* Patches from HP, Gentoo, Mandrake Linux, others * Beware new Sober variant * Phishing morphs into pharming, and other interesting reading
We lead with something a little off the wall today: Network World is putting together plans for a weekly “podcast” that, among other things, highlights some of the talent of our readers and listeners. We’re looking for techies that may play in a band in their spare time and want to share some of their music with our audience. If you’re interested, drop me a line at jmeserve@nww.com.
-Jason
Today’s bug patches and security alerts:
HP warns of Java DoS flaw
HP is warning of a denial-of-service vulnerability in the Java SDK and Run Time Environment (RTE) for its Tru64 Unix flavor. An attacker could only cause the system to fail and not execute code. Updated version of the SDK and RTE are available:
https://h18012.www1.hp.com/java/download
HP patches TGA daemon
According to alert from HP, “A potential security vulnerability has been identified with HP-UX running the TGA daemon, where certain network traffic could be used to create a Denial of Service (DoS). The vulnerability is remotely exploitable.” For more, go to:
https://www.nwfusion.com/go2/0131bug2a.html
**********
Gentoo, Mandrake Linux patch ClamAV
Two vulnerabilities have been found in ClamAV, an anti-virus toolkit. One flaw could be exploited to bypass the anti-virus screening using a base64-encoded image file in a URL. The second flaw could result in a denial-of-service when a specially crafted ZIP file is passed through the system. Patches are available:
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-46.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0131bug2b.html
**********
Gentoo, Mandrake Linux release patches for ncpfs
The ncpfs protocol, which allows access to NetWare services, contains multiple vulnerabilities. These could be exploited to run arbitrary commands and view files on the affected system. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200501-44.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0131bug2c.html
**********
Gentoo, Mandrake Linux release patch for UM-IMAP
The CRAM-MD5 authentication system used by UM-IMAP will allow access to anyone after 4 failed authentication attempts. Fortunately, the affected configuration is not the default setup. Patches are available:
Gentoo:
https://security.gentoo.org/glsa/glsa-200502-02.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0131bug2d.html
**********
Gentoo releases fix for f2c
Temporary files created by f2c, a Fortran 77 to C/C++ converter, could be exploited in a symlink attack. This type of attack could be used to overwrite files on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-42.xml
Gentoo fixes vdr vulnerability
A bug in vdr, a video recording application similar to TiVo, could be exploited to overwrite arbitrary files on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-42.xml
Gentoo patches gallery
Gentoo has released a new update for gallery, a Web-based photo album, that fixes two vulnerabilities. One could leak password information and the other cold be exploited to run arbitrary code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200501-45.xml
Gentoo patches enscript
Multiple vulnerabilities have been found in enscript, a tool for converting ASCII to PostScript. Two of the flaws could be exploited to run malicious code on the affected machine. A third could be used to crash the machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-03.xml
Gentoo releases patch for FireHOL
FireHOL, an iptables rules generator, is vulnerable to a symlink attack. A local attacker could exploit this vulnerability to overwrite files on the affected system. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-01.xml
Gentoo releases squid patch
Gentoo is reporting multiple vulnerabilities in squid, an open source proxy server. The flaws could be used in a denial-of-service attacks or to potentially run arbitrary code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-04.xml
**********
Mandrake Linux patches chbg
A buffer overflow in the Mandrake Linux chbg package could be exploited to run malicious code on the affected machine. A specially crafted configuration file is needed to exploit the overflow. For more, go to:
https://www.nwfusion.com/go2/0131bug2e.html
**********
Debian updates squirrelmail
User input into SquirrelMail is not properly checked, which could be exploited to run code on the affected machine. Individual mail accounts could be compromised as well. For more, go to:
https://www.debian.org/security/2005/dsa-662
Debian patches prozilla
According to Debian, “Several buffer overflows have been discovered in prozilla, a multi-threaded download accelerator which could be exploited by a remote attacker to execute arbitrary code on the victim’s machine. An exploit for prozilla is already in the wild.” For more, including a patch, go to:
https://www.debian.org/security/2005/dsa-663
Debian releases fix for cpio
The archive utility cpio could create files with permissions that make them easily overwritable by an attacker. For more, go to:
https://www.debian.org/security/2005/dsa-664
**********
Russian company picks hole in XP Service Pack 2
Russian security company Positive Technologies has released a patch to a security hole it said it discovered in Microsoft’s Windows XP Service Pack 2 last year. IDG News Service, 01/31/05.
https://www.nwfusion.com/news/2005/0131updatrus.html?nl
**********
Today’s roundup of virus alerts:
W32/Sober-J – New Sober variant that spreads via e-mail, harvesting target addresses from infected machine. The infected message has a variety of characteristics, but usually has an attachment ending in ZIP, PIF, SCR, BAT, COM or EXE. No word on what kind of permanent damage it may cause. (Sophos)
W32/Rbot-UW This Rbot variant spreads through network shares, allows backdoor access via IRC and can be used for a number of malicious purposes. It installs itself as “lsassM.exe” in the Windows System directory. (Sophos)
W32/Rbot-VD – This Rbot variant exploits many known Windows vulnerabilities as it spreads through network shares. Backdoor access is provided via IRC, which can be used to launch a number of malicious applications. Rbot-VD drops “winis.exe” in the Windows System folder. (Sophos)
W32/Rbot-VC – Yet another Rbot variant that allows backdoor access through IRC. This one spreads through the file “bling.exe” and drops “update.exe” in the Windows System folder. (Sophos)
W32/Agobot-PI – An Agobot variant that exploits network shares with weak or no password protection. It drops “Ksrv32.exe” in the Windows System folder and can allow access via IRC. In addition to being used for malicious purposes, the virus disables security applications and access to related Web sites. (Sophos)
W32/Bobax-F – A Bobax variant that uses a randomly named DLL file as its infection point. It spreads by exploiting the Windows LSASS vulnerability and can be used a Spam relay. (Sophos)
W32/Bobax-H – A similar variant to Bobax-F, including the randomly named file. (Sophos)
Troj/Banito-E – A Trojan that can be accessed via IRC and used to log keystrokes, launch denial-of-service attacks and steal system information. It logs keystrokes to “syskl32.ss” in the Windows System directory. (Sophos)
W32/Sdbot-UN – Another bot variant that spreads through network shares and allows access to the infected machine via IRC. This one drops the file “SDKc55rezzz2.exe” in the Windows System folder. (Sophos)
W32/MyDoom-AO – A new MyDoom variant that launches a Notepad document filled with garbage to fake out the user. It spreads via e-mail and drops “lsasrv.exe” in the Windows System folder. The infected e-mail attachment will have an extension of PIF, SCR, EXE OR BAT. It can limit access to security Web sites by modifying the Windows HOSTS folder. (Sophos)
**********
From the interesting reading department:
Phishing morphs into pharming
Fraudsters and mischief makers are developing more insidious techniques for tricking users into visiting bogus websites. Rather than using spam to con prospective victims into clicking their way to illicit sites – so called phishing attacks – internet ne’er-do-wells are using DNS poisoning or domain hijacks to redirect users to dodgy urls. The Register, 01/31/05.
https://www.theregister.co.uk/2005/01/31/pharming/
New zombie spam technique may send spam levels through the roof
If the warnings of security experts are to be believed, we are on the verge of a major onslaught of spam. Writers of malware that co-opts PCs into zombie spam armies have changed tack. Previously, PCs that had been hijacked had been set up as mail servers were and used to send out thousands of e-mails per day directly to… well, most of the world. Now, newer versions of the Trojans are having the compromised computers send the spam through their owners’ ISPs. ArsTechnica, 02/02/05.




