Juniper reports software flaw

Opinion
Jan 31, 20059 mins

* Patches from SCO, Conectiva, Gentoo, others * Beware new worm targeting MySQL installations * Warning over Microsoft Word files, and other interesting reading

Today’s bug patches and security alerts:

Juniper bitten by software bug

Cisco is not the only one with vulnerable routing software. Juniper this week is telling all M- and T-Series router customers running releases of JUNOS software developed prior to Jan. 7, 2005,to upgrade the software or suffer a “serious security vulnerability.” Network World, 01/27/05.

https://www.nwfusion.com/edge/news/2005/0127juniper.html

**********

Novell posts workaround for GroupWise flaw

A bug in Novell GroupWise’s could allow a user to gain some read privileges on the affected machine. Novell has not published a patch for the problem, but workaround information is available in the alert:

https://support.novell.com/servlet/tidfinder/10096251

**********

SCO patches x.org for UnixWare

It is possible to “hijack” socket directories created in the temp directory by x.org. SCO has released a fix for this problem for UnixWare. For more, go to:

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8

SCO issues fix for OpenServer’s wu-ftp

A bug the directory restrictions function in the wu-ftp server could direct unauthorized users into the root directory. A fix is available. For more, go to:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.6

SCO releases fix for OpenServer’s scosessoin

A flaw in the way command line strings are handle by scosession could allow a local attacker to gain elevated privileges on the affected machine. For more, go to:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5

**********

Conectiva patches squid

A denial-of-service vulnerability exists in Squid, an open source proxy server. The flaw is a memory leak in fakeauth_auth NTLM that could ultimately cause the system to run out of memory. A patch is available.

https://www.nwfusion.com/go2/0131bug1a.html

**********

OpenPKG patches SASL

A flaw in the way SASL searches for related components at system startup could be exploited by a local user to run arbitrary code on the affected machine. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2005.004-sasl.html

**********

Gentoo patches multiple flaws in teTeX, pTeX and CSTeX

A vulnerability in xpdf, a PDF document viewer, also impacts the teTeX, pTeX and CSTeX applications. An attacker could exploit this to run arbitrary code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-31.xml

AWStats patch for Gentoo

The AWStats log file analysis tool does not properly validate certain input, which could be exploited to run malicious code on the affected machine remotely. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-36.xml

Gentoo releases fix for GraphicsMagick

A heap overflow in the way GraphicsMagick handles PhotoShop document files could be exploited to run code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-37.xml

Gentoo issues update for Perl

Two functions in Gentoo’s Perl implementation are vulnerable to symlink attacks, which could result in files being overwritten. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-38.xml

Gentoo patches SquirrelMail

User input into SquirrelMail is not properly checked, which could be exploited to run code on the affected machine. Individual mail accounts could be compromised as well. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-39.xml

Gentoo releases patch for ngIRCd

A buffer overflow in the ngIRCd open source IRC daemon for Gentoo could be exploited to crash the affected machine or potentially run arbitrary commands. For more, go to:

https://security.gentoo.org/glsa/glsa-200501-40.xml

**********

Mandrake Linux patches tetex

A vulnerability in xpdf, a PDF document viewer, also impacts Mandrake Linux’s tetex package. Attackers could exploit this to run their code of choice on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0131bug1b.html

Mandrake Linux patches evolution

According to an alert from Mandrake Linux, ” Max Vozeler discovered an integer overflow in the camel-lock-helper  application.  This application is installed setgid mail by default. A local attacker could exploit this to execute malicious code with  the privileges of the “mail” group; likewise a remote attacker could setup a malicious POP server to execute arbitrary code when an Evolution user connects to it.” For more, go to:

https://www.nwfusion.com/go2/0131bug1c.html

Mandrake Linux issues fix for gpdf

A buffer overflow vulnerability in xpdf also impacts Mandrake Linux’s gpdf application. An attacker could exploit this to run their code of choice on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0131bug1d.html

Mandrake Linux updates koffice, kdegraphics

A buffer overflow in the xpdf PDF document viewer also affects Mandrake Linux’s implementation of koffice and kdegraphics. Attackers could exploit this to run any code on the affected machine. For more, go to:

kdegraphics:

https://www.nwfusion.com/go2/0131bug1e.html

koffice:

https://www.nwfusion.com/go2/0131bug1f.html

**********

Debian releases patch for kdebase

The KDE screensaver application is vulnerable to a crash. An attacker sitting at the affected machine could take control of it. For more, go to:

https://www.debian.org/security/2005/dsa-660

Debian patches f2c

Temporary files created by f2c, a Fortran 77 to C/C++ converter, could be exploited in a symlink attack. This type of attack could be used to overwrite files on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-661

Debian issues fix for libdbi-perl

The DBI library for Perl creates PID files in a non-secure manner. An attack could exploit this to overwrite arbitrary files. For more, go to:

https://www.debian.org/security/2005/dsa-658

Debian releases fix for libpam-radius-auth

Multiple flaws have been found in libpam-radius-auth package, a PAM RADIUS authentication module. One flaw could result in information leakage, the other could cause an integer overflow. For more, go to:

https://www.debian.org/security/2005/dsa-659

Debian patches vdr

According to an alert from Debian, “The vdr daemon which is used for video disk recorders for DVB cards can overwrite arbitrary files.” For more, go to:

https://www.debian.org/security/2005/dsa-656

**********

Today’s roundup of virus alerts:

New worm targets MySQL installations

The new pest is a version of a common network worm named “Forbot.” It infects machines by exploiting loosely secured MySQL installations running on Windows machines connected to the Internet. The new Forbot variant is one of the first known examples of an automated Internet threat targeting MySQL, and could infect machines running a wide range of database applications that use MySQL, according to Joe Stewart, a senior security researcher at LURHQ. IDG News Service, 01/27/05.

https://www.nwfusion.com/news/2005/0127newworm.html?nl

https://isc.sans.org/port_details.php?port=3306&tarax=1

New Bagle worms making the rounds

Two new versions of the Bagle e-mail worm are spreading on the Internet and through peer-to-peer file-sharing networks, according to warnings issued on Thursday by anti-virus software companies. The latest Bagle variants, Bagle.AX and Bagle.AY, are the 50th and 51st versions of the original Bagle worm, which appeared in January 2004. Like the first Bagle, sometimes spelled “Beagle,” versions AX and AY spread in executable files and infect machines running Microsoft’s Windows operating system, anti-virus companies said. IDG News Service, 01/27/05.

https://www.nwfusion.com/news/2005/0127newbagle.html?nl

W32/Codbot-A – Codbot attempts to exploit a number of Windows vulnerabilities as it tries to install a backdoor Trojan on the target system. It drops “NETMON.EXE” in the Windows System folder and can be used to download code from a remote site. (Sophos)

W32/Cisum.A – A new network worm that uses a random file name as its infection point and displays the message “YOU ARE AN IDIOT” on the screen. The worm also attempts to stop security-related applications. (Panda Software)

W32/Rbot-AIX – An Rbot variant that exploits a number of Windows vulnerabilities as it spreads via network shares. This variant drops “trass.exe” in the Windows System folder and can be used for a number of malicious purposes. (Sophos)

W32/Rbot-UU – This Rbot variant drops “USBHARDWARE32C.EXE” in the Windows System folder after spreading through a weakly protected network share. It allows backdoor access via IRC. (Sophos)

W32/Forbot-DR – Another Forbot variant that provides backdoor access to the infected machine via IRC. It installs “lmas.exe” in the Windows System directory and can be used for a number of malicious purposes. (Sophos)

W32/MyDoom-AN – A new MyDoom variant that spreads via e-mail and ICQ. It uses a variety of e-mail attributes, but all of the infected attachments are .zip files. MyDoom attempts to stop a number of security applications and modifies the Windows HOST file to limit access to security Web sites. (Sophos)

W32/Wurmark-F – This Wurmark variant displays the image “uglym.jpg” as it infects the target machine. The virus spreads via .zip attachment and drops “ANSMTP.DLL” and “bszip.dll” in addition to the jpg. (Sophos)

W32/Bobax-G – A Bobax variant that exploits the Windows RPC-DCOM and LSASS vulnerabilities as it spreads via network shares. It limits access to security Web sites and can be used to download malware. (Sophos)

Troj/Goldun-G – A Trojan that is used to steal banking passwords. It drops “SVHOST.EXE” on the infected machine and displays a porn image. (Sophos)

Troj/Vidlo-H – This Trojan injects its code into Internet Explorer when it runs. It can download additional code, including a password-stealing Trojan. (Sophos)

Crowt.A – An e-mail worm that looks like an “e-mail to friend” from CNN. It installs a keystroke logger and opens a backdoor. (Panda Software)

**********

From the interesting reading department:

Warning over Microsoft Word files

Writing a Microsoft Word document can be a dangerous business, according to document security firm Workshare. Up to 75% of all business documents contained sensitive information most firms would not want exposed, a survey by the firm revealed. BBC Online, 01/28/05.

https://news.bbc.co.uk/1/hi/technology/4211743.stm

Lexus cars potentially vulnerable to virus?

Here’s another Technology Gone Wild story to scare you.  Russian anti-virus research firm Kaspersky Lab says you can now add cars to the growing list of things that can be infected with a computer virus. Engadget, 01/26/05.

https://www.engadget.com/entry/1234000760029037/