* Patches from Gentoo, SuSE, Debian, others * Beware Google-spoofing worm
endif; ?>Today’s bug patches and security alerts:
Multiple vulnerabilities in Linksys router firmware
Versions of 3.03.6 and 3.01.03 of the Linksys WRT54G wireless router contain several vulnerabilities that could be exploited by an attacker to take control of the HTTP Web management interface. Version 4.20.7 is said to fix the issue. The update can be downloaded here:
http://www.networkworld.com/go2/0919bug1j.html
Related advisories from iDefense:
Linksys WRT54G Router Remote Administration apply.cgi Buffer Overflow Vulnerability
http://www.networkworld.com/go2/0919bug1i.html
Linksys WRT54G ‘upgrade.cgi’ Firmware Upload Design Error Vulnerability
http://www.networkworld.com/go2/0919bug1h.html
Linksys WRT54G Management Interface DoS Vulnerability
http://www.networkworld.com/go2/0919bug1g.html
Linksys WRT54G ‘restore.cgi’ Configuration Modification Design Error Vulnerability
http://www.networkworld.com/go2/0919bug1f.html
Linksys WRT54G Router Remote Administration Fixed Encryption Key Vulnerability
http://www.networkworld.com/go2/0919bug1e.html
**********
Sun reports flaw in Java Application Server
A flaw in the Sun Java Application Server could be exploited by a remote user to view the contents of JAR files, which could be exploited in future attacks. A fix is available:
https://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1
**********
Gentoo patches Net-SNMP
Gentoo’s implementation of Net-SNMP contains an non-secure DT_RPATH module, which could be exploited to gain elevated privileges. For more, go to:
https://security.gentoo.org/glsa/glsa-200509-05.xml
Gentoo issues fix for phpLDAPadmin
According to an alert from Gentoo, “A flaw in phpLDAPadmin may allow attackers to bypass security restrictions and connect anonymously.” For more, go to:
https://security.gentoo.org/glsa/glsa-200509-04.xml
Gentoo releases patch for OpenTTD
A format string flaw in OpenTTD could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200509-03.xml
Gentoo updates Python
The Python scripting language is vulnerable to a heap overflow in the PCRE code library, which could be exploited to run malicious commands on the affected machine. For more, go to:
https://www.gentoo.org/security/en/glsa/glsa-200509-08.xml
Gentoo updates X.Org
A heap overflow X.Org could be exploited to run malicious code and gain elevated privileges on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200509-07.xml
**********
SuSE patches php4,php5
Multiple flaws have been found in Versions 4 and 5 of the popular PHP scripting language. The most serious of the flaws could be exploited to run malicious code on the affected machine. For more, go to:
https://www.novell.com/linux/security/advisories/2005_51_php.html
**********
Debian, OpenPKG, Ubuntu patches modssl
An “information disclosure” vulnerability has been found in modssl. Debian, OpenPKG and Ubuntu have released a fix for the problem:
Debian:
https://www.debian.org/security/2005/dsa-807
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2005.017-modssl.html
Ubuntu:
http://www.networkworld.com/go2/0919bug1d.html
**********
Mandriva releases patch for smb4k
A flaw in the way certain temporary files are created by Mandriva’s implementation of smb4k could be exploited in a symlink attack to access other files. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:157
**********
Ubuntu releases kernel update
A new kernel update from Ubuntu fixes a number of flaws found in previous releases. The flaws could be exploited in a denial-of-service attack or to run arbitrary code. For more, go to:
http://www.networkworld.com/go2/0919bug1c.html
Ubuntu patches lesstif1
A previous update for lesstif did not fix all the original problems. For more, go to:
http://www.networkworld.com/go2/0919bug1b.html
**********
Debian patches tdiary
According to a Debian alert, “The tdiary Development Team has discovered a Cross-Site Request Forgery (CSRF) vulnerability in tdiary, a new generation Weblog that can be exploited by remote attackers to alter the users information.” For more, go to:
https://www.debian.org/security/2005/dsa-808
**********
Debian, Ubuntu release Mozilla updates
Several vulnerabilities have been found in the Mozilla browser code, which could be exploited to run arbitrary code on the affected machine. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-810
Ubuntu:
http://www.networkworld.com/go2/0919bug1a.html
**********
Today’s roundup of virus alerts:
Security vendor warns of Google-spoofing worm
Downloaders looking for a free “Star Wars” game may instead find themselves installing a new worm that gives them dodgy Google search results. The worm, called P2Load.A, is being spread on peer-to-peer programs like Shareaza and Imesh, masquerading as a free version of the Lucasfilm game “Knights of the Old Republic II,” said Forrest Clark, senior manager of consumer product marketing with anti-virus vendor Panda Software. IDG News Service, 09/16/05.
http://www.networkworld.com/news/2005/091605-google-worm.html?nl
W32/Forbot-FO — A backdoor worm that spreads via an e-mail attachment in a message that looks like an account warning. The attachment will have a .zip extension and install “svchosts.exe” in the Windows System directory. (Sophos)
W32/Rbot-ANQ — An Rbot variant that spreads via network shares, dropping “ms-dos.pif” on the infected machine. It exploits several Windows flaws in its attempt to infect the machine. Backdoor access is allowed through IRC. (Sophos)
Troj/Dremn-B — A keylogging Trojan that tries to capture username and password information. It drops “syspol.exe” in the Windows System folder. (Sophos)
W32/Agobot-PI — An Agobot variant that spreads through network shares and allows backdoor access via IRC. It drops “Ksrv32.exe” in the Windows System folder. It can be used for a number of malicious applications, disables security related applications and limits access to security Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Sdbot-ADC — An Sdbot variant that exploits a number of known Windows flaws as it spreads through network shares. It drops “msconfig32.exe” in the Windows System directory and provides backdoor access via IRC. (Sophos)
W32/Sdbot-ADE — Another Sdbot variant that allows backdoor access via IRC. It drops “iexplore.exe” in the Windows System folder. (Sophos)
W32/Mytob-EJ — A new Mytob variant that spreads through an e-mail message that usually looks like an account warning. The infected attachment will have a double extension and “servce.exe” is dropped in the Windows System folder. (Sophos)
Troj/Clicker-Y — A Trojan that tries to open a remote Web site. It drops “efsdfgxg.exe” in the Windows system folder. (Sophos)
W32/Tirbot-D — A backdoor Trojan that exploits the Windows LSASS vulnerability. It drops “MSDTCs.exe” in the Windows system folder and allows the infected machine to be used for a number of malicious purposes. (Sophos)
Troj/Kagen-A — A virus that displays a Word document with a message written in Indonesian. It installs itself as “ccApps.exe” in the Windows system directory. (Sophos)




