Sun patches Java Web Proxy Server

Opinion
Sep 15, 20054 mins

* Patches from Sun, Debian, Trustix, others * Beware new Mytob variant that spreads via a message that looks like an account warning

Today’s bug patches and security alerts:

Sun patches Java Web Proxy Server

Three vulnerabilities have been found in the Sun Java Web Proxy Server. The flaws could be exploited in a denial-of-service attack against the affected machine. Sun has released Version 3.6 Service Pack 8 to fix the problem. For more, go to:

https://sunsolve.sun.com/search/document.do?assetkey=1-26-101913-1

Related updates:

Apple:

https://docs.info.apple.com/article.html?artnum=302265

https://docs.info.apple.com/article.html?artnum=302266

**********

HP warns of flaw in OpenView Network Node Manager

According to an HP advisory, “Potential vulnerabilities have been identified with OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely by an unauthorized user to gain privileged access.” For more, go to:

https://www.securityfocus.com/archive/1/409720/30/60/threaded

**********

More Squid updates available

As we reported earlier in the week, a denial of service vulnerability has been found in the open source Squid proxy server. Specifically, the flaw is in the “store.c” code library. Additional fixes are available:

Debian:

https://www.debian.org/security/2005/dsa-809

Gentoo:

https://security.gentoo.org/glsa/glsa-200509-06.xml

Mandriva:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:162

OpenPKG:

https://www.openpkg.org/security/OpenPKG-SA-2005.021-squid.html

**********

More Apache updates available

A couple of vulnerabilities have been found in the popular Apache Web server, both Version 1 and 2. The flaws could be exploited in a cross-scripting attack against other servers. For more, go to:

Debian (Apache):

https://www.debian.org/security/2005/dsa-803

Debian (Apache2):

https://www.debian.org/security/2005/dsa-805

Mandriva (Apache2):

https://www.mandriva.com/security/advisories?name=MDKSA-2005:161

SuSE:

https://www.novell.com/linux/security/advisories/2005_51_apache2.html

Ubuntu (Apache):

http://www.networkworld.com/go2/0912bug2a.html

Ubuntu (Apache2):

http://www.networkworld.com/go2/0912bug2b.html

**********

Trustix releases a “multi” update

A new update from Trustix fixes flaws apache, openssh and squid. The most serious of the flaws could be exploited to run malicious code on the affected machine. For more, go to:

https://www.trustix.org/errata/2005/0047/

**********

Debian patches kdelibs

A number of KDE graphical environments contain multiple flaws. The most serious of them could be exploited to gain root access on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-804

**********

Today’s roundup of virus alerts:

Troj/Dloader-UC — A new downloader Trojan that pulls additional malicious code from the Internet. It drops “ipwf.exe” in the Windows System folder. (Sophos)

W32/Rbot-ANK — An Rbot variant that spreads through network shares by exploiting a number of Windows vulnerabilities. Rbot allows backdoor access via IRC and can be used for a number of malicious applications. This variant drops “mswinsck.exe” in the  Windows System folder. (Sophos)

W32/Rbot-ANP –Another similar Rbot variant. This one drops “sdktemp.exe” in the Windows System folder. (Sophos)

W32/Sdbot-ACZ — An Sdbot variant that exploits multiple Windows flaws as it spreads via network shares. It installs itself as “plou.exe” in the Windows System folder and allows backdoor access via IRC. (Sophos)

Troj/Dropper-BC — A virus that drops “gfgdgfddfgdfgwe.exe” in the Windows system. Fortunately, it’s a corrupt file and will not run. (Sophos)

Troj/Dropper-BD — Another corrupted version of Dropper. This one installs “gfgdgfd.exe”. (Sophos)

W32/Goldax-A — Goldax is a peer-to-peer worm that drops “mcfCC4.dll” and “mcfdrv.sys” in the Windows System folder of the infected machine. It places a number of files that look like porn on the infected system. (Sophos)

Troj/Divo-B — A Trojan that tries to steal personal information entered into banking sites, It spreads via network shares and displays a message in Spanish or English asking the user to enter “memorable information”. (Sophos)

Troj/WinterLv-A — A backdoor Trojan that allows attackers to steal information, launch denial-of-service attacks, create an FTP server and more. It registers itself as the service called “Networksvc”. (Sophos)

W32/Mytob-JM — A new Mytob variant that spreads via a message that looks like an account warning. It usually comes as an attachment with a double extension. It installs itself as “Lien Van de Kelder.exe” in the Windows System folder and can limit access to security related Web sites by modifying the Windows HOSTS file. (Sophos)