Cisco patches Windows VPN client

Opinion
May 25, 20065 mins

* Patches from Cisco, Apple, Trustix, others * Beware data-stealing Trojan that sends its bounty to a remote site

Today’s bug patches and security alerts:

Cisco patches Windows VPN client

According to a Cisco advisory, “The Cisco VPN Client for Windows is affected by a local privilege escalation vulnerability that allows non-privileged users to gain administrative privileges. A user needs to authenticate and start an interactive Windows session to be able to exploit this vulnerability.”

**********

Apple releases Xcode Tools 2.3

A flaw in previous versions of Xcode Tools could allow WebObjects project open to modification by a remote user. The new update fixes the flaw.

**********

Trustix releases ‘Multi’ update

A new update from Trustix fixes flaws in the kernel and MySQL. The most serious of the flaws could be exploited to run malicious code on the affected host.

**********

Ubuntu patches AWStats

According to an Ubuntu advisory, “AWStats did not properly sanitize the ‘migrate’ CGI parameter. If the update of the stats via web front-end is allowed, a remote attacker could execute arbitrary commands on the server with the privileges of the AWStats server.” A fix is available.

**********

OpenPKG releases OpenLDAP update

A buffer overflow has been found in OpenLDAP that could be exploited through a boundary error in slurpd. A fix is available.

**********

New updates from Debian:

Kernel 2.4.18 (multiple flaws)

Kernel 2.4.19 (multiple flaws)

MySQL (multiple flaws)

MySQL 4.1 (multiple flaws)

nagios (buffer overflow, code execution)

mpg123 (buffer overflow)

**********

New fixes from Gentoo:

libextractor (heap overflows, code execution)

Quagga Routing Suite (multiple vulnerabilities)

**********

New patches from Mandriva:

kernel (multiple flaws)

hostapd (denial of service)

kphone (permissions issue)

shadow-utils (unauthorized mailboxes)

**********

Today’s roundup of virus alerts:

Troj/Wlook-A — This is an information stealing Trojan that installs itself as “loadhw.exe” in the Windows System folder. (Sophos)

W32/Bagle-JE — A mass-mailing worm that communicates with remote sites via HTTP and can be used to harvest e-mail addresses from the infected host. It drops “csrss.exe” in the Windows System folder. (Sophos)

W32/Brontok-Z — Another e-mail worm that looks to be sent from “angelina_ph” or jennifer_sh”, both appearing to be from the same domain as the target user. It’ll most likely have the subject line “My Best Photo” and an attachment called “Photo.zip”. It creates a number of random directories on the host and drops files such as “esbron.com” in multiple places. (Sophos)

Troj/Stinx-V — An IRC backdoor Trojan that installs “cmssr.exe” in the Windows System folder. (Sophos)

W32/Mytob-HV — An IRC backdoor that spreads through an e-mail appearing to be from “abuse@“. The message claims an account will be terminated unless you click the link. It installs “taskgmr.exe” in the Windows System folder. (Sophos)

W32/Mytob-HW — Another Mytob variant that uses “taskgmr.exe” in the System folder as its infection point. (Sophos)

W32/Mytob-HX — This Mytob variant also spreads through an e-mail message appearing to be from “abuse@“. It drops “windows.exe” in the System folder. (Sophos)

Troj/Opnis-C — A worm that drops a number of files on the infected host, including “vsre446EC7DB.exe” in the Windows System folder. No word on any permanent damage caused. (Sophos)

W32/Rbot-DRD — An IRC backdoor Trojan that can be used in denial-of-service attacks, log keystrokes and act as a SOCKS proxy. It spreads through network shares by exploiting known Windows flaws and through backdoors left by other Trojans. (Sophos)

W32/Sality-U — A virus that just seems to infect other files. Sophos is calling it “parasitic”. It installs “wdmfmc32.dll” in the Windows System folder. (Sophos)

W32/Zasran-A — An e-mail worm that spreads through an infected ZIP attachment. It drops “mszsrn32.dll” in the System directory. (Sophos)

W32/Zasran-B — A similar Zasran variant. This one expands the number of attachment names it can use, though all will have a ZIP extension. (Sophos)

Troj/Delf-CFX — This Trojan installs “weiba.exe” in the Windows System folder. No word on what sort of damage it can cause or tasks it may carry out. (Sophos)

W32/Traxg-E — A Trojan that displays a fake error message that a folder has been damaged. It spreads through network shares and e-mail. It is installed as a randomly named application. (Sophos)

Troj/Dloadr-HAA — A Trojan used for downloading and installing additional malicious code on the affected machine. It de-registers “shdocvw.dll” on the infected host. (Sophos)

W32/Bobandy-A — This worm seems to be used to harvest e-mail addresses from an infected host. It spreads through a message that appears to have a password-protected file attached. The infected attachment will have a .zip or .uu extension. (Sophos)

Troj/Haxdoor-AS — A data-stealing Trojan that sends its bounty to a remote site. It is installed as “satdll.dll” in the System directory. (Sophos)

W32/Kassbot-P — An IRC backdoor Trojan that can be used for DDoS attacks, port scanning and to terminate security applications. It spreads through network shares by exploiting known Windows flaws. It drops “win32dll.exe” in the Windows folder. (Sophos)

Troj/Banloa-ACM — A backdoor Trojan that installs itself as “Isass.scr”. It can communicate with remote sites via HTTP. (Sophos)

Troj/Rasdoor-D — A backdoor Trojan that drops “dc.exe” in the Temp folder. No other characteristics are given. (Sophos)