* Patches from HP, SuSE, Trustix, others * Beware latest Mytob variants
Today’s bug patches and security alerts:
HP releases critical Oracle for OpenView patch
According to an alert from HP, “Oracle has issued a Critical Patch Update which contains solutions for a number of potential security vulnerabilities. These vulnerabilities may be exploited locally or remotely to compromise the confidentiality, availability or integrity of Oracle for OpenView (OfO).” For more, go to:
http://www.networkworld.com/go2/1031bug1a.html
**********
SuSE releases patch for permissions
A flaw in the three predefined “permissions” that ship with SuSE Linux could be exploited by an attacker to modify files on the affected machine without the proper authentication. (Sophos)
http://www.networkworld.com/go2/1031bug1b.html
**********
Trustix releases new “multi” update
A new update from Trustix covers flaws in apache, lynx, mod_php4, openssl, php4, php, squid, texinfo and wget. The most serious of the flaws could be exploited to run malicious code on the affected system. For more, go to:
https://www.trustix.org/errata/2005/0059/
**********
Debian patches libgda2
Two format strings in libgda2, the GNOME Data Access library for GNOME2, could be exploited to run malicious code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-871
**********
Gentoo patches cURL
A buffer overflow in cURL, a command line tool for Linux, could be exploited to run malicious applications on an affected system. For more, go to:
https://security.gentoo.org/glsa/glsa-200510-19.xml
Gentoo releases update for Zope
According to a Gentoo advisory, “Zope is vulnerable to a file inclusion vulnerability when exposing RestructuredText functionalities to untrusted users.” For more, go to:
https://security.gentoo.org/glsa/glsa-200510-20.xml
Gentoo issues fix for phpMyAdmin
A local file inclusion vulnerability in phpMyAdmin could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200510-16.xml
**********
Debian, Mandrake Linux release patches for netpbm
A buffer overflow in one of netpbm’s conversion tools could be exploited to run malicious code on the affected machine. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-878
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:199
**********
Debian, Mandriva issue fixes for sudo
A flaw in the way sudo cleans up its environment variables could be exploited by an attacker to run arbitrary commands on the affected machine with elevated privileges. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-870
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:201
**********
Today’s roundup of virus alerts:
W32/Mytob-FC — This new Mytob variant spreads e-mail and provides backdoor access via IRC. It spreads through message that looks like an account or password warning and usually has a double-extension attachment that ends in “.zip”. It drops “wID32.exe” in the Windows System folder. (Sophos)
W32/Mytob-BZ — Another Mytob mass mailing worm. This variant drops “taskgmr.exe” in the Windows System folder and can limit access to certain security Web sites by modifying the Windows HOSTS file. (Sophos)
Troj/Hanlo-B — A backdoor worm that communicates with remote servers via HTTP. It drops a number of .exe files on the infected machine including “tBmp107.exe” through “tBmp707.exe”. (Sophos)
W32/Rbot-ATC — An Rbot variant that exploits weak passwords and multiple Windows vulnerabilities as it spreads through network shares. It drops “MSAOL32dll.exe” in the Windows System folder and allows backdoor access via IRC. (Sophos)
W32/Rbot-APU — Another Rbot variant that exploits known Windows flaws and machines infected with the Sasser worm as it spreads through network shares. This variant drops “WinSGR32.exe” in the Windows System directory. (Sophos)
W32/Rbot-ATE — The third Rbot variant today drops “hhs32.pif” in the Windows System folder. It too can be used to provide backdoor access to the infected machine through IRC. (Sophos)
W32/Rbot-ATL — Our foutrh Rbot variant of the day acts similar to the previous three. This one drops “msnq3insller.exe” in the Windows System directory. (Sophos)
Troj/Midrug-B — A basic Trojan that can be used to access remote sites via HTTP. No word on what files it drops or exactly how it spreads. (Sophos)
W32/Brontok-D — A mass mailing worm that uses mostly non-English phrases for subject lines and an attachment called “Kangen.exe”. It drops “eksplorasi.exe” in the Windows folder. No word of any permanent damage caused by this virus. (Sophos)
W32/Tilebot-P — A new IRC backdoor worm that spreads through network shares by exploiting a couple of well-known Windows flaws. It copies itself to “msconfig32.exe” in the root directory. (Sophos)
W32/Loosky-A — An e-mail worm that spreads through a message entitled “Skylook for Skype” with an attachment called “skylook_1.exe”. Looks like all this does is harvest e-mail addresses. (Sophos)
W32/Lerma-A — A worm that spreads via network shares and could overwrite a number of popular file types. It drops “Ermasys32.exe” and other files in the Windows and Windows System folders. (Sophos)
Troj/Keylog-AP — A keylogging Trojan that installs itself as “wcsys.exe” in the Windows System folder. It writes its bounty to “wcsys32.dll” and mails the data to the e-mail author when the file gets bigger than 4KB. (Sophos)
W32/Agobot-TW — This new Agobot variant spreads through network shares by exploiting a number of known Windows vulnerabilities. It drops “msn5.exe” in the Windows System folder and registers as “Video Process”. It provides backdoor access via IRC, allowing intruders to take control of the infected system. (Sophos)
W32/Chode-J — A worm that spreads via instant messages using a link to the infected file. It can be used for distributed denial-of-service attacks, as a proxy, and to download/install new code. It is installed as “csrss.exe” in the Windows System folder. (Sophos)




