* Patches from Microsoft, Debian, Ubuntu, others * Beware new variants of Mytob, Bagle, Rbot, more * Change in Microsoft Vista security system promises Windows migration headaches, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Microsoft patches critical Exchange, Windows flaws
Microsoft as expected on Tuesday released one critical security update for its Exchange messaging server and two security updates for Windows, one of which was critical. IDG News Service, 05/09/06.
Related advisory:
**********
Cisco warns of AVS TCP Relay vulnerability
According to a Cisco advisory, “Cisco Application Velocity System’s (AVS) default configuration allows transparent relay of TCP connections to any reachable destination TCP port if the receiving TCP service can process requests embedded in a HTTP POST method message. This issue does not require a software upgrade and can be mitigated by a configuration command for all affected customers. Fixed versions of the AVS software have been modified to provide a more secure default configuration.” A free update is available.
**********
New patches from Debian:
cgiirc (multiple buffer overflows)
Mozilla (denial of service, code execution)
**********
New patches from Ubuntu:
Nagios (buffer overflow, code execution)
**********
New updates from Mandriva:
**********
New patches from Gentoo:
pdnsd (Denial of service, possible code execution)
Mozilla Thunderbird (multiple flaws)
Nagios (buffer overflow, code execution)
**********
Today’s roundup of virus alerts:
W32/Kidala-A — A mass-mailing worm that installs an IRC backdoor on the infected host. It spreads through a message the looks like a bounced-message error. The infected attachment will have a zip, cmd, pif, scr, exe or com extension. It drops “LCD32.exe” in the Windows System folder. (Sophos)
Troj/Baglet-F — An e-mail harvesting worm that looks for addresses on an infected host and sends them to a pre-defined server. No word on any permanent damage caused. (Sophos)
Troj/WowPWS-E — This Trojan installs itself as “svchs0t.exe” in the SystemShellExt folder. No word on any damage caused. (Sophos)
Troj/Nethell-B — This virus can download and install additional malicious code from remote sites. Its main purpose is to steal login/password information for various Web sites. (Sophos)
Troj/Torpig-AP — This information-stealing worm drops three files in the
W32/Mytob-HT — A new Mytob variant that spreads through an e-mail claiming to be a warning about a suspended account. The infected attachment will have double extension ending in EXE, SCR or PIF. It drops “wupdate.exe” in the Windows System folder, can steal sensitive information and modifies the Windows HOSTS file to prevent access to certain security related Web sites. (Sophos)
Troj/Clagger-Q — A Trojan that communicates with remote sites via HTTP. It is installed as “1.exe” in the Windows System directory. (Sophos)
Troj/Clagger-R — This Clagger variant installs itself as “suhoy316.exe” in the Windows folder. (Sophos)
W32/Bobax-BV — This Bobax variant spreads through network shares by exploiting known Windows flaws. It also has a built-in SMTP engine to send out infected e-mails. (Sophos)
W32/Bagle-JE — This Bagle variant tries to harvest e-mail addresses from the infected host. It is installed as “csrss.exe” in the System folder. (Sophos)
Troj/Dloadr-UZ — A downloader app that is registered as a Browser Helper Object on the infected host. It is installed as “pio12.dll” in the System folder. (Sophos)
W32/Rbot-CHE — An Rbot variant that drops “updatem.exe” in the Windows System folder and allows backdoor access through IRC. It spreads through network shares by exploiting known Windows vulnerabilities. (Sophos)
Troj/KillSec-D — A Trojan that kills antivirus applications, modify the HOSTS file and steal information. It is installed as “winlogon.exe” in the Windows folder. (Sophos)
Troj/Danmec-G — This Trojan turns the infected host into a proxy for HTTP traffic. It drops a number of files on the infected machine, including “checkreg.exe” in the System folder. (Sophos)
W32/Erkez-G — A virus that spreads through an e-mail claiming to have photo attachments. It drops “AntiVirus Update.exe” in the Windows System folder. (Sophos)
Troj/CashGrab-P — A password-stealing Trojan that drops more than a dozen files on the infected host, including “msiesetup.exe” in the System directory. (Sophos)
**********
From the interesting reading department:
Change in Microsoft Vista security system promises Windows migration headaches
Corporate users with third-party, Windows-based authentication systems such as VPNs could face a difficult transition to Microsoft’s Vista because of an overhaul of the core Windows logon architecture, according to independent software vendors and analysts. Network World, 05/08/06.
Security Weblog: Botmaster goes to jail
Jeason James Ancheta, the 21-year-old criminal who masterminded a “bot” empire for financial gain, was sentenced yesterday to 57 months in prison. NetworkWorld.com, 05/10/06.
A interesting post to the Bugtraq mailing list by David Litchfield: A few people have asked me recently what it is I’m actually looking for from Oracle. I have a nice little laundry list of things, of course, but mostly all I’ve been waiting for is to hear Oracle to say, “We admit we have a problem with regards to security, but here’s our strategy and we’re going to make it better.”




