Python vulnerability patched

Opinion
Feb 7, 20055 mins

* Patches from Python, Gentoo, Debian, others * Beware MSN Messenger worm, Bropia.F

Tomorrow should be a fun day as Microsoft is set to release 13 new patches for Windows and other applications. Be on the lookout! http://www.nwfusion.com/news/2005/0204thirtpatch.html

Tomorrow should be a fun day as Microsoft is set to release 13 new patches for Windows and other applications. Be on the lookout!

https://www.nwfusion.com/news/2005/0204thirtpatch.html

Microsoft advisory:

https://www.microsoft.com/technet/security/bulletin/advance.mspx

Today’s bug patches and security alerts:

Python vulnerability patched

The Python development group has discovered a flaw in the SimpleXMLRPCServer library module. An attacker could use this to view object data and potentially execute malicious code. Patches are available:

Python 2.2:

https://python.org/security/PSF-2005-001/patch-2.2.txt

Python 2.3 and 2.4:

https://python.org/security/PSF-2005-001/patch.txt

Debian’s Python 2.2:

https://www.debian.org/security/2005/dsa-666

**********

Code execution flaw in Eudora 6.2

NGSSoftware is warning of a “high risk” vulnerability in the popular Eudora e-mail client. Two flaws could be exploited to run malicious code on the affected machine. Eudora has released Version 6.2.1 to fix the problem.

Download Eudora Version 6.2.1:

https://www.eudora.com/security.html

NGSSoftware advisory:

https://www.ngssoftware.com/advisories/eudora-01.txt

**********

Gentoo patches Newspost

According to a Gentoo advisory, “A buffer overflow can be exploited to crash Newspost remotely and potentially execute arbitrary code.” Newspost is an application for posting to Usenet groups. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-05.xml

**********

Mandrake Linux issues update for vim

Two scripts, “tcltags” and “vimspell.sh”, included with the vim editor create temporary files in a non-secure fashion. A symlink attack could be used to exploit this, allowing a malicious user to overwrite arbitrary files on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0207bug1a.html

**********

Debian issues fix for postgresql

According to a Debian alert, a flaw in the postgresql database could allow an attacker to load any local library into the application, which could result in malicious code being run on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-668

Debian releases squid patch

Debian is warning of multiple vulnerabilities in squid, an open source proxy server. The flaws could be used in a denial-of-service attacks or to potentially run arbitrary code on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-667

**********

Today’s roundup of virus alerts:

MSN Messenger worm raised to medium threat

Security experts have raised the warning level on a worm that spreads via Microsoft’s MSN Messenger, in an effort to slow its crawl through Taiwan, Korea, China and the U.S. The Bropia.F worm, a variant of the Bropia.A worm detected last month, was raised to a medium-risk threat this week by anti-virus firm Trend Micro. IDG News Service, 02/04/05.

https://www.nwfusion.com/news/2005/0204msnmesse.html?nl

The image associated with the Bropia virus:

https://www.pandasoftware.com/img/enc/W32BropiaE_img1.gif

W32/Rbot-SQ – This Rbot variant copies itself to the Windows System folder as “mcafeee.exe”. It allows backdoor access via IRC and spreads through weakly protected network shares. It can be used to carry out DoS attacks, steal local information and log keystrokes. (Sophos)

W32/Rbot-UC – Similar to Rbot-SQ above, this variant exploits a number of known Windows vulnerabilities as it spreads via network shares. This one uses the file “msdiag32.exe” as its infection point. (Sophos)

W32/Ahker-Bm – A mass mailer that comes with a subject line of “Service Pack 2 BUG!!” and an infected ZIP attachment. It disables a number of security-related processes that could be running on the infected machine and limits access to security Web sites by modifying the Windows HOSTS file. (Sophos)

W32/Protorid-AB – This worm spreads via network shares by exploiting the Windows RPC-DCOM vulnerability. It copies itself in to a number of predefined directories and provides backdoor access via IRC. The infected machine can be used a host for malicious purposes. (Sophos)

Troj/Shine-B – A virus that tries to change the Internet Explorer proxy settings, rendering IE useless. (Sophos)

W32/Traxg-C – This mass mailer displays the message “This Folder Has Been Damage!” on the infected machine. It uses a random file name as its infection point. It may also drop the file “FOLDER.HTT” in the C drive’s root directory. (Sophos)

W32/Bobax-F – A worm that turns the infected machine into a Spam relay. It spreads via networks shares, exploiting the Windows LSASS vulnerability. (Sophos)

W32/LegMir-Z – A worm that drops the file “virDll.dll” on the infected machine and tries to corrupt a number of EXE files. It attempts to disrupt security-related applications running on the infected machine. (Sophos)

Locknut.A – A virus that infects the Symbian 7.0S operating system for cellphones. It looks like a patch for the operating system, but could kill some applications on the infected phone. (Panda Software)