* Patches from Debian, Gentoo, Mandrake Linux others * Beware latest backdoor viruses
Today’s bug patches and security alerts:
Debian releases patch for mailman
User input into the mailman mailing list server is not properly checked, which could result in information being disclosed. This is a new release that “really” fixes the problem. For more, go to:
https://www.debian.org/security/2005/dsa-674
Debian patches toolchain
Toolchain, a library of code and scripts, creates insecure temporary files that could be exploited in a symlink attack. An attacker exploiting this could overwrite arbitrary files on the affected system. For more, go to:
https://www.debian.org/security/2005/dsa-679
Debian issues fix for synaesthesia
A flaw in synaesthesia, a tool for representing sound visually, could be exploited to read arbitrary files on the affected machine. A patch is available:
https://www.debian.org/security/2005/dsa-681
Debian releases update for typespeed
A bug in Typespeed, a game for teaching touch typing, could be exploited to run arbitrary code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-684
Debian patches emacs21
A vulnerability in the popular Emacs text editor could be exploited to run arbitrary code on the affected machine. The vulnerable machine would have to be connected to a POP server in order for this flaw to be exploited. For more, go to:
https://www.debian.org/security/2005/dsa-685
Debian fixes bug in bidwatcher
Bidwatcher, a tool for monitoring eBay auctions, contains a format string vulnerability, which could be exploited remotely by a faked eBay site. For more, go to:
https://www.debian.org/security/2005/dsa-687
**********
Debian, Gentoo patch gftp
A directory traversal vulnerability has been found in gftp. A malicious user could exploit this to overwrite files on the affected machine. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-686
Gentoo:
https://security.gentoo.org/glsa/glsa-200502-27.xml
**********
Mandrake Linux patches postgresql
Several buffer overflow flaws, which could be exploited to run arbitrary code, have been patched in the postgresql database application. For more, go to:
https://www.nwfusion.com/go2/0221bug1a.html
Mandrake Linux updates xpdf, gpdf, cups and tetex
A integer overflow in xpdf could impact gpdf, cups and tetex. A previous patch for this issue did not address 64-bit systems. For more, go to:
xpdf:
https://www.nwfusion.com/go2/0221bug1b.html
gpdf:
https://www.nwfusion.com/go2/0221bug1c.html
cups:
https://www.nwfusion.com/go2/0221bug1d.html
tetex:
https://www.nwfusion.com/go2/0221bug1e.html
Mandrake Linux releases update for rwho
A vulnerability in rwho could be exploited by a remote user to crash the rwho listening process. For more, go to:
https://www.nwfusion.com/go2/0221bug1f.html
Mandrake Linux patches kdelibs
According to an alert from Mandrake Linux, “A bug in the way kioslave handles URL-encoded newline (%0a) characters before the FTP command was discovered. Because of this, it is possible that a specially crafted URL could be used to execute any ftp command on a remote server, or even send unsolicited email.” For more, go to:
https://www.nwfusion.com/go2/0221bug1g.html
**********
KDE warns of flaw in fliccd
A buffer overflow in the KDE fliccd code and could be exploited to gain root privileges. For more, go to:
https://www.kde.org/info/security/advisory-20050215-1.txt
**********
HP warns of vulnerability in Web-based management software
According to an alert from HP, “A potential remotely exploitable buffer overflow vulnerability has been identified in the HP HTTP Server component of the HP Web-enabled Management Software. The potential vulnerability could result in a denial of service condition or in the execution of privileged code.” For more, go to:
https://www.nwfusion.com/go2/0221bug1h.html
**********
Today’s roundup of virus alerts:
W32/Sdbot-VH — An IRC backdoor worm variant that spreads via network shares and drops “svhost.exe” in the Windows System folder. It can be used for a number of malicious functions. (Sophos)
W32/Poebot-A — A backdoor virus that allows backdoor access via IRC. It drops “lssas.exe” in the Windows System directory. No word on what functions can be controlled through IRC. (Sophos)
W32/Poebot-H — Very similar to Poebot-A above, down to the same file used for infecting a machine. (Sophos)
W32/Rbot-WB — An Rbot variant that can be used to run DoS attacks, send spend, act as a proxy and more. It drops “winmep.exe” in the Windows System folder after spreading via network shares. (Sophos)
W32/Rbot-WF — Another Rbot variant that spreads through network shares by exploiting a number of known Windows vulnerabilities. This version drops “SVCHOSTdll.exe” in the infected machine’s Windows System folder. (Sophos)
W32/Kipis-I — This worm spreads via e-mail that looks like a Valentine. Once installed on the infected machine, it opens port 1988 to listen for commands. (Sophos)
W32/MyDoom-AS — Another MyDoom variant that spreads via e-mail using a number of message characteristics. All infected attachments will have an extension of pif, scr, exe, cmd, bat or zip, most of which should be stripped before they reach the end user. It causes the usual round of nastiness on the infected machine. (Sophos)
Troj/Lineage-D — A keystroke logger that installs itself as “ttplorer.exe” in the Windows System folder. Not sure how it spreads, but I am guessing through network shares. (Sophos)
W32/Assiral-A — An e-mail worm that spreads via a message entitled “Re: Lov YA” and has an attachment called “LOVE_LETTER.TXT.exe”. It will disable administration functions in Windows. (Sophos)




