* Patches from Apple, Trustix, Mandriva, others * Beware latest Tilebot variants * Technology Update: Security analyzers target vulnerabilities
endif; ?>Today’s bug patches and security alerts:
Apple releases new OS X update
A new update for Mac OS X 10.4.6 fixes flaws in numerous applications, including AppKit, ImageIO, BOM, CFNetwork, ClamAV, CoreFoundation, CoreGraphics, Finder, FTPServer, Flash Player, Keychain, LaunchServices, libcurl, Mail, MySQL Manager, Preview, QuickDraw, QuickTime Streaming Server, Ruby and Safari. The most serious of the flaws could be exploited to run code on the affected system.
Apple updates QuickTime to fix flaws
QuickTime 7.0 and earlier contain multiple vulnerabilities affecting both Windows PCs and Macs, according to an advisory from Apple. The most serious of the flaws could be exploited to run malicious code on affected systems. Users should upgrade to Version 7.1.
**********
Trustix releases kernel update
A number of flaws have been fixed in the Trustix Linux kernel, the most serious of which could be exploited by an attacker to run arbitrary code on the affected host.
**********
Debian releases Mozilla Firefox update
According to the Debian advisory, “Martijn Wargers and Nick Mott described crashes of Mozilla due to the use of a deleted controller context. In theory this could be abused to execute malicious code. Since Mozilla and Firefox share the same codebase, Firefox may be vulnerable as well.”
**********
A number of format string vulnerabilities xine-ui, which could be exploited by attackers to run malicious code on an affected system.
**********
The Gentoo implementation of the MySQL database is vulnerable to an information leak. Gentoo lists this as a low-priority update.
**********
New updates from Fedora:
emacs (format string flaw, code execution)
GnuPG (signature verification flaw)
**********
Today’s roundup of virus alerts:
W32/Tilebot-EV — A new Tilebot variant that spreads through network shares by exploiting known Windows flaws. It provides backdoor access through IRC and can communicate with remote servers via HTTP. It drops “userinit.exe” in the System folder. (Sophos)
W32/Tilebot-ER — A second similar Tilebot variant. This one installs itself as “winscntrl.exe” in the System directory. (Sophos)
Troj/Tibs-AK — A Trojan that communicates with remote sites over HTTP. It installs “taskdir.exe” in the Windows System folder. (Sophos)
Troj/Banker-BIP — A downloader Trojan that can install additional malicious code on the affected machine. It initially installs “system32.exe” to the System and Startup directories. (Sophos)
W32/Brontok-AE — An e-mail worm that spreads through messages from “angelina_ph” or “jennifer_sh” at the recipient’s domain. The message will have non-English text and a “photo.zip” attachment. It drops a new version of “msvbvm60.dll” in the Windows System folder. (Sophos)
Troj/VB-API — This Trojan installs itself as “ntxp2.exe” in the Windows folder. It’s main aim is to reduce system security. (Sophos)
W32/Poebot-ET — A backdoor Trojan that exploits known Windows flaws to spread between machines. It is installed as “iexplore.exe” in the Windows System folder. (Sophos)
Troj/Clicker-CM — A downloader Trojan that can install additional malicious code on the infected host. It is originally installed as “IeHelperEx.dll” in the Windows System folder. (Sophos)
W32/Kassbot-P — This IRC backdoor worm can be used to launch DoS attacks, download additional code and reduce system security. It spreads through AOL Instant Messenger and network shares by exploiting known Windows flaws. It is installed as “win32dll.exe” in the Windows folder. (Sophos)
Troj/Agent-BMT — Another malware downloader. It is installed as “qkjyt7dx.dll” in the Windows directory. (Sophos)
**********
From the interesting reading department:
Technology Update: Security analyzers target vulnerabilities
Protocol abuse targets vulnerabilities in many types of devices and applications, from firewalls, VoIP controllers and VPN gateways to intrusion-prevention systems and other perimeter defense. Despite the considerable investments made in security infrastructure, many vulnerabilities remain undetected. Network World, 05/11/06.




