Cisco releases three updates

Opinion
Nov 3, 20056 mins

* Patches from Cisco, Gentoo, Debian, others * Beware Mitglieder.FK, a new Trojan that seems to spreading quickly around Spain and the U.S. * Vulnerable security algorithms raise concerns

Today’s bug patches and security alerts:

Cisco releases three updates:

IOS heap-based overflow vulnerability in system timers

According to the Cisco advisory, “The Cisco Internetwork Operating System (IOS) may permit arbitrary code execution after exploitation of a heap-based buffer overflow vulnerability. Cisco has included additional integrity checks in its software, as further described below, that are intended to reduce the likelihood of arbitrary code execution.” For more, go to:

http://www.networkworld.com/go2/1031bug2a.html

Cisco Airespace WLAN controllers allow unencrypted network access

According to a Cisco advisory, “Cisco Access Points operating in Lightweight Access Point Protocol (LWAPP) mode may allow unauthenticated end hosts to send unencrypted traffic to a secure network by sending frames from the Media Access Control (MAC) address of an already authenticated end host. Only the access points that are operating in LWAPP (i.e., controlled by a separate Wireless LAN Controller) mode are affected. Access points that are running in autonomous mode are not affected.” For more, go to:

https://www.cisco.com/warp/public/707/cisco-sa-20051102-lwapp.shtml

Cisco IPS MC malformed configuration download vulnerability

According to the Cisco advisory, “An issue exists in one of the components of the Cisco Management Center for IPS Sensors (IPS MC) v2.1 during the generation of the Cisco IOS IPS (Intrusion Prevention System) configuration file that may result in some signatures belonging to certain classes being disabled during the configuration deployment process.” For more, go to:

https://www.cisco.com/warp/public/707/cisco-sa-20051101-ipsmc.shtml

**********

New Apple update fixes Mac OS X flaws

A new update patch from Apple repairs multiple flaws in Mac OS X 10.4.3. The affected applications and system tools include Finder, Software Update, memberd, Keychain and the Kernel. The most serious of the flaws could allow a user to gain elevated privileges on the affected machine. For more, go to:

https://docs.info.apple.com/article.html?artnum=302763

**********

Gentoo, Mandriva patch Ethereal

A number of flaws have been found in the Ethereal network monitoring tool. The most serious of the vulnerabilities could be exploited to run malicious applications on the affected machine. For more, go to:

Gentoo:

https://security.gentoo.org/glsa/glsa-200510-25.xml

Mandriva:

http://www.networkworld.com/go2/1031bug2b.html

**********

Ubuntu releases fix for libgda2

Two format strings in libgda2, the GNOME Data Access library for GNOME2, could be exploited to run malicious code on the affected machine. For more, go to:

http://www.networkworld.com/go2/1031bug2c.html

Ubuntu patches sudo

A flaw in the way sudo cleans up its environment variables could be exploited by an attacker to run arbitrary commands on the affected machine with elevated privileges. For more, go to:

http://www.networkworld.com/go2/1031bug2d.html

**********

Debian, Mandriva, Ubuntu release Lynx fix

A buffer overflow in the Lynx news reader could be exploited to redirect users to malicious Web sites. For more, go to:

Debian:

https://www.debian.org/security/2005/dsa-874

Mandriva:

http://www.networkworld.com/go2/1031bug2e.html

Ubuntu:

http://www.networkworld.com/go2/1031bug2f.html

**********

Today’s roundup of virus alerts:

Mitglieder.FK — A new Trojan that seems to spreading quickly around Spain and the U.S. The virus spreads through e-mail with a blank subject line and a .ZIP attachment, which contains the infected .EXE file. (Panda Software)

W32/Agobot-ADS — An Agobot variant that spreads through weakly protected network shares. It installs itself as “standalone.exe” in the Windows System folder and can be used for a number of malicious applications including as a SOCKS proxy, e-mail harvester, DDoS zombie, and keylogger. (Sophos)

Troj/Dloader-XF — A downloader Trojan that is designed to grab additional code from remote sites. It drops “q4.pak” and “prc.exe” in the Windows System folder. (Sophos)

W32/Sdbot-ZM — A new Sdbot variant that installs “nawdll32.exe” in the Windows System folder. It allows backdoor access via IRC and can be used to scan for other hosts, start an FTP server and download additional code. (Sophos)

Troj/Inor-V — This is an HTML script Trojan that drops “fiks.exe” on the infected machine. (Sophos)

W32/Rbot-ATT — A new Rbot variant that targets machines with weakly protected network shares or that are already infected with out types of viruses. It drops “init.exe” in the Windows System folder and allows remote access via IRC. (Sophos)

W32/Rbot-ATQ — Another Rbot Trojan that runs in the background, allowing access to the infected host via IRC. It is installed as “cmss.exe” in the Windows System directory. (Sophos)

W32/Rbot-AUF — This Rbot variant uses “msconfig32.exe” in the Windows System directory as its infection point. It too allows backdoor access via IRC. (Sophos)

W32/Rbot-AUL — Our fourth similar Rbot variant of the day infects the host with “msnwindows.exe” in the Windows System folder and allows access through IRC. (Sophos)

Troj/Banker-GD — A Trojan that targets data (particularly username and password) entered into certain Brazilian banking sites. It is installed as “wscntfy.exe” in the Windows System folder. (Sophos)

W32/Randex-Y — Another backdoor Trojan that spreads through network shares and allows backdoor access via IRC. It drops “msnv32.exe” in the Windows System folder of the infected machine. (Sophos)

Troj/Squado-A — A downloader that tries to gather additional malicious code from remote sites. It installs “MS Office.hta” in one of the Windows startup folders. (Sophos)

Troj/Agent-EU  — A Trojan that can be used to steal files and participate in DDoS attacks against third parties. It drops “system.exe”, “libHide.dll”, “systemup.exe” and “vbstub.exe” on the infected host. (Sophos)

Troj/Dagonit-A — This Trojan provides backdoor access through a randomly opened TCP port. It installs a number of files in the current folder, including “dalia2.exe”. (Sophos)

**********

From the interesting reading department:

Vulnerable security algorithms raise concerns

Industry experts agree that the future of two widely used security algorithms is fated, but with no clear alternatives in sight products that rely on them may have to remain “good enough” for some time. NetworkWorld.com, 11/01/05.

http://www.networkworld.com/news/2005/110105-nist-crypto.html