* Patches from Microsoft, Apple, Debian, others * Beware Rbot variants that exploit Windows flaws * Botnets getting nastier, and other interesting reading
Today’s bug patches and security alerts:
Single Windows security patch coming
Microsoft will release a single patch addressing a critical flaw in its Windows operating system this week. The update will be issued as part of the software company’s monthly security update. IDG News Service, 11/04/05.
http://www.networkworld.com/news/2005/110405-windows-patch.html?nl
**********
Apple releases QuickTime security fix
A new version of QuickTime (7.0.3) is available and fixes four flaws found in previous releases. The most serious of the flaws could be exploited to overwrite application data. The new update can be downloaded from the main QuickTime site:
https://www.apple.com/quicktime/
Security advisory:
https://docs.info.apple.com/article.html?artnum=302772
**********
Macromedia reports critical flaw in FlashPlayer 7
A flaw in the Flash.ocx component that processed SWF files could be exploited by a Web site owner to run malicious code on visitor’s machines. Users should update to FlashPlayer 8 to fix the flaw. For more, go to:
http://www.networkworld.com/go2/1107bug1a.html
**********
Hidden accounts on Sony Vaio laptops?
A post on the Bugtraq mailing lists claims there could be hidden user accounts on Sony Vaio laptops. According to the post: Sony Vaio laptops require you to create a user account the first time you start your laptop. If the user you select is not “Administrator”, Sony still goes ahead and creates a user “Administrator” with a blank password. This user does not show up in control panel under User Accounts but if you do start up in safemode the laptop allows you to login as Administrator. This gives an attacker an opportunity to gain administrative access to a computer and access to create add delete or modify user accounts.
No word from Sony confirming the issue.
**********
Debian patches net-snmp
A denial-of-service vulnerability has been found in Debian’s implementation of net-snmp. A fix is available. For more, go to:
https://www.debian.org/security/2005/dsa-873
**********
Mandriva patches uim
According to an alert from Mandriva, “Masanari Yamamoto discovered that Uim uses environment variables incorrectly. This bug causes a privilege escalation if setuid/setgid applications are linked to libuim.” For more, go to:
http://www.networkworld.com/go2/1107bug1b.html
Mandriva releases fix for squid
A flaw in Squid could be exploited by a remote FTP server to cause a denial-of-service attack. For more, go to:
http://www.networkworld.com/go2/1107bug1c.html
Mandriva patches unzip
Unzip does not properly set permission on certain files, which could be exploited by a local user to gain elevated privileges on the affected machine. For more, go to:
http://www.networkworld.com/go2/1107bug1d.html
Mandriva releases patch for php-imap
A buffer overflow in the php-imap server could be exploited to run malicious code on the affected machine. For more, go to:
http://www.networkworld.com/go2/1107bug1e.html
Mandriva issues fix for perl-Compress-Zlib
The perl-Compress-Zlib contains a flawed version of zlib. An update is available. For more, go to:
http://www.networkworld.com/go2/1107bug1f.html
**********
Today’s roundup of virus alerts:
Troj/Bancban-HA — An Internet banking Trojan that installs itself as “wupdmgr.exe” in the Windows folder. It communicates with a remote site via HTTP. (Sophos)
W32/Rbot-AUQ — A new Rbot variant that exploits a number of known Windows flaws as it spreads through network shares. It allows backdoor access via IRC. It drops “winsv.exe” in the Windows System folder. (Sophos)
W32/Rbot-ATE — Another new Rbot variant that exploits Windows flaws, dropping “hhs32.pif” in the Windows System folder. (Sophos)
W32/Rbot-AST — Our third Rbot variant is similar to the previous two, though this one drops “wininit32.exe” in the Windows System folder. (Sophos)
W32/Rbot-AWB — A fourth Rbot variant of the day can also allow backdoor access via IRC. This variant drops “msniu.exe” in the Windows System folder. (Sophos)
W32/Agobot-ADS — A backdoor worm that allows access through IRC. It infects machines through weakly protected network shares, dropping “standalone.exe” in the Windows System folder. In addition to being used for such malicious purposes as stealing local data and participating in DDoS attacks, it also modifies the Windows HOSTS file to prevent access to security related Web sites. (Sophos)
W32/Poebot-P — A worm that installs itself as “iexplore.exe” in the Windows System folder. It exploits weakly protected network shares and a number of known Windows flaws. No word on what kind of permanent damage it may cause. (Sophos)
W32/Mytob-FF — Another Mytob e-mail worm that spreads through a message that looks like it comes from an account or tech support rep. The infected attachment is usually a zip file and “pipe.exe” is dropped in the Windows System folder. It modifies the Windows hosts file to prevent access to certain web sites. (Sophos)
W32/Mytob-FH — A second Mytob variant that acts similar to Mytob-FF above. This variant drops “namedpipe.exe” in the Windows System folder. (Sophos)
Troj/ParDrop-A — A Windows worm that drops “inetinfo.exe” in the Windows System folder. It seems to allow some sort of access to the infected machine or can be used to download additional code. No other details are available. (Sophos)
Troj/Paymite-C — This Windows Trojan changes a number of Internet Explorer settings. It installs “paytime.exe” in the Windows System folder. (Sophos)
Troj/BagleDl-W — A Bagle variant that tries to download additional malicious code from a number of remote sites. It installs “hloader_exe.exe” in the Windows System folder. (Sophos)
Troj/Goldun-AK — This Trojan drops “mside.dll” on the infected machine and can be used to steal information entered into Web sites, particularly usernames and passwords. (Sophos)
W32/Oscabot-N — A worm that tries to send links via AOL Instant Messenger. No word on what happens if a user clicks the link. (Sophos)
**********
From the interesting reading department:
Botnets getting nastier
Software robots – bots – that invade computers so an attacker can covertly control them have existed for at least two decades. Today, however, their proliferation, sophistication and criminal use are making them a top public enemy. Network World, 11/07/05.
http://www.networkworld.com/news/2005/110705-botnets.html?nl
Los Angeles division of FBI makes botnet-related arrest
The Los Angeles division of the FBI Thursday arrested a 20-year-old man on charges that he illegally made thousands of dollars by setting up a botnet of compromised computers to sell them for hacking and spam purposes. Network World, 11/04/05.
http://www.networkworld.com/news/2005/110405-botnet-arrest.html?nl
Microsoft hails security focus in Web services package
Microsoft Monday is planning to release an upgrade to its free Web Services Enhancements (WSE) package for Windows developers, focusing on security. InfoWorld, 11/03/05.
http://www.networkworld.com/news/2005/110305-microsoft-wse.html?nl




