A gamut of Linux patches

Opinion
Jan 24, 20057 mins

* Patches from Debian, Conectiva, SCO, others * Beware new MyDoom variant * Symantec boxes to battle spam and viruses, and other interesting reading

Today’s bug patches and security alerts:

Debian patches squid

A denial-of-service vulnerability exists in Squid, an open source proxy server. The flaw is a memory leak in fakeauth_auth NTLM that could ultimately cause the system to run out of memory. For more, go to:

https://www.debian.org/security/2005/dsa-651

Debian updates sword

A function in the Debian sword application does not properly sanitize user input, which could lead to arbitrary code be executed on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-650

Debian releases update for xtrlock

A buffer overflow in xtrlock, an X display locking program, could be exploited by a local attacker to crash the program. For more, go to:

https://www.debian.org/security/2005/dsa-649

Debian issues fix for unarj

Several vulnerabilities have been found in unarj, a compression utility. The flaws could be exploited to run arbitrary code on the affected machine and overwrite system files. For more, go to:

https://www.debian.org/security/2005/dsa-652

**********

Conectiva patches libtiff3

Libtiff, an image handling system, is vulnerable to several integer overflows, according to an alert from Conectiva. An attacker could exploit this to run arbitrary code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0124bug1a.html

**********

Mandrake Linux releases fix for xine-lib

A buffer overflow has been discovered in one of xine-lib’s functions. The input size is not properly checked for certain data fields. For more, go to:

https://www.nwfusion.com/go2/0124bug1b.html

Mandrake Linux patches mpg123

A heap overflow in the open source MP3 player mpg123 could be used by an attacker to insert code into the header of an MPEG2 or MP3 file and potentially run any code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0124bug1c.html

Mandrake Linux issues fix for playmidi

According to an alert from Mandrake Linux, “A buffer overflow in playmidi that could be exploited by a local attacker if installed setuid root.” For more, go to:

https://www.nwfusion.com/go2/0124bug1d.html

**********

SCO patches BIND for OpenServer

A flaw in ISC’s BIND nameserver could allow a remote attacker to “poison” the name server cache, resulting in the server returning negative responses. For more, go to:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.4

SCO releases OpenSSL fix for UnixWare

Several vulnerabilities have been found in OpenSSL, which could affect any application that uses the library for SSL and TLS encryption. For more, go to:

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.7

**********

Gentoo releases fix for ImageMagick

A buffer overflow in a module for ImageMagik, an image manipulation tool, could be exploited by an attacker to run any code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-26.xml

**********

Today’s roundup of virus alerts:

W32/Forbot-DR – A network worm that spreads by exploiting the Windows LSASS vulnerability. It drops the file “lmas.exe” in the Windows System folder and can be used for a number of malicious purposes. (Sophos)

W32/Forbot-DS – Another Forbot variant that spreads via network shares and allows backdoor access via IRC. It installs “nvsv32.exe” in the Windows System directory and can be used to steal information and delete network shares. (Sophos)

W32/Oddbob-C – A worm that spreads via network shares, exploiting the Windows LSASS vulnerability to gain access to the target machine. It downloads malware from a preconfigured Web site and starts the process “zzzxIPSPEC_1”. (Sophos)

W32/Sdbot-TS – A bot that allows backdoor access via IRC after infecting a machine through a network share. It installs “IEXPLORE.EXE” in the Windows System directory and can be used to log keystrokes, including passwords. (Sophos)

W32/Kassbot-A – This virus runs spreads via network shares by exploiting a number of known Windows vulnerabilities and allows backdoor access via IRC. It runs as a service called “nethost” and can be used in a number of purposes. (Sophos)

W32/Rbot-UC – An Rbot variant that can be used for a number of malicious purposes and spreads via network shares. It installs itself as “msdiag32.exe” in the Windows System folder. (Sophos)

W32/Rbot-UD – Another Rbot variant that is similar to Rbot-UC above, except it uses the “icp.exe” as its infection point. (Sophos)

W32/Rbot-UE – This Rbot variant installs “YPager.exe” in the Windows System folder, mimicking a Yahoo Messenger application. It can allow backdoor access via IRC and used for a number of malicious purposes. (Sophos)

W32/MyDoom-AL – A new MyDoom variant that spreads via e-mail with a .zip attachment carrying the infection. It drops services.exe, winlogon.exe, csrss.ex and smss.exe in the various Windows folders. It can stop security related services and limit access to certain security sites. (Sophos)

Bropia.A – A virus that spreads via MSN Messenger using an infected PIF file. It disables the ctrl-alt-delete “three finger salute” as well as the right mouse button. (Panda Software)

**********

From the interesting reading department:

Clear Choice Test: Vulnerability alerting services

Vulnerability alerting services free up expensive IT security staff. Network World, 01/24/05.

https://www.nwfusion.com/reviews/2005/012405revvuln.html?nl

Audio: Behind the scenes at PivX

With Network World looking at seven Vulnerability Alerting Services in this week’s issue, we take a look at how one of these companies operates behind the scenes. Joining the program is Thor Larholm, senior security researcher for PivX. Network World Fusion, 01/24/05.

https://www.nwfusion.com/research/2005/0124radio.html?nl

Microsoft to boost Media Player security

Microsoft says it will patch versions of Windows Media Player to prevent users from inadvertently downloading viruses, adware, and spyware when opening copy-protected media files. The update will be available within 30 days, the company says. PC World, 01/21/05.

https://www.nwfusion.com/news/2005/0121microtobo.html?nl

Symantec boxes to battle spam and viruses

Symantec this week is expected to announce a series of appliances that do double duty by combating both spam and viruses. Network World, 01/24/05.

https://www.nwfusion.com/news/2005/012405symantec.html?nl

Vendor extends patch tools to Linux, Unix

Patch management vendor New Boundary Technologies is expanding the range of its software beyond Windows to answer user demands for cross-platform support that will address vulnerabilities, regardless of where they exist on the network. Network World, 01/24/05.

https://www.nwfusion.com/news/2005/012405newboundary.html?nl

Barracuda device guards outgoing e-mail

Barracuda Networks last week released a new version of its anti-spam appliance that prevents unwanted e-mail and viruses from being sent out of a corporate network while keeping sensitive data, trade secrets and other company information inside the organization. Network World, 01/24/05.

https://www.nwfusion.com/news/2005/012405barracuda.html?nl

IT hiring inches upward

Companies cautiously seek to increase IT staff with network, security and business skills. Network World, 01/24/05.

https://www.nwfusion.com/careers/2005/012405man.html?nl

MCI to buy managed security service provider

MCI announced Thursday its plans to acquire NetSec, a managed security service provider, for $105 million. Network World Fusion, 01/20/05.

https://www.nwfusion.com/edge/news/2005/0120mcibuy.html?nl

Reports of phishing attacks up again in December

Reports of online identity theft scams known as “phishing” attacks were up again in December, when more than 1,700 active phishing Web sites were reported, a 10% jump from the previous month, according to data released Thursday by the Anti-Phishing Working Group. IDG News Service, 01/20/05.

https://www.nwfusion.com/news/2005/0120reporofph.html?nl