* Patches from Microsoft, Symantec, Debian, others * Beware new Sober mass mailing variant that spreads via "text.zip" attachment
Today’s bug patches and security alerts:
Microsoft releases 12 patches for 16 vulnerabilities
Microsoft provided fixes for almost every supported version of Windows, including the recently updated Windows XP Service Pack 2, and patches for holes in everything from critical Windows components to the Internet Explorer Web browser and MSN Messenger IM application. IDG News Service, 02/08/05.
https://www.nwfusion.com/news/2005/0208microrelea.html?nl
For more, go to:
Microsoft advisories:
MS05-004: ASP.NET Path Validation Vulnerability:
https://www.microsoft.com/technet/security/Bulletin/MS05-004.mspx
MS05-005: Vulnerability in Microsoft Office XP could lead to Buffer Overrun:
https://www.microsoft.com/technet/security/Bulletin/MS05-005.mspx
MS05-006: Vulnerability in Windows SharePoint Services and SharePoint Team Services Could Allow Cross-Site Scripting and Spoofing Attacks:
https://www.microsoft.com/technet/security/Bulletin/MS05-006.mspx
MS05-007: Vulnerability in Windows Could Allow Information Disclosure:
https://www.microsoft.com/technet/security/Bulletin/MS05-007.mspx
MS05-008: Vulnerability in Windows Shell Could Allow Remote Code Execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-008.mspx
MS05-009: Vulnerability in PNG Processing Could Lead to Buffer Overrun:
https://www.microsoft.com/technet/security/Bulletin/MS05-009.mspx
MS05-010: Vulnerability in the License Logging Service Could Allow Code Execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-010.mspx
MS05-011: Vulnerability in Server Message Block Could Allow Remote Code Execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-011.mspx
MS05-012: Vulnerability in OLE and COM Could Allow Remote Code Execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-012.mspx
MS05-013: Vulnerability in the DHTML Editing ActiveX Control could allow code execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-013.mspx
MS05-014: Cumulative Security Update for Internet Explorer:
https://www.microsoft.com/technet/security/Bulletin/MS05-014.mspx
MS05-015: Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution:
https://www.microsoft.com/technet/security/Bulletin/MS05-015.mspx
CERT advisory:
https://www.cert.org/advisories/CA-2000-02.html
ISS alert:
https://xforce.iss.net/xforce/alerts/id/186
EEye advisory (for SMB Client):
https://www.eeye.com/html/research/advisories/AD20050208.html
**********
Symantec patches flaw in virus scanning module
A flaw in Symantec’s older virus scanning module used for scanning UPX compressed files could be exploited by an attacker to pass a virus through the system. Some version of Symantec’s products still use this module. For more, go to:
https://www.symantec.com/avcenter/security/Content/2005.02.08.html
**********
Cisco warns of SNMP flaw in video products
According to an alert from Cisco, “Hard-coded Simple Network Management Protocol (SNMP) community strings are present in Cisco IP/VC Videoconferencing System models 3510, 3520, 3525 and 3530. Any user who has access to the vulnerable devices and knows the community strings, can obtain total control of the device.” For more, go to:
https://www.cisco.com/warp/public/707/cisco-sa-20050202-ipvc.shtml
**********
iDefense issues advisory for AIX’s auditselect
A format string vulnerability in auditselect for a AIX could be exploited to write to arbitrary memory location. Auditselect is installed with root privileges. For more, go to:
https://www-1.ibm.com/support/docview.wss?uid=isg1IY67519
iDefense advisory:
https://www.nwfusion.com/go2/0207bug2a.html
**********
iDefense warns of flaw in chdev for AIX
A buffer overflow in the chdev command included with IBM AIX operating system could be exploited by a local user to run malicious code on the affected system with root privileges. IBM has issued an advisory. For more, go to:
https://www-1.ibm.com/support/docview.wss?uid=isg1IY67455
iDefense advisory:
https://www.nwfusion.com/go2/0207bug2b.html
**********
Debian patches emacs20, xemacs21
A vulnerability in the popular Emacs text editor could be exploited to run arbitrary code on the affected machine. The vulnerable machine would have to be connected to a POP server in order for this flaw to be exploited. Patches are available:
emacs20:
https://www.debian.org/security/2005/dsa-670
xemacs21:
https://www.debian.org/security/2005/dsa-671
Debian issues fix for php3
Two vulnerabilities that were found in PHP4 have also been found in PHP3. The flaws could be exploited in a cross-scripting attack and to potentially run malicious code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-669
**********
Mandrake Linux issues fix for perl
The rmtree() function in perl does not operate in a secure manner. An attacker could exploit the flaw to delete more than just the intended files. A patch is available:
https://www.nwfusion.com/go2/0207bug2c.html
**********
HP releases patch for ftpd on HP-UX
A buffer overflow in the FTP daemon for HP-UX could be exploited by a remote attacker to gain elevated privileges on the affected machine. Users should download wu-ftp Version 2.6 from the HP IT Resource Center:
https://www1.itrc.hp.com/service/index.html
HP patches Mozilla Suite for Tru64
A remotely exploitable denial-of-service vulnerability has been found in the Mozilla Application Suite Version 1.7.3 for HP’s Tru64 Unix. For more, go to:
https://www.nwfusion.com/go2/0207bug2d.html
**********
Gentoo releases pdftohtml patch
A vulnerability in the PDF viewer application Xpdf also impacts pdftohtml, a utility for converting PDF documents in to HTML. An attacker may exploit this to run their code of choice on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-10.xml
Gentoo releases patch for PostgreSQL
A flaw in the PostgreSQL database server could be exploited by a local user to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-08.xml
LessTif patch for Gentoo users
LessTif, an interface toolkit, is vulnerable to the same libXpm flaws as OpenMotif. An attacker could exploit this to run arbitrary code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-06.xml
Gentoo patches OpenMotif
A remote code execution vulnerability in libXpm also affects OpenMotif. There are multiple vulnerabilities that could be exploited including buffer overflows and memory boundary violations. For more, go to:
https://security.gentoo.org/glsa/glsa-200502-07.xml
Gentoo releases patch for Python
The Python development group has discovered a flaw in the SimpleXMLRPCServer library module. An attacker could use this to view object data and potentially execute malicious code. Gentoo Python implementations prior to 2.3.4 are affected by this vulnerability. For more, go to:http://security.gentoo.org/glsa/glsa-200502-09.xml
**********
Experts: International domain names may pose threat
Security experts are warning about a new threat to Web surfers: malicious Web sites that use international domain names to spoof the Web addresses of legitimate sites. The new trick is a variation of a known technique called the “homograph attack” and takes advantage of loopholes in the way some popular Web browsers display domain names that use non-English characters. It could allow malicious hackers and online identity theft groups to trick unsuspecting users into divulging sensitive personal information, according to advisories from The Shmoo Group, a hacker collective, and Secunia. IDG News Service, 02/07/05.
https://www.nwfusion.com/news/2005/0207experinter.html?nl
**********
SCO patches ‘enable’ command
A flaw in the ‘enable’ command-line command for OpenServer is vulnerable to multiple buffer overflows. An attacker could potentially gain elevated privileges. For more, go to:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.13
SCO patches Foomatic for UnixWare
According to an alert from SCO, “Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.” For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.12
SCO fixes multiple flaws in racoon
Several vulnerabilities have been patched in SCO’s racoon implementation for UnixWare. Racoon is daemon that sets parameters for IPSec sessions. A remote attacker could delete certificates and potentially gain unauthorized access to the affected machine. For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10
SCO patches TCP flaw in UnixWare, OpenServer
The way certain “long living” TCP connections, such as those used by Border Gateway Protocol (BGP), are handled by UnixWare and OpenServer could exploited in a Rose attack. This could be used to cause a denial-of-service. Patches are available:
UnixWare
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14
OpenServer:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9
**********
Today’s roundup of virus alerts:
W32/Rbot-VM – Yet another Rbot variant that spreads via network shares (exploiting known Windows vulnerabilities) and allowing backdoor access via IRC. It installs itself as “updates.exe” in the Windows System folder. (Sophos)
W32/Rbot-VO – This Rbot variant installs “WINGTP.EXE” in the Windows System folder. In addition to allowing backdoor access via IRC, it may also disable network shares. (Sophos)
W32/Rbot-ALO – This variant installs “npmsys.exe” in the Windows System folder. (Sophos)
W32/Agobot-PI – A worm that spreads via network shares, installing itself as “Ksrv32.exe” in the Windows System directory. It can be used for a number of malicious purposes, including stealing information and launching denial-of-service attacks. It also disables security-related applications running on the infected machine. (Sophos)
W32/Agobot-PN – Similar to Agobot-PI above, except this variant uses the file “BCVSRV32.EXE” as its infection point. (Sophos)
W32/Agobot-PQ – Similar to the above variants. This one installs “msjavx86.exe” on the infected machine. (Sophos)
W32/Sober-J – A new Sober mass mailing variant that uses the attachment “text.zip” to spread. (Sophos)
Troj/Chimo-A – A Trojan that installs a mail relay on the infected machine. It installs “hicom.exe” in the Windows System folder of the infected machine. (Sophos)




