* Patches from Sun, Debian, Trustix, others * Beware new Mytob variant that spreads via a message that looks like an account warning
endif; ?>Today’s bug patches and security alerts:
Sun patches Java Web Proxy Server
Three vulnerabilities have been found in the Sun Java Web Proxy Server. The flaws could be exploited in a denial-of-service attack against the affected machine. Sun has released Version 3.6 Service Pack 8 to fix the problem. For more, go to:
https://sunsolve.sun.com/search/document.do?assetkey=1-26-101913-1
Related updates:
Apple:
https://docs.info.apple.com/article.html?artnum=302265
https://docs.info.apple.com/article.html?artnum=302266
**********
HP warns of flaw in OpenView Network Node Manager
According to an HP advisory, “Potential vulnerabilities have been identified with OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely by an unauthorized user to gain privileged access.” For more, go to:
https://www.securityfocus.com/archive/1/409720/30/60/threaded
**********
More Squid updates available
As we reported earlier in the week, a denial of service vulnerability has been found in the open source Squid proxy server. Specifically, the flaw is in the “store.c” code library. Additional fixes are available:
Debian:
https://www.debian.org/security/2005/dsa-809
Gentoo:
https://security.gentoo.org/glsa/glsa-200509-06.xml
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:162
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2005.021-squid.html
**********
More Apache updates available
A couple of vulnerabilities have been found in the popular Apache Web server, both Version 1 and 2. The flaws could be exploited in a cross-scripting attack against other servers. For more, go to:
Debian (Apache):
https://www.debian.org/security/2005/dsa-803
Debian (Apache2):
https://www.debian.org/security/2005/dsa-805
Mandriva (Apache2):
https://www.mandriva.com/security/advisories?name=MDKSA-2005:161
SuSE:
https://www.novell.com/linux/security/advisories/2005_51_apache2.html
Ubuntu (Apache):
http://www.networkworld.com/go2/0912bug2a.html
Ubuntu (Apache2):
http://www.networkworld.com/go2/0912bug2b.html
**********
Trustix releases a “multi” update
A new update from Trustix fixes flaws apache, openssh and squid. The most serious of the flaws could be exploited to run malicious code on the affected machine. For more, go to:
https://www.trustix.org/errata/2005/0047/
**********
Debian patches kdelibs
A number of KDE graphical environments contain multiple flaws. The most serious of them could be exploited to gain root access on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-804
**********
Today’s roundup of virus alerts:
Troj/Dloader-UC — A new downloader Trojan that pulls additional malicious code from the Internet. It drops “ipwf.exe” in the Windows System folder. (Sophos)
W32/Rbot-ANK — An Rbot variant that spreads through network shares by exploiting a number of Windows vulnerabilities. Rbot allows backdoor access via IRC and can be used for a number of malicious applications. This variant drops “mswinsck.exe” in the Windows System folder. (Sophos)
W32/Rbot-ANP –Another similar Rbot variant. This one drops “sdktemp.exe” in the Windows System folder. (Sophos)
W32/Sdbot-ACZ — An Sdbot variant that exploits multiple Windows flaws as it spreads via network shares. It installs itself as “plou.exe” in the Windows System folder and allows backdoor access via IRC. (Sophos)
Troj/Dropper-BC — A virus that drops “gfgdgfddfgdfgwe.exe” in the Windows system. Fortunately, it’s a corrupt file and will not run. (Sophos)
Troj/Dropper-BD — Another corrupted version of Dropper. This one installs “gfgdgfd.exe”. (Sophos)
W32/Goldax-A — Goldax is a peer-to-peer worm that drops “mcfCC4.dll” and “mcfdrv.sys” in the Windows System folder of the infected machine. It places a number of files that look like porn on the infected system. (Sophos)
Troj/Divo-B — A Trojan that tries to steal personal information entered into banking sites, It spreads via network shares and displays a message in Spanish or English asking the user to enter “memorable information”. (Sophos)
Troj/WinterLv-A — A backdoor Trojan that allows attackers to steal information, launch denial-of-service attacks, create an FTP server and more. It registers itself as the service called “Networksvc”. (Sophos)
W32/Mytob-JM — A new Mytob variant that spreads via a message that looks like an account warning. It usually comes as an attachment with a double extension. It installs itself as “Lien Van de Kelder.exe” in the Windows System folder and can limit access to security related Web sites by modifying the Windows HOSTS file. (Sophos)




