Updates for Debian, Mandriva, rPath

Opinion
Sep 4, 20064 mins

* Patches from Debian, Mandriva, rPath * Beware e-mail worm that harvests addresses from the Windows Address Book * Opinion: Phishers get fancy with Lamborghini e-mail scam, and other interesting reading

Today’s bug patches and security alerts:

New patches for Debian:

sendmail (denial of service)

capi4hylafax (code execution)

cheesetracker (buffer overflow, code execution)

apache (multiple flaws)

**********

New fixes for Mandriva:

xorg-x11 (elevated privileges)

sudo (updated whitelist)

MySQL (multiple flaws)

musicbrainz (code execution)

sendmail (denial of service)

**********

New updates for rPath:

kernel (multiple flaws)

ibmusicbrainz (code execution)

**********

Today’s roundup of virus alerts:

W32/Stration-D and E — An e-mail worm that harvests addresses from the Windows Address Book. The infected message will have an attachment with a double extension. It is installed as “svchost32.exe” in the Windows folder and can disable certain anti-virus applications. (Sophos)

Troj/Opnis-C — A Trojan that drops three files in the Windows System folder, two randonmly named and “vsre446EC7DB.exe”. No word on any permanent damage caused. (Sophos)

Troj/Zlob-RF — This Trojan is installed as “mscomserv.exe” in the Windows System folder and can be used to download additional malware. (Sophos)

W32/Rbot-FKQ — A new Rbot variant that spreads through network shares by exploiting known Windows flaws. It drops “ActiveScan.exe” in the System directory and can allow backdoor access via IRC. (Sophos)

W32/Rbot-FKR — A second new Rbot variant that spreads through the same methods as Rbot-FKQ above. This one drops “creative.exe” in the Windows System directory. (Sophos)

W32/Rbot-FKT — The third Rbot variant of the day also allows backdoor access through IRC. This one is installed as “vcshost.exe” in the Windows System folder. (Sophos)

Troj/Flecsip-K — A new backdoor Trojan that can communicate with remote servers via HTTP. It is installed as “apigrab.dll” in the Windows System directory. (Sophos)

Troj/Zapchas-BX — An IRC backdoor worm that drops a number of files in the Windows System folder, including “svchost.exe”. (Sophos)

W32/Sdbot-BAY — Another IRC backdoor worm that spreads through network shares by exploiting known Windows flaws. The worm drops “msput.exe” in the Windows folder. (Sophos)

Troj/Loot-BF — A Trojan that is used to send Spam from the infected host. It registers itself with the display name “Windows Log”. (Sophos)

W32/Feebs-BE — A mass-mailing worm that comes in a message titled “Protected Message Service” or something similar with an infected ZIP attachment. It drops “msrf.exe” in the System folder and populates file-sharing directories with copies of itself. (Sophos)

W32/Vanebot-C — A virus that allows backdoor access through IRC and spreads through network shares by exploiting known Windows flaws. It is initially installed as “jconsole.exe” in the System folder. It displays a fake error message claiming an application cannot run on Windows and requires a Linux emulator. (Sophos)

W32/Alcra-E — A Trojan that disguises itself as a Windows Media video file. It drops “MsMovies.exe” in a subfolder of the System directory and displays a fake error message that warns of a missing codec. (Sophos)

Troj/Smoodo-B — This Trojan disables anti-virus applications and tries to inject itself into the “svchost.exe” process. (Sophos)

Troj/Bancos-AUN — A Trojan that targets user information for Brazilian banking sites. It is installed as “tasklist32.exe” in the Windows System folder. (Sophos)

W32/Tilebot-GI — A Windows backdoor work that spreads through network shares by exploiting known operating system flaws. It installs “sql-smss.exe” in the System folder and allows access through an IRC channel. (Sophos)

Troj/Goldun-DZ — A virus designed to drop additional malware on the infected host. Goldun-DZ initially drops “mscbos.dll” in the Windows System folder. (Sophos)

**********

From the interesting reading department:

Opinion: Phishers get fancy with Lamborghini e-mail scam

Gee, I thought you were supposed to give something made of iron or wood on your sixth wedding anniversary, not a Lamborghini. NetworkWorld.com, 09/01/06.

GAO report critical of federal banks’ security

The Government Accountability Office (GAO) in Washington, D.C., Thursday issued an information security report critical of the Federal Reserve banks’ computer systems and networks that are used in selling Treasury notes at auctions. NetworkWorld.com, 09/01/06.

Q&A: ISS founder on IBM and beyond

Internet Security Systems (ISS) last week entered an agreement to be acquired by IBM for $1.3 billion in cash, a deal expected to close by the end of the year. Network World Senior Editor Ellen Messmer recently talked with Chris Klaus, founder and chief security advisor at ISS, about what he plans to do next – and it could involve an online virtual world he hopes you’ll visit, too. NetworkWorld.com, 09/01/06.

Quantum cryptography demo is a security first

Researchers demonstrate combination of quantum data encryption, quantum key distribution. NetworkWorld.com, 09/01/06.