Microsoft’s monthly patch bonanza

Opinion
Feb 10, 20058 mins

* Patches from Microsoft, Symantec, Debian, others * Beware new Sober mass mailing variant that spreads via "text.zip" attachment

Today’s bug patches and security alerts:

Microsoft releases 12 patches for 16 vulnerabilities

Microsoft provided fixes for almost every supported version of Windows, including the recently updated Windows XP Service Pack 2, and patches for holes in everything from critical Windows components to the Internet Explorer Web browser and MSN Messenger IM application. IDG News Service, 02/08/05.

https://www.nwfusion.com/news/2005/0208microrelea.html?nl

For more, go to:

Microsoft advisories:

MS05-004: ASP.NET Path Validation Vulnerability:

https://www.microsoft.com/technet/security/Bulletin/MS05-004.mspx

MS05-005: Vulnerability in Microsoft Office XP could lead to Buffer Overrun:

https://www.microsoft.com/technet/security/Bulletin/MS05-005.mspx

MS05-006: Vulnerability in Windows SharePoint Services and SharePoint Team Services Could Allow Cross-Site Scripting and Spoofing Attacks:

https://www.microsoft.com/technet/security/Bulletin/MS05-006.mspx

MS05-007: Vulnerability in Windows Could Allow Information Disclosure:

https://www.microsoft.com/technet/security/Bulletin/MS05-007.mspx

MS05-008: Vulnerability in Windows Shell Could Allow Remote Code Execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-008.mspx

MS05-009: Vulnerability in PNG Processing Could Lead to Buffer Overrun:

https://www.microsoft.com/technet/security/Bulletin/MS05-009.mspx

MS05-010: Vulnerability in the License Logging Service Could Allow Code Execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-010.mspx

MS05-011: Vulnerability in Server Message Block Could Allow Remote Code Execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-011.mspx

MS05-012: Vulnerability in OLE and COM Could Allow Remote Code Execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-012.mspx

MS05-013: Vulnerability in the DHTML Editing ActiveX Control could allow code execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-013.mspx

MS05-014: Cumulative Security Update for Internet Explorer:

https://www.microsoft.com/technet/security/Bulletin/MS05-014.mspx

MS05-015: Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution:

https://www.microsoft.com/technet/security/Bulletin/MS05-015.mspx

CERT advisory:

https://www.cert.org/advisories/CA-2000-02.html

ISS alert:

https://xforce.iss.net/xforce/alerts/id/186

EEye advisory (for SMB Client):

https://www.eeye.com/html/research/advisories/AD20050208.html

**********

Symantec patches flaw in virus scanning module

A flaw in Symantec’s older virus scanning module used for scanning UPX compressed files could be exploited by an attacker to pass a virus through the system. Some version of Symantec’s products still use this module. For more, go to:

https://www.symantec.com/avcenter/security/Content/2005.02.08.html

**********

Cisco warns of SNMP flaw in video products

According to an alert from Cisco, “Hard-coded Simple Network Management Protocol (SNMP) community strings are present in Cisco IP/VC Videoconferencing System models 3510, 3520, 3525 and 3530. Any user who has access to the vulnerable devices and knows the community strings, can obtain total control of the device.” For more, go to:

https://www.cisco.com/warp/public/707/cisco-sa-20050202-ipvc.shtml

**********

iDefense issues advisory for AIX’s auditselect

A format string vulnerability in auditselect for a AIX could be exploited to write to arbitrary memory location. Auditselect is installed with root privileges. For more, go to:

https://www-1.ibm.com/support/docview.wss?uid=isg1IY67519

iDefense advisory:

https://www.nwfusion.com/go2/0207bug2a.html

**********

iDefense warns of flaw in chdev for AIX

A buffer overflow in the chdev command included with IBM AIX operating system could be exploited by a local user to run malicious code on the affected system with root privileges. IBM has issued an advisory. For more, go to:

https://www-1.ibm.com/support/docview.wss?uid=isg1IY67455

iDefense advisory:

https://www.nwfusion.com/go2/0207bug2b.html

**********

Debian patches emacs20, xemacs21

A vulnerability in the popular Emacs text editor could be exploited to run arbitrary code on the affected machine. The vulnerable machine would have to be connected to a POP server in order for this flaw to be exploited. Patches are available:

emacs20:

https://www.debian.org/security/2005/dsa-670

xemacs21:

https://www.debian.org/security/2005/dsa-671

Debian issues fix for php3

Two vulnerabilities that were found in PHP4 have also been found in PHP3. The flaws could be exploited in a cross-scripting attack and to potentially run malicious code on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-669

**********

Mandrake Linux issues fix for perl

The rmtree() function in perl does not operate in a secure manner. An attacker could exploit the flaw to delete more than just the intended files. A patch is available:

https://www.nwfusion.com/go2/0207bug2c.html

**********

HP releases patch for ftpd on HP-UX

A buffer overflow in the FTP daemon for HP-UX could be exploited by a remote attacker to gain elevated privileges on the affected machine. Users should download wu-ftp Version 2.6 from the HP IT Resource Center:

https://www1.itrc.hp.com/service/index.html

HP patches Mozilla Suite for Tru64

A remotely exploitable denial-of-service vulnerability has been found in the Mozilla Application Suite Version 1.7.3 for HP’s Tru64 Unix. For more, go to:

https://www.nwfusion.com/go2/0207bug2d.html

**********

Gentoo releases pdftohtml patch

A vulnerability in the PDF viewer application Xpdf also impacts pdftohtml, a utility for converting PDF documents in to HTML. An attacker may exploit this to run their code of choice on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-10.xml

Gentoo releases patch for PostgreSQL

A flaw in the PostgreSQL database server could be exploited by a local user to run malicious code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-08.xml

LessTif patch for Gentoo users

LessTif, an interface toolkit, is vulnerable to the same libXpm flaws as OpenMotif. An attacker could exploit this to run arbitrary code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-06.xml

Gentoo patches OpenMotif

A remote code execution vulnerability in libXpm also affects OpenMotif. There are multiple vulnerabilities that could be exploited including buffer overflows and memory boundary violations. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-07.xml

Gentoo releases patch for Python

The Python development group has discovered a flaw in the SimpleXMLRPCServer library module. An attacker could use this to view object data and potentially execute malicious code. Gentoo Python implementations prior to 2.3.4 are affected by this vulnerability. For more, go to:http://security.gentoo.org/glsa/glsa-200502-09.xml

**********

Experts: International domain names may pose threat

Security experts are warning about a new threat to Web surfers: malicious Web sites that use international domain names to spoof the Web addresses of legitimate sites. The new trick is a variation of a known technique called the “homograph attack” and takes advantage of loopholes in the way some popular Web browsers display domain names that use non-English characters. It could allow malicious hackers and online identity theft groups to trick unsuspecting users into divulging sensitive personal information, according to advisories from The Shmoo Group, a hacker collective, and Secunia. IDG News Service, 02/07/05.

https://www.nwfusion.com/news/2005/0207experinter.html?nl

**********

SCO patches ‘enable’ command

A flaw in the ‘enable’ command-line command for OpenServer is vulnerable to multiple buffer overflows. An attacker could potentially gain elevated privileges. For more, go to:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.13

SCO patches Foomatic for UnixWare

According to an alert from SCO, “Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.” For more, go to:

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.12

SCO fixes multiple flaws in racoon

Several vulnerabilities have been patched in SCO’s racoon implementation for UnixWare. Racoon is daemon that sets parameters for IPSec sessions. A remote attacker could delete certificates and potentially gain unauthorized access to the affected machine. For more, go to:

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10

SCO patches TCP flaw in UnixWare, OpenServer

The way certain “long living” TCP connections, such as those used by Border Gateway Protocol (BGP), are handled by UnixWare and OpenServer could exploited in a Rose attack. This could be used to cause a denial-of-service. Patches are available:

UnixWare

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14

OpenServer:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9

**********

Today’s roundup of virus alerts:

W32/Rbot-VM – Yet another Rbot variant that spreads via network shares (exploiting known Windows vulnerabilities) and allowing backdoor access via IRC. It installs itself as “updates.exe” in the Windows System folder. (Sophos)

W32/Rbot-VO – This Rbot variant installs “WINGTP.EXE” in the Windows System folder. In addition to allowing backdoor access via IRC, it may also disable network shares. (Sophos)

W32/Rbot-ALO – This variant installs “npmsys.exe” in the Windows System folder. (Sophos)

W32/Agobot-PI – A worm that spreads via network shares, installing itself as “Ksrv32.exe” in the Windows System directory. It can be used for a number of malicious purposes, including stealing information and launching denial-of-service attacks. It also disables security-related applications running on the infected machine. (Sophos)

W32/Agobot-PN – Similar to Agobot-PI above, except this variant uses the file “BCVSRV32.EXE” as its infection point. (Sophos)

W32/Agobot-PQ – Similar to the above variants. This one installs “msjavx86.exe” on the infected machine. (Sophos)

W32/Sober-J – A new Sober mass mailing variant that uses the attachment “text.zip” to spread. (Sophos)

Troj/Chimo-A – A Trojan that installs a mail relay on the infected machine. It installs “hicom.exe” in the Windows System folder of the infected machine. (Sophos)