IBM releases patch for DB2

Opinion
Feb 14, 20058 mins

* Patches from IBM, CA, HP, others * Beware latest Rbot variants

Today’s bug patches and security alerts:

IBM releases patch for DB2

IBM released Fixpak 8 for its DB2 Universal Database Version 8.1 and earlier. NGSSoftware discovered the “high-risk” vulnerability but is not released detailed information for three months. For more, go to:

https://www.nwfusion.com/go2/0214bug1a.html

NGSSoftware advisory:

https://www.ngssoftware.com/advisories/db2-09-05-05.htm

iDefense warns of three IBM AIX flaws

iDefense has issued advisories about three flaws in IBM AIX that affect ipl_varyon, lspath and netpmon. All three flaws are of the buffer overflow variety and could be exploited to gain elevated privileges or execute malicious code. Patches are available:

AIX 5.1:

https://www.nwfusion.com/go2/0214bug1b.html

AIX 5.2:

https://www.nwfusion.com/go2/0214bug1c.html

AIX 5.3:

https://www.nwfusion.com/go2/0214bug1d.html

iDefense advisories:

ipl_varyon:

https://www.nwfusion.com/go2/0214bug1e.html

lspath:

https://www.nwfusion.com/go2/0214bug1f.html

netpmon:

https://www.nwfusion.com/go2/0214bug1g.html

**********

CA releases patch for BrightStor ARCserve Backup v11 Discovery Service

According to an advisory from iDefense, “Remote exploitation of a buffer overflow vulnerability in Computer Associates International Inc’s BrightStor ARCserve Backup v11 Discovery Service may allow execution of arbitrary code.” A patch is available:

https://www.nwfusion.com/go2/0214bug1h.html

iDefense advisory:

https://www.nwfusion.com/go2/0214bug1i.html

**********

HP patches BIND for HP-UX

A denial-of-service vulnerability has been found in the BIND name service for HP-UX. The flaw could be exploited by a remote user to crash the affected system. For more, go to:

https://www.nwfusion.com/go2/0214bug1j.html

**********

Debian patches Evolution

Evolution, a groupware application, contains a heap overflow that could be exploited to gain elevated privileges and execute any code. For more, go to:

https://www.debian.org/security/2005/dsa-673

Debian releases fix for xview

A number of buffer overflow flaws have been found in xview, which could be exploited to run malicious code on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-672

Debian updates hztty

According to a Debian advisory, “Erik Sjölund discovered that hztty, a converter for GB, Big5 and zW/HZ Chinese encodings in a tty session, can be triggered to execute arbitrary commands with group utmp privileges.” For more, go to:

https://www.debian.org/security/2005/dsa-675

Debian patches xpcd

A buffer overflow in xpcd, an SVGA PhotoCD viewer for Linux, could be exploited to run arbitrary code on the affected machine with elevated privileges. For more, go to:

https://www.debian.org/security/2005/dsa-676

Debian issues sympa fix

A buffer overflow in the one the scripts used by sympa, a mailing list manager, could be exploited to run arbitrary code on the affected machine. Debian has released a patch for the problem:

https://www.debian.org/security/2005/dsa-677

Debian releases patch for netkit-rwho

A vulnerability in the rwhod program that comes with netkit-rwho could be exploited to crash the “listening” service. For more, go to:

https://www.debian.org/security/2005/dsa-678

**********

Fedora patches abiword

According the Fedora advisory, “A buffer overflow in the wv library included in abiword allows remote attackers to execute arbitrary code via a document with a long DateTime field.” For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=1906

Fedora issues fix for libpng

A number of buffer overflow vulnerabilities have been found in libpng, a PNG image handling application. An attacker could exploit this to run malicious code on the affected machine. For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=1943

Fedora releases fix for iptables

According to an advisory from Fedora, “Under certain conditions, iptables did not properly load the required modules at system startup, which caused the firewall rules to fail to load and protect the system from remote attackers.” For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=2252

Fedora updates gaim

A new update for gaim, an open source IM client, is available. The release fixes a number of bugs and security flaws.

https://bugzilla.fedora.us/show_bug.cgi?id=2188

Fedora updates PDF viewers

Various PDF document viewers for the Fedora core contain multiple overflow vulnerabilities, which could be exploited to run malicious code on the affected machines. Patches are available:

Xpdf:

https://bugzilla.fedora.us/show_bug.cgi?id=2352

gpdf:

https://bugzilla.fedora.us/show_bug.cgi?id=2353

**********

Gentoo releases Perl update

According to an advisory from Gentoo, “Vulnerabilities leading to file overwriting and code execution with elevated privileges have been discovered in the perl-suid wrapper.” For more, go to:

https://security.gentoo.org/glsa/glsa-200502-13.xml

Gentoo fixes Webmin

A vulnerability in Gentoo’s Webmin implementation may result in the encrypted root password being disclosed. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-12.xml

**********

Debian, Gentoo patch Mailman

User input into the mailman mailing list server is not properly checked, which could result in information being disclosed. Patches are available:

Debian:

https://www.debian.org/security/2005/dsa-674

Gentoo:

https://security.gentoo.org/glsa/glsa-200502-11.xml

**********

Mandrake Linux releases MySQL fix

A flaw in the way temporary files are created by the MySQL mysqlaccess script could be exploited by a non-privileged user to overwrite any file on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0214bug1k.html

Mandrake Linux patches Python

The Python development group has discovered a flaw in the SimpleXMLRPCServer library module. An attacker could use this to view object data and potentially execute malicious code. Gentoo Python implementations prior to 2.3.4 are affected by this vulnerability. For more, go to:

https://www.nwfusion.com/go2/0214bug1l.html

Mandrake Linux patches enscript

Multiple vulnerabilities have been found in enscript, a tool for converting ASCII to PostScript. Two of the flaws could be exploited to run malicious code on the affected machine. A third could be used to crash the machine. A patch is available:

https://www.nwfusion.com/go2/0214bug1m.html

Mandrake Linux issues fix for cpio

The archive utility cpio could create files with permissions that make them easily overwritable by an attacker. A patch is available:

https://www.nwfusion.com/go2/0214bug1n.html

**********

Mandrake Linux, SuSE patch squid

Multiple vulnerabilities have been found in squid, an open source proxy server. The flaws could be used in a denial-of-service attacks or to potentially run arbitrary code on the affected machine. Patches are available:

Mandrake Linux:

https://www.nwfusion.com/go2/0214bug1o.html

SuSE:

https://www.novell.com/linux/security/advisories/2005_06_squid.html

**********

Trustix releases “multi” patch

A new update from Trustix fixes vulnerabilities in bind, clamav, cpio, cups, mod_python, perl, postgresql, python and squid. The most serious of these could be exploited to run malicious code on the affected machine.

https://www.trustix.org/errata/2005/0003/

**********

ZoneAlarm patches Inter-Process Communication functions

A flaw in the Inter-Process Communication (IPC) functions in the ZoneAlarm family of products and Check Point Integrity has been patched. A local user could exploit the flaw to cause a system lock. For more, go to:

https://download.zonelabs.com/bin/free/securityAlert/19.html

**********

Today’s roundup of virus alerts:

W32/Agobot-PQ – An Agobot variant that installs itself as “msjavx86.exe” in the Windows System directory after spreading via weakly protected network shares. It can be used for a number of malicious purposes and limit security applications. (Sophos)

W32/Agobot-PR – This Agobot variant exploits a number of known Windows vulnerabilities as it attempts to spread through network shares. It drops “Srv325.exe” in the Windows System folder and can be used for a number of malicious purposes. (Sophos)

W32/Rbot-VQ – A backdoor Trojan that exploits a number of known Windows vulnerabilities as it spreads via network shares. This variant installs “services33.exe” in the Windows System folder and can be used a proxy. (Sophos)

W32/Rbot-VT – The Vermont Rbot variant. Similar to Rbot-VQ above, except this one uses “wm1exe.exe” as its infection point in the Windows System directory. (Sophos)

W32/Rbot-TF – Another Rbot backdoor that can be used for a number of malicious purposes. This one drops “wuaruclt.exe” in the Windows System folder. (Sophos)

W32/Rbot-VX – Our fourth Rbot variant of the day has very similar characteristics to its predecessors, except for the file it drops: “crtl.exe”. (Sophos)

W32/Sdbot-UW – Another bot that provided backdoor IRC access to the infected machine after spreading through a network share. Sdbot-UW drops “XUDEXOLI.EXE” in the Windows System directory. (Sophos)

VBS/Mcon-G – A Visual Basic Script worm that drops “ttfload.vbs” in all folders with “startup” in the name. It can spreads through network shares or IRC channels. (Sophos)