* Patches from Microsoft, Debian, Gentoo, others * Beware latest Rbot variants * George Mason University suffers security breech, and other interesting reading
endif; ?>Don’t want to wait until Mondays and Thursdays to read our alerts? Now you can get daily updates here: http://www.nwfusion.com/weblogs/alerts/
Don’t want to wait until Mondays and Thursdays to read our alerts? Now you can get daily updates here:
https://www.nwfusion.com/weblogs/alerts/
We’ve even got an RSS feed:
https://www.nwfusion.com/weblogs/alerts/index.rdf
Today’s bug patches and security alerts:
Microsoft issues three new updates
Microsoft has issued its first three patches for 2005. Two of the three are deemed “critical,” the third “important.” First, a flaw in the HTML Help ActiveX control could be exploited to take complete control of the affected system, if the active user is logged in as an administrator. Second, older versions of Windows (anything not including XP SP2) contain vulnerabilities in the kernel and the “Cursor and Icon Format Handling” functionality. In the most extreme case, an attacker could take control of the affected machine. Finally, the Indexing Service in Windows 2003 and Windows XP SP1 is vulnerable to attack through it’s query handling system, which does not properly sanitize user input. For more, go to:
https://www.nwfusion.com/news/2005/0111micropatch.html?nl
Patches:
MS05-001: Vulnerability in HTML Help Could Allow Code Execution
https://www.microsoft.com/technet/security/Bulletin/MS05-001.mspx
MS05-002: Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution
https://www.microsoft.com/technet/security/Bulletin/MS05-002.mspx
MS05-003: Vulnerability in the Indexing Service Could Allow Remote Code Execution
https://www.microsoft.com/technet/security/Bulletin/MS05-003.mspx
CERT advisories:
HTML Help:
https://www.us-cert.gov/cas/techalerts/TA05-012B.html
Cursor and Icon format handling:
https://www.us-cert.gov/cas/techalerts/TA05-012A.html
**********
DoS vulnerability in Squid
A denial-of-service vulnerability exists in Squid, an open source proxy server. The flaw is a memory leak in fakeauth_auth NTLM that could ultimately cause the system to run out of memory. For more, go to:
https://www.squid-cache.org/Versions/v2/2.5/bugs/
**********
Debian, Gentoo patch exim
According to a Gentoo alert, “Buffer overflow vulnerabilities, which could lead to arbitrary code execution, have been found in the handling of IPv6 addresses as well as in the SPA authentication mechanism in Exim.” For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-635
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-23.xml
**********
Debian, Gentoo patch KDE
According to an alert from Debian, “A vulnerability in the kioslave library, which is part of kdelibs, which allows a remote attacker to execute arbitrary FTP commands via an ftp:// URL that contains an URL-encoded newline before the FTP command.” KDE is a graphical user interface for Linux. Patches are available:
Debian:
https://www.debian.org/security/2005/dsa-631
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-18.xml
**********
Debian and Gentoo patch HylaFAX
A bug in the code HylaFAX, a software package for sending and receiving faxes, uses for validating usernames could be exploited to bypass the authentication altogether. Patches are available:
Debian:
https://www.debian.org/security/2005/dsa-634
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-21.xml
**********
Apple releases iTunes update
Apple has released Version 4.7.1 of iTunes that fixes a buffer overflow found in previous releases. The flaw is in the way iTunes parses playlists and could be exploited to crash the affected machine or potentially run any code the attacker wanted. The new version can be downloaded here:
https://www.apple.com/itunes/download/
**********
Flaw in open source MP3 player
Security researchers at Secunia are warning of a heap overflow in the open source MP3 player mpg123. Attackers could insert code into the header of an MPEG2 or MP3 file to exploit the overflow and potentially run any code on the affected machine. For more, go to:
https://secunia.com/advisories/13779/
**********
OpenPKG releases patch for Perl
A flaw in the rmtree() function in OpenPKG’s Perl implementation could be exploited in a symlink attack to delete arbitrary files on an affected machine. For more, go to:
https://www.openpkg.org/security/OpenPKG-SA-2005.001-perl.html
**********
SuSE updates libtiff
Remote attackers can exploit heap and integer overflow vulnerabilities in libtiff, a package for displaying images. These flaws could be used to run any code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0110bug2a.html
**********
Gentoo releases patch for TikiWiki
A flaw in TikiWiki, a Web-based groupware/content management system, could be exploited by users to upload and run PHP scripts on the affected server. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-12.xml
Gentoo patches KPdf, KOffice
A vulnerability in Xpdf, a tool for viewing PDF files, impacts Gentoo’s KPdf and KOffice. A remote attacker can exploit the vulnerability to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-17.xml
Broken sandbox in Gentoo’s Konqueror
The sandbox in Konqueror that protects the rest of the operating system from potentially rogue Java applets is flawed. It is possible to bypass the sandbox restrictions, allowing a Java applet to perfom any action on the affected system. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-16.xml
Gentoo patches dillo
A format string vulnerability in dillo, a small Web browser, could be exploited by an attacker to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-11.xml
Gentoo patches o3read
The o3read file conversion utility for OpenOffice.org files contains a buffer overflow that could be exploited via a malicious XML file. An attacker may exploit this to run any code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-20.xml
Gentoo releases fix for pdftohtml
A bug the PDF file handler Xpdf impacts the pdftohtml package as well, which is used to covert PDF files into HTML or XML. A malicious PDF file could be used to exploit the vulnerability, allowing an attack to run any code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-13.xml
Gentoo patches poppassd_pam vulnerability
A flaw in Gentoo’s poppassd_pam, a system for changing POP passwords, could be exploited by an attacker to change any password without authorization. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-20.xml
**********
Debian releases fixes lintian
Lintian, a tool for checking the Debian packages, contains a bug that could be exploited in a symlink attack against the affected server. Attackers could alter or add files when exploiting these flaws. For more, go to:
https://www.debian.org/security/2005/dsa-630
Debian issues patch for linpopup
A buffer overflow in linpopup could be exploited to run malicious code on the affected machine. According to Debian, linpopup is “an X11 port
of winpopup, running over Samba.” For more, go to:
https://www.debian.org/security/2005/dsa-632
Temporary file vulnerability in Debian’s bmv
A flaw in bmv, a PostScript viewer application, could result in temporary files being created without the proper security precautions. These temporary files could be exploited by an attacker using a symlink attack. For more, go to:
https://www.debian.org/security/2005/dsa-633
Debian patches libc6
The libc6 package, a C library for GNU/Linux, contains a vulnerability in the way on of its functions creates temporary files. These files are not properly secured, making them vulnerable to a symlink attack. A fix is available:
https://www.debian.org/security/2005/dsa-636
**********
Today’s roundup of virus alerts:
Virus-infected Windows Media files?
Panda Software is reporting two new Trojan horse applications that take advantage of peer-to-peer systems and Windows Media DRM technology to spread to unsuspecting users: “The video files infected by these Trojans have a .wmv extension and are protected by licenses, supposedly issued by the companies overpeer (for Trj/WmvDownloader.A), or protectedmedia (for Trj/WmvDownloader.B).”
https://www.nwfusion.com/weblogs/multimedia/2005/007211.html?nl
W32/Rbot-TD – This Rbot variant spreads via network shares and allows backdoor access via IRC. It uses a random filename to infect the machine and can be used for a number of malicious purposes. (Sophos)
W32/Rbot-TE – Another Rbot variant that attempts to exploit many known Windows vulnerabilities as it spreads via network shares. It installs itself as “dllman.exe” in the Windows System directory and provides backdoor access via IRC. (Sophos)
W32/Rbot-TF – Very similar to Rbot-TE, except it installs “wuaruclt.exe”. (Sophos)
W32/Woned-A – A Windows worm that installs itself as “WIN32DLL.EXE”. It spreads via file sharing applications by faking file names like “Adobe_Photoshop_CS_FULL_AND_CRACK.exe”. (Sophos)
W32/Sdbot-SW – An Sdbot variant that drops two files on the infected machine: “HB90HGF3.EXE” and “SYSEDITS.EXE”. It can spread via network shares. (Sophos)
W32/Agobot-OV – This bot copies itself into “fnksvc32.exe” in the Windows System directory. It can be access remotely via IRC and can carry out denial-of-service attacks, act as a proxy, steal information from the local machine and more. (Sophos)
W32/Wurmark-D – A mass-mailing worm that spreads through a message entitled “HAPPY NEW YEAR!!!” and contains an infected .zip file. The worm drops “ANSMTP.DLL”, “attached.zip”, “bszip.dll”, “newyear.jpg” and “xxz.tmp” in the Windows System directory and “bt32.exe” in the C: root folder. (Sophos)
W32/Forbot-DK – A bot that exploits the Windows LSASS vulnerability in order to infect a machine. It drops the file “WinxPupd.exe” in the Windows System directory and can be used for a number of malicious purposes, including stealing CD keys, act as a proxy, delete services, download files and more. (Sophos)
W32/Bobax-D – A Sasser-like worm that exploits the Windows LSASS vulnerability. It uses a randomly named DLL file to infect the machine. Attackers can use the infected machine to send Spam. The worm disables the Windows firewall and will attempt to delete the registry. (Sophos)
**********
From the interesting reading department:
George Mason University suffers security breech
George Mason University recently discovered unauthorized access to a database that has exposed 32,000 people to potential identity theft, although no such activity has yet been traced to the security breech. Network World Fusion, 01/12/05.
https://www.nwfusion.com/news/2005/0112gmuniv.html?nl
DOD cyber sleuths swap secrets in Florida
The U.S. Department of Defense is making changes to streamline its response to online threats across the various branches of the military, and deal with a steady stream of new online woes, from hacking attempts to child pornography and threats posed by powerful portable storage devices such as iPods, according to senior DOD officials. IDG News Service, 01/12/05.
https://www.nwfusion.com/news/2005/0112dodcyber.html?nl
McAfee sells off security research division
Anti-virus software vendor McAfee will sell off its McAfee Research division to Sparta as part of a move to streamline its operations. IDG News Service, 01/12/05.
https://www.nwfusion.com/news/2005/0112mcafesells.html?nl
Weblog: Think like a hacker
Network Life columnist Deb Radcliff talks with reformed hacker Geoff Shivley, who now runs vulnerability patching company PivX. Network Life, 01/09/05.
https://www.networklifemag.com/weblogs/securitychief/2005/007187.html?nl




