Microsoft has re-issued a critical security update for its Internet Explorer (IE) browser. The re-issued patch is important because it “fully resolves” a serious security bug Microsoft introduced with the original update, released Aug. 8. IDG News Service, 08/24/06.

**********

Intel wireless patch a memory hog

Microsoft isn’t the only company re-issuing security patches this month. Intel plans to re-release a critical security patch for its Centrino platform because of a memory hogging bug. The updated patch should be available on Intel’s Web site Friday, said Amy Martin, an Intel spokeswoman. At issue is a bug in the Proset wireless connection software that came with the update. This flaw causes Proset to consume more and more of the PC’s memory, ultimately bringing performance to a grinding halt. IDG News Service, 08/24/06.

**********

Trustix releases “multi” update

The latest update from Trustix fixes flaws in imagemagick, kernel, php and php4. The most serious of the flaws could be exploited to run malicious code on an affected system.

**********

FreeBSD issues patch for ppp

A buffer overflow in FreeBSD’s implementation of the ppp protocol could be exploited by an attacker to gain elevated privileges on the affected machine. A fix is available.

**********

New updates for Debian:

squirrelmail (info disclosure)

sendmail (denial of service)

**********

New patches from Mandriva:

xorg-x11 (buffer overflow, code execution)

MySQL (unauthorized data access)

kernel (multiple flaws)

wireshark (multiple flaws)

**********

New fixes from Gentoo:

AlsaPlayer (multiple flaws)

Heartbeat (denial of service)

Heimdal (local privilege escalation)

**********

Today’s roundup of virus alerts:

W32/Stration-A — A virus that spreads through an e-mail message that looks like a failed sent message. The attachment is called “body.log.cmd” and the virus drops “svchost32.exe” in the Windows folder. It can be used to download additional malicious code. (Sophos)

Troj/Haxdoor-DA — Another e-mail message that tries to disguise itself as an order confirmation with an attached ZIP file. If opened, it drops a number of files in the Windows System folder, including “ycsvgd.sys”. It allows backdoor access to the infected host. (Sophos)

W32/Looked-H and I — This virus spreads through network shares and attempts to infect running EXE programs. It initially drops “rundl132.exe” in the Windows folder. (Sophos)

Troj/Banker-CZP — A windows Trojan that drops “msnmsgr.exe” in the Startup folder and in a Windows sub-directory. It can send notification of its existence to remote sites. (Sophos)

Troj/Clagger-AA — A downloader Trojan that attempts to install additional malicious code on the infected host. “1.exe” is initially installed in the Windows folder. (Sophos)

W32/Fanbot-D — An IRC backdoor worm that is installed as “remote.exe” in the Windows System folder. (Sophos)

W32/Toyep-A — An e-mail worm that claims to be a receipt for payment or requests payment. The infected message will have an attachment called “data.zip”. It initially drops “mfcapi32u.exe” in the Windows System folder. (Sophos)

W32/VBSilly-B — A virus that spreads by infecting attached USB drives. It initially drops a number of files on the infected host, including “windows.pif” in the Startup folder. (Sophos)

**********

From the interesting reading department:

IT execs feel the heat as security woes multiply

With security threats increasing and regulation tightening, companies are demanding greater IT accountability – and that can mean being forced to walk the plank after a breach. Network World, 08/25/06.

Paris Hilton accused of voice-mail hacking

The feud between celebrities Paris Hilton and Lindsay Lohan has taken a turn for the geeky, with a small fake Caller ID seller accusing Hilton of hacking into voicemail accounts on an un-named mobile phone network. IDG News Service, 08/25/06.