RealNetworks patches RealPlayer 10

Opinion
Nov 14, 20056 mins

* Patches from RealNetworks, Mandriva, Debian, others * Beware second Stinx variant

Today’s bug patches and security alerts:

RealNetworks patches RealPlayer 10

RealNetworks has released a new update for its RealPlayer media client that fixes a number of vulnerabilities found in previous releases. The most serious of the flaws could be exploited by an attacker to run arbitrary code. For more, go to:

https://service.real.com/help/faq/security/051110_player/EN/

Related EEye advisories:

https://www.eeye.com/html/research/advisories/AD20051110b.html

https://www.eeye.com/html/research/advisories/AD20051110a.html

**********

Linux vendors have released a bushel of security updates out. We bring the list with abbreviated descriptions:

Mandriva:

apache-mod_auth_shadow (unauthorized access):

http://www.networkworld.com/go2/1114bug1q.html

squirrelmail (preference modification):

http://www.networkworld.com/go2/1114bug1p.html

gda2.0 (format string, code execution):

http://www.networkworld.com/go2/1114bug1o.html

wget (race condition, file overwrite):

http://www.networkworld.com/go2/1114bug1n.html

clamav (multiple flaws):

http://www.networkworld.com/go2/1114bug1m.html

openvpn (code execution):

http://www.networkworld.com/go2/1114bug1l.html

libungif (multiple flaws):

http://www.networkworld.com/go2/1114bug1k.html

emacs (code execution):

http://www.networkworld.com/go2/1114bug1j.html

fetchmail (permission flaws):

http://www.networkworld.com/go2/1114bug1i.html

w3c-libwww (denial of service):

http://www.networkworld.com/go2/1114bug1h.html

**********

Ubuntu:

zip (multiple flaws):

http://www.networkworld.com/go2/1114bug1g.html

rpm (multiple flaws):

http://www.networkworld.com/go2/1114bug1f.html

libungif4 (buffer overflows):

http://www.networkworld.com/go2/1114bug1e.html

fetchmail (permission flaws):

http://www.networkworld.com/go2/1114bug1d.html

**********

Debian:

awstats (perl code execution):

https://www.debian.org/security/2005/dsa-892

kdelibs (previous patch flawed):

https://www.debian.org/security/2005/dsa-804

**********

SuSE:

pwdutils, shadow (privilege escalation):

http://www.networkworld.com/go2/1114bug1c.html

**********

OpenPKG:

openvpn (DoS, code execution):

https://www.openpkg.org/security/OpenPKG-SA-2005.023-openvpn.txt

**********

Fedora:

httpd and mod_ssl (multiple flaws):

http://www.networkworld.com/go2/1114bug1b.html

**********

HP updates:

HP-UX envd Local Execution of Privileged Code

HP-UX Trusted Mode remshd Remote Unauthorized Access

HP OpenVMS Local Denial of Service

All three updates can be downloaded by logging into the HP ITRC site:

http://www.itrc.hp.com

**********

Today’s roundup of virus alerts:

Sony Stops Shipping Controversial DRM Code

One day after hackers released malicious software that used controversial Sony copy-protection software to attack computers, Sony has decided to stop shipping the product, the company said today. IDG News Service, 11/11/05.

http://www.pcworld.com/news/article/0,aid,123511,00.asp

Related virus – Ryknos.A:

http://www.networkworld.com/go2/1114bug1a.html

Troj/Stinx-E — A backdoor worm that connects to a number of predefined IP addresses and remains connected. It drops “$sys$drv.exe” in the Windows System folder. It’s a virus that may try to exploit the Sony DRM system that comes with certain audio CDs.

Troj/Stinx-E — A second Stinx variant that tries to exploit the Sony DRM system. This one drops “$sys$xp.exe” in the Windows System folder. (Sophos)

W32/Rbot-AJO — An Rbot variant that exploits a number of known Windows vulnerabilities as it spreads through network shares. It drops a randomly named file in the Windows System directory and allows backdoor access through IRC. (Sophos)

W32/Rbot-AWM — Another Rbot variant. This one too exploits Windows flaws and can allow backdoor access via IRC. It drops “VGATune.exe” in the Windows System folder. (Sophos)

W32/Ixbot-D — Another backdoor worm that allows entry through IRC. This worm installs “wqxfne.exe” in the Windows System folder after spreading through a network share. (Sophos)

W32/Bagle-AR — A new mass mailing worm that spreads through a message with an infected .zip attachment. It installs “re_file.exe” in the Windows System folder and attempts to disable certain security related applications. (Sophos)

Troj/Haxdoor-AO — A stealth worm that installs itself as “cpudev.sys” in the Windows System directory. The virus can delete files on the infected machine. (Sophos)

W32/Loosky-B — A multi-part worm that spreads via e-mail. In drops a number of files on the infected machine, including “sachostx.exe” in the Windows folder. The virus attempts to bypass the Internet Firewall, install a proxy and a backdoor. The message looks like it’s an ad for a Skype tool. The infected attachment is called “skylook_1.exe”. (Sophos)

W32/Nelo-A — A virus that tries to copy itself to the root of any disk. It installs itself as “Systrsy.exe” in the Internet Explorer folder. According to Sophos, Nelo-A may open and close the CD drive. (Sophos)

Troj/Ranck-DF — A Trojan that acts as an HTTP proxy server. It uses a randomly name file to infect the host. (Sophos)

Troj/Dadobra-I — A downloader Trojan that tries to gather more malicious code from remote sites. It installs itself as “servicos..exe” in the Windows System directory. (Sophos)

Troj/Shredl-B — Another downloader Trojan. This one installs “ixplorer.exe” in the Windows System folder. (Sophos)

W32/Mytob-FI — A new Mytob variant that spreads through network shares and e-mail. The infected message looks like an account warning from a system administrator type. It drops “expI0rer.exe” in the Windows System folder. It limits access to security related sites by modifying the Windows HOSTS file. (Sophos)

W32/Mytob-FK — A second new Mytob variant. This one is similar except it drops “wID32.exe” in the Windows System folder. (Sophos)

W32/Tilebot-AY — A network Trojan that exploits a number of known Windows flaws. It drops “cytob.exe” in the Windows folder and can be used to steal passwords among other malicious tasks. (Sophos)

W32/Sdbot-XH — This Windows worm spreads through network shares, dropping “windesktop.exe” in the Windows System folder and allowing backdoor access via IRC. The virus modifies the Windows HOSTS file to limit access to certain Web sites. (Sophos)

W32/Stando-E — A worm that drops “mgrShell.exe” and “scApp.exe” in the Windows System folder. The worm may try to append data to DOC files. (Sophos)

W32/Appflet-B — This e-mail worm spreads through a message titled “Axaye Sexy Dokhtaraye Iran Zamin!”. It displays a fake error message and drops two randomly named files (an exe and sys) in the Windows System folder. (Sophos)

Troj/ZDown-A — A simple downloader Trojan that tries to stop security related processes running on the infected host. (Sophos)

Troj/Feutel-AD — This backdoor worm installs itself as “G_Server2.0.exe” in the Windows System folder. It also injects itself into other programs to help avoid detection. (Sophos)

Troj/Bancban-HX — A Trojan that tries to steal data entered into banking Web sites. It installs a number of files on the infected host, including “imgrt.txt” in the Windows System folder. (Sophos)

W32/Francette-W — A worm that provides backdoor access to the infected machine via IRC. It is installed as a randomly named file. An attacker could use the infected host as a redirect for phishing sites. (Sophos)

Troj/Clagger-A — A Trojan that communicates with remote sites through HTTP and attempts to disable the Windows firewall. (Sophos)

W32/Badgrad-B — A worm that drops “badgers_s.exe” on the infected machine but seems harmless. (Sophos)