* Patches from Cisco, Debian, Gentoo, others * Beware new MyDoom mass-mailing worm variant * IronPort adds Symantec anti-virus to e-mail appliances, and other interesting reading
Today’s bug patches and security alerts:
Cisco patches three IOS flaws
Cisco devices running IOS are vulnerable to attacks that involve malformed packets causing the affected device to reboot. Devices running IOS and supporting Border Gateway Protocol (BGP), MPLS or IPv6 packets could be vulnerable. Cisco has released a free update to fix these issues:
IPv6 issue:
https://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml
BGP issue:
https://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml
MPLS issue:
https://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml
**********
New Mac OS X update available
A new security update for Apple’s Mac OS X is available. It fixes flaws in at, ColorSync, libxml2, Mail, PHP, Safari and SquirrelMail. The most serious of these could be exploited to run malicious code on the affected machine. For more, go to:
https://docs.info.apple.com/article.html?artnum=300770
**********
iDefense warns of 3Com access point flaw
A flaw in 3Com’s OfficeConnect Wireless 11g Access Point could allow an attacker to glean system information via the port 80 Web management interface, according to iDefense. Firmware version 1.00.08 is vulnerable and others may be as well. A fix is available here:
https://www.nwfusion.com/go2/0124bug2a.html
iDefense advisory:
https://www.nwfusion.com/go2/0124bug2b.html
**********
Debian, Gentoo, Mandrake Linux patch Ethereal
A new update for Ethereal fixes seven flaws in the popular network monitoring software. Most could be used to in a denial-of-service attack, though a few could be exploited to run any code on the affected machine. Patches can be downloaded from:
Debian:
https://www.debian.org/security/2005/dsa-653
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-27.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0124bug2c.html
**********
Gentoo, Mandrake Linux release patch for mailman
Gentoo’s and Mandrake Linux’s mailman implementation, a Python-based mailing list server, are vulnerable to a cross-scripting attack. An attacker could use special URLs that when click will execute malicious code on the affected machine. Fixes are available:
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-29.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0124bug2d.html
**********
Gentoo, Mandrake Linux patch Cups
Multiple vulnerabilities have been discovered in CUPS (Common UNIX Printing System), some of which could be exploited to run arbitrary code on the affected machine. Patches are available:
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-30.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0124bug2e.html
**********
PDF-related flaws abound
A number of open source PDF viewer applications are vulnerable to a couple buffer and stack overflow vulnerabilities, which could be exploited to run malicious code on the affected platforms. Fixes are available:
Conectiva (xpdf):
https://www.nwfusion.com/go2/0124bug2f.html
Gentoo (Xpdf, Gpdf):
https://security.gentoo.org/glsa/glsa-200501-28.xml
Gentoo (Kpdf, KOffice):
https://security.gentoo.org/glsa/glsa-200501-32.xml
KDE (KOffice):
https://www.kde.org/info/security/advisory-20050120-1.txt
KDE (kpdf):
https://www.kde.org/info/security/advisory-20050119-1.txt
Mandrake Linux (xpdf):
https://www.nwfusion.com/go2/0124bug2g.html
Related iDefense advisory:
https://www.nwfusion.com/go2/0124bug2h.html
**********
Debian, Mandrake Linux patch zhcon
A user-controlled configuration file could be used to gain elevated privileges on the affected machine, allowing an attacker to read any file. Patches are available:
Debian users:
https://www.debian.org/security/2005/dsa-655
Mandrake Linux:
https://www.nwfusion.com/go2/0124bug2i.html
**********
SuSE patches kernel flaws
A number of vulnerabilities have been found in SuSE’s Linux kernel. The flaws could be exploited in denial-of-service attacks and to potentially run any code on the affected machine. An update is available:
https://www.nwfusion.com/go2/0124bug2j.html
SuSE releases patch for RealPlayer 8
An integer overflow in RealPlayer could allow an attacker to run any code on the affected machine using a specially crafted .rm media file. EEye security consultants found the flaw back in October and Real suggests upgrading to RealPlayer 10.
EEye advisory:
https://www.eeye.com/html/research/advisories/AD20041001.html
Real advisory:
https://service.real.com/help/faq/security/040928_player/EN/
**********
Debian issues patch for enscript
Multiple vulnerabilities have been found in enscript, a tool for converting ASCII to PostScript. Two of the flaws could be exploited to run malicious code on the affected machine. A third could be used to crash the machine. For more, go to:
https://www.debian.org/security/2005/dsa-654
Debian releases fix for xine-lib
A buffer overflow has been discovered in one of xine-lib’s functions. The input size is not properly checked for certain data fields. For more, go to:
https://www.debian.org/security/2005/dsa-657
**********
KDE patches Konversation
The IRC client Konversation for KDE contains a number of security vulnerabilities. According to KDE, Konversation does not properly expand escaped variables, passwords in the QuickConnect function could be exposed to others and a number of Perl scripts included with the application do not properly handle command line arguments. An update is available:
https://www.kde.org/info/security/advisory-20050121-1.txt
**********
Gentoo issues fix for MySQL
A symlink attack vulnerability has been found in the popular MySQL database system. Temporary files are created with “predictable” names in world-writeable directories. An attacker could exploit this to overwrite any file on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-33.xml
Gentoo fixes Evolution
According to Gentoo, “An overflow in the camel-lock-helper application can be exploited by an attacker to execute arbitrary code with elevated privileges.” Evolution is a Gnome groupware application. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-35.xml
**********
Mandrake Linux patches squid
Two vulnerabilities exist in Squid, an open source proxy server. One of the problems is a memory corruption with Gopher and the other is an integer overflow in WCCP (Web Cache Communication Protocol) messages. For more, go to:
https://www.nwfusion.com/go2/0124bug2k.html
**********
Today’s roundup of virus alerts:
Mobile malware kills Symbian service
Two new Trojan horse programs threaten to render some Symbian-based mobile phones totally useless. The programs, Gavno.a and Gavno.b, masquerade as patch files designed to trick users into downloading them, said Aaron Davidson,chief executive officer of SimWorks International Ltd., in a telephone interview on Monday. IDG News Service, 01/24/05.
https://www.nwfusion.com/news/2005/0124mobilmalwa.html?nl
W32/Sdbot-TV – A new Sdbot variant that drops two files on the infected machine, both in the Windows System directory: “QAVANT.EXE” and “QAVBAP.EXE”. The virus provides backdoor access via IRC and can download code from a remote site. (Sophos)
W32/Sdbot-TW – Our second Sdbot variant of the day can be used to participate in DDoS attacks. It too spreads via network shares and provides backdoor access via IRC. It drops “IEXPLORE.EXE” in the Windows System folder. (Sophos)
W32/Rbot-UH – Another bot variant that spreads via network shares, allows backdoor access via IRC and can be used for a number of malicious purposes. This one exploits the Windows DCOM, LSASS and Microsoft SQL Server vulnerabilities. It installs “MCAFESHIELD.EXE” in the Windows System folder. (Sophos)
W32/MyDoom-AM – A new MyDoom mass-mailing worm variant. It spreads via various message types, though each has an attachment that ends with pif, scr, exe, cmd, bat or zip. It drops “lsasrv.exe” on the infected machine, opens notepad and fills it with garbage, then disables access to security-related Web sites by modifying the HOSTS file. (Sophos)
W32/Bobax-E – This worm’s main purpose seems to be as a mail relay for spammers. It spreads via network shares, exploiting the Windows LSASS vulnerability. It drops a randomly named DLL on the infected machine. (Sophos)
W32/Patco-A – A worm that drops two files on the infected machine: “patch802.exe” and “codeme.exe”. It can overwrite Word Document files in the My Documents directory. (Sophos)
W32/Kassbot-A – Another worm that can be used to participate in DDoS attacks and lower the level of security on the infected machine. It runs as the service “nethost”. (Sophos)
W32/Forbot-DV – A Forbot variant that drops “MsConfiG.exe”. Like most bots, it spreads via network shares and can provide backdoor access via IRC, which can be used for a number of malicious purposes. (Sophos)
Troj/Agent-ZC – This Trojan horse is used to send Spam. It creates the file “restorecrashwin32.bat”. (Sophos)
**********
From the interesting reading department:
MyDoom one year later: more zombies, more spam
Computer security experts remembered the MyDoom e-mail worm Wednesday, one year after it tore through the Internet, deluged e-mail systems with infected messages and set records for infecting vulnerable computer systems. IDG News Service, 01/26/05.
https://www.nwfusion.com/news/2005/0126mydoooney.html?nl
IronPort adds Symantec anti-virus to e-mail appliances
IronPort Systems on Monday announced plans to sell Symantec’s anti-virus software with its C-Series Email Security appliances. Network World Fusion, 01/25/05.
https://www.nwfusion.com/news/2005/0125iron.html?nl
SAP launches two security initiatives
SAP has launched two new initiatives aimed at helping customers secure their SAP software systems. IDG News Service, 01/25/05.
https://www.nwfusion.com/news/2005/0125saplaunc.html?nl
Start-up promises better speed, security on Itanium
A start-up founded by a group of ex-HP executives, including the chief architect behind Itanium, officially debuted Mondayand announced plans to ship software this summer that promises to boost the speed and security of Web applications on Itanium servers. Network World Fusion, 01/24/05.
https://www.nwfusion.com/news/2005/0124sec64.html?nl
Kavado unveils Defiance TMS for Web application protection
Kavado, which for several years has offered its Web application security firewall InterDo that blocks attacks through intrusion prevention, is coming out with a new product called Defiance that also takes advantage of intrusion detection to passively monitor as well. Network World Fusion, 01/24/05.
https://www.nwfusion.com/news/2005/0124kavado.html?nl
McAfee updates IntruShield line
McAfee has updated its line of network intrusion prevention systems with two new IntruShield hardware appliances for large enterprises and ISPs. IDG News Service, 01/24/05.
https://www.nwfusion.com/news/2005/0124mcafeupdat.html?nl
Gibbs: Backspin: The IT Big One: Just a matter of time
What if an uncrackable virus targets spyware as a delivery and transmission vector? Or what about a zero-day exploit built into a virus or worm that infects, say, Windows operating systems? It would be great to believe that such a combination couldn’t exist, but that wouldn’t be a smart bet given the history of the security problems of commercial products and their increasing complexity. Network World, 01/24/05.
https://www.nwfusion.com/columnists/2005/012405backspin.html?nl
Op-ed: Trusted LANs set to take off
Between 1995 and 2000, two important innovations occurred: virtual LANs and Gigabit Ethernet. Now in 2005, the LAN market is about to make another fundamental transition: from virtual LANs to trusted LANs, which let secure internal networks be provisioned at high speeds whether transport is wireless or wired. Network World, 01/24/05.
https://www.nwfusion.com/columnists/2005/012405lippis.html?nl




