Solaris Management Console password vulnerability

Opinion
Jan 17, 20058 mins

* Patches from Debian, Trustix, Conectiva, more * Beware new worm posing as tsunami aid appeal * Experts warn of trick to bypass IE download warnings, and other interesting reading

Today’s bug patches and security alerts:

Solaris Management Console password vulnerability

Sun is warning of a flaw in the way its Solaris Management Console (SMC) handles “aging” passwords. SMC can be configured to prompt users to change their password after X number of days. A bug in the way this is handled could allow account access without the need for any password. For more, go to:

https://sunsolve.sun.com/search/document.do?assetkey=1-26-57717-1

**********

Flaws found in NetGear ProSafe VPN Firewall switch

SecuriNews is reporting two vulnerabilities in the NetGear ProSafe VPN Firewall 8 switch (FVS318). Attackers could bypass URL filters by using HEX characters in the URL. Also, the event log could contain URLs with JavaScript in them. This script would be executed in the administrator’s browser. Currently, there is no workaround or patch. For more, go to:

https://www.securinews.com/vuln.htm?vulnid=103

**********

Gentoo, Mandrake Linux update CUPS

Multiple vulnerabilities have been discovered in CUPS (Common UNIX Printing System), some of which could be exploited to run arbitrary code on the affected machine. Patches are available:

Gentoo:

https://www.gentoo.org/security/en/glsa/glsa-200412-25.xml

Mandrake Linux:

https://www.nwfusion.com/go2/0117bug1a.html

**********

Conectiva, SuSE updates php4

Conectiva and SuSE have released a major update for their implementation of the PHP scripting language. The updates fix a total of 11 security vulnerabilities. For more, go to:

Conectiva:

https://www.nwfusion.com/go2/0117bug1b.html

SuSE:

https://www.nwfusion.com/go2/0117bug1c.html

**********

Debian releases gopher patch

Two undisclosed flaws have been found in Debian’s Gopher server implementation. A patch is available. For more, go to:

https://www.debian.org/security/2005/dsa-638

Debian patches exim-tls

A buffer overflow in exim-tls’s host_aton function could be exploited to run any code on the affected machine via an “illegal IPv6 address,” according to Debian. Exim is mail transport agent. For more, go to:

https://www.debian.org/security/2005/dsa-637

Debian patches mc

A number of vulnerabilities in midnight commander (mc) have been patched by Debian in this update. Many could exploited in a denial-of-service attack against the affected server. For more, go to:

https://www.debian.org/security/2005/dsa-639

**********

Trustix patches kernel, fcron

A “multi” patch fixes vulnerabilities in the Trustix kernel and fcron. Certain kernel implementation contain a page fault handling flaw and several vulnerabilities were found in the fcron configuration tool. For more, go to:

https://www.trustix.org/errata/2005/0001/

**********

Conectiva releases Ethereal update

A new update for Conectiva’s Ethereal implementation fixes seven flaws in the popular network monitoring software. Most could be used to in a denial-of-service attack, though a few could be exploited to run any code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0117bug1d.html

Conectiva patches krb5 buffer overflow

A heap overflow in Kerberos 5’s (krb5) password history handling could be exploited to run arbitrary code on the affected machine. A fix is available. For more, go to:

https://www.nwfusion.com/go2/0117bug1e.html

Conectiva issues TikiWiki patch

A flaw in TikiWiki, a Web-based groupware/content management system, could be exploited by users to upload and run PHP scripts on the affected server. For more, go to:

https://www.nwfusion.com/go2/0117bug1f.html

**********

Mandrake Linux fixes HylaFAX

A bug in the code HylaFAX, a software package for sending and receiving faxes, uses for validating usernames could be exploited to bypass the authentication altogether. For more, go to:

https://www.nwfusion.com/go2/0117bug1g.html

Mandrake Linux patches imlib

A number of overflow vulnerabilities have been found in imlib, an image handling code library. An attacker could use a specially-crafted image file to run arbitrary code via any application that is linked to imlib. For more, go to:

https://www.nwfusion.com/go2/0117bug1h.html

Mandrake Linux issues nfs-utils

A buffer overflow in nfs-utils could allow ” An attacker with access to an NFS share could send a specially crafted request which could then lead to the execution of arbitrary code,” according to Mandrake Linux. For more, go to:

https://www.nwfusion.com/go2/0117bug1i.html

**********

Today’s roundup of virus alerts:

New worm poses as tsunami aid appeal

The worm carries the subject line “Tsunami Donation! Please help!” and the text message “Please help us with your donation and view the attachment below! We need you!” The attachment, labeled “tsunami.exe,” spreads the virus to other Internet users, according to security firm Sophos PLC. IDG News Service, 01/17/05.

https://www.nwfusion.com/news/2005/0117newworm.html?nl

W32/Wurmark-E – A mass-mailing virus that drops a Trojan horse on the infected machine, allowing backdoor access via IRC. It spreads via an attachment with a .scr extension. (Sophos)

W32/Sdbot-TG – This backdoor Trojan drops the file “TELLME.EXE” on the infected machine and installs “CCAPPMS.EXE” in the Windows System folder. Access to the infected machine can be gained through IRC. (Sophos)

W32/Sdbot-TJ -Very similar to Sdbot-TG above, except this variant drops “cqcags.exe” in the Windows System folder. (Sophos)

W32/Baba-B – A mass-mailing worm that looks like a message delivery failure notification. The attached file will have the name “message txt length bytes mcafee.com” and will drop CSRSS.EXE and CSRSS.BIN in the C root directory. (Sophos)

W32/Myfip-F – This worm spreads via network shares, installing “kernel32dll.exe” in the Windows System directory. It can be used to steal the content of specific system files. (Sophos)

W32/Rbot-AGZ – An Rbot variant that spreads via network shares by exploiting a number of known Windows vulnerabilities. This variant drops “Flashget.exe” in the Windows System directory and can turn the infected machine into a zombie. (Sophos)

W32/Rbot-TL – Very similar to Rbot-AGZ above, except it uses the file “win32.exe” and can terminate security-related applications running on the infected machine. (Sophos)

W32/Rbot-TP – Another copycat Rbot variant. This one installs “svcdll.exe” in the Windows System folder. (Sophos)

W32/Rbot-TQ – This Rbot variant drops “msexcel.exe” in the Windows System folder and can be used as a key logger. (Sophos)

W32/MyDoom-AA – A new MyDoom mass mailing variant that installs itself as “lsasrv.exe” in the infected machine’s Windows System folder. It spreads via an attachment with a exe, scr, pif, cmd, bat or zip extension. (Sophos)

W32/Forbot-DM – Spreads via network shares by exploiting the Windows LSASS vulnerability. It drops “cipsn.exe” in the Windows System folder and can provide backdoor access via IRC. (Sophos)

**********

From the interesting reading department:

Technology Insider: Patch management

The good news is there are scores of automated patch management product available. The bad news is it’s not easy to pick one that’s right for your network. In this Technology Insider, we’ll describe how leading-edge users are solving their patch woes. Network World, 01/17/05.

https://www.nwfusion.com/techinsider/2005/0117patch.html?nl

Experts warn of trick to bypass IE download warnings

A computer security researcher and an anti-virus company are warning Microsoft customers about an unpatched hole in the company’s Internet Explorer Web browser that could allow a remote attacker to bypass security warnings and download malicious content onto vulnerable systems. IDG News Service, 01/14/05.

https://www.nwfusion.com/news/2005/0114experwarn.html?nl

IPS gets bigger role in spyware defense

Users looking to get a handle on the spyware scourge are getting help from traditional intrusion-prevention system vendors that are starting to add features that block spyware, worms and other security threats. Network World, 01/17/05.

https://www.nwfusion.com/news/2005/011705mcaffee.html?nl

Veritas customers wary of merger

Security vendor Symantec has taken a beating on Wall Street since announcing plans in December to buy storage management company Veritas Software for $13.5 billion. But perhaps an even more skeptical crowd awaits Symantec in the form of Veritas customers. Network World, 01/17/05.

https://www.nwfusion.com/news/2005/011705veritasfolo.html?nl

Software unmasks those who try to hide identity

Identity resolution software finds relationships between individuals – demonstrating obscure links between people who could be in cahoots, or discovering that two or more individuals thought to be separate people are in fact the same person. It’s a market that’s gotten a lot of attention since the Sept. 11 terrorist attacks. Most recently, IBM made its interest clear in the technology by acquiring SRD for an undisclosed amount. Network World, 01/17/05.

https://www.nwfusion.com/news/2005/011705ibm.html?nl

DoD targets child porn on military PCs

When it comes to cybercrime, one of the biggest problems facing the Department of Defense comes from within – the rank and file personnel suspected of downloading child pornography on military PCs. Network World, 01/17/05.

https://www.nwfusion.com/news/2005/011705dodcybercrime.html?nl

BMC adds to ID management arsenal

BMC Software last week announced it would pump up its management product suite with the acquisition of Calendra and its identity management technology. Network World, 01/17/05.

https://www.nwfusion.com/news/2005/011705bmc.html?nl

WLAN security company Bluesocket adds $10 million to coffers

Bluesocket, which got its start in the wireless LAN market back when people were more enthused about Bluetooth than Wi-Fi, this week is announcing $10 million in additional venture funding. Network World Fusion, 01/18/05.

https://www.nwfusion.com/news/2005/0118blueventure.html?nl