* Patches from Ubuntu, Debian, others * Beware viruses starting to target Online Poker sites * Blue Security waves white flag, and other interesting reading
Today’s bug patches and security alerts:
Researchers reports Novell NDPS vulnerability
According to researchers at Hustle Labs, “There’s an integer overflow present that affects Novell Windows clients and Novell Netware server and Novell Open Enterprise server.” A remote attacker could exploit the vulnerabilities. Updates are available.
Novell advisories:
NDPS on NetWare remote integer overflow vulnerability
NDPS client remote integer overflow vulnerability
**********
A flaw in the RealVNC remote access server could be exploited to gain access to the host machine without needing to know the password. The attacker would have the privileges of the user (usually Administrator) running the RealVNC server. Those running the service behind a firewall or SSH tunnel are protected.
**********
A number of vulnerabilities have been found in the Quagga server for Ubuntu. Attackers could exploit these for denial of service attacks and to potentially run arbitrary code.
**********
A cross-scripting vulnerabilities in phpLDAPadmin, a Web interface for configuring LDAP servers, could be exploited by an attacker to inject HTML and script code on to the infected system.
According to a Debian advisory, “David Maciejak noticed that webcalendar, a PHP-Based multi-user calendar, returns different error messages on login attempts for an invalid password and a non-existing user, allowing remote attackers to gain information about valid usernames.” A fix is available.
**********
Today’s roundup of virus alerts:
Researchers at F-Secure find new viruses are starting to target Online Poker sites. The money is there, so criminals are sure to follow.
Troj/Mlsuc-C — A Trojan that can be used to reboot a machine, transfer files between infected hosts, delete files and terminate processed running on the host. It drops a number of files in the System folder, including “phde32.sys”. (Sophos)
Troj/Zlob-JR — A downloader Trojan that installs “wininet.dll” and “regperf.exe” on the infected host. It can be used to install/execute additional malicious code. (Sophos)
Troj/Zlob-JU — Another Zlob variant. This one drops “simpole.tlb” and “stdole3.tlb” in the Windows System directory. (Sophos)
Troj/Banloa-ACM — A backdoor Trojan that is installed as “Isass.scr” in the Windows System folder. It can be used to download additional malicious code to the infected host. (Sophos)
Troj/Clicker-CM — Another malicious code downloader. This one drops a numerous files on the infected host, including “IeHelperEx.dll” in the Windows System directory. It registers itself as a Browser Helper Object. (Sophos)
Troj/WowPWS-H — A password stealing Trojan that targets World of Warcraft users. It is installed as “lsass.exe” in the Windows System folder. (Sophos)
W32/Bagle-JJ — A new Bagle mass-mailing worm that usually comes as a ZIP attachment. Its main task is to harvest e-mail addresses from the infected host. (Sophos)
W32/Kidala-B — A mass-mailing and network worm that exploits known Windows flaws. It is installed as “Swords.exe” in the Windows System directory and can be used in DoS attacks, to download code and shut off security applications. (Sophos)
W32/Brontok-AQ — An e-mail worm that spreads through a message titled “Fotoku yg Paling Cantik” or “My Best Photo”, both coming with a “photo.zip” attachment. It closes windows on the infected host and installs “msvbvm60.dll” in the System directory. (Sophos)
Troj/Cimuz-AI — A backdoor worm that can communicate with remote sites via HTTP and can be used to steal e-mail account usernames and passwords. It is installed as “ipv4mons.dll”. (Sophos)
Troj/Agent-BMV — This downloader Trojan drops a number of files in the Windows folder, including “pf78.exe” and “pf79.exe”. (Sophos)
Troj/Mdrop-AMA — A malware dropper that initially installs “mc-110-12-0000118.exe” in the Windows System folder. (Sophos)
Troj/Drsmartl-S — Yet another worm designed to drop additional malicious code and malware on an infected host. This worm initially installs “newname.dat” in the Windows directory. (Sophos)
**********
From the interesting reading department:
Blue Security waves white flag
Israeli anti-spam firm Blue Security Tuesday said that it is ceasing operations after a crippling series of attacks launched against its services earlier this month by a Russian spammer named PharmaMaster. Computerworld, 05/17/06.
Revamped Symantec security client due next year
Symantec is readying a new application for enterprise PCs that will integrate security and network policy enforcement technology the company picked up from recent acquisitions. IDG News Service, 05/17/06.




