Apple releases fix for Java

Opinion
Feb 24, 20056 mins

* Patches from Gentoo, Fedora, others * Beware virus being distributed in fake FBI e-mail

Today’s bug patches and security alerts:

Apple releases fix for Java

A flaw in the way untrusted Java applets are handled by the Mac OS X Java plug-in could be exploited to gain elevated privileges on the affected machine. Upgrading to Java 1.4.2 fixes the problem:

https://docs.info.apple.com/article.html?artnum=300980

**********

Gentoo patches PuTTY

PuTTY, an SSH client, contains a remotely exploitable flaw that could be used to run malicious code on the affected machine. A patch is available from Gentoo:

https://security.gentoo.org/glsa/glsa-200502-28.xml

Gentoo patches GProFTPD

One of the commands in GProFTPD contains a format string vulnerability. This could be exploited to run code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-26.xml

Gentoo issues fix for Midnight Commander

A number of overflow vulnerabilities have been found in Midnight Commander, a file manager system for Gentoo. The flaws could be exploited to run arbitrary code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-24.xml

Gentoo updataes KStars

A buffer overflow in KStars for Gentoo could be exploited to run malicious code on the affected system. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-23.xml

Gentoo patches wpa_supplicant

A buffer overflow in Gentoo’s wpa_supplicant, which is used in support of wireless client authentication, could be be exploited in a denial-of-service attack. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-22.xml

Gentoo issues patch for lighttpd

A flaw in lighttpd, a lightweight Web server, could be exploited to reveal the source of scripts running on the affected server. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-21.xml

Gentoo releases fix for VMware Workstation

According to an alert from Gentoo, “VMware may load shared libraries from an untrusted, world-writable directory, resulting in the execution of arbitrary code.” For more, go to:

https://security.gentoo.org/glsa/glsa-200502-21.xml

Gentoo releases Opera update

The Opera browser contains several vulnerabilities that could be exploited to run malicious code on the affected machine. A patch is available for Gentoo users. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-17.xml

Gentoo patches PowerDNS

A denial-of-service vulnerability has been found in PowerDNS, an DNS nameserver. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-15.xml

**********

Fedora, Gentoo patch cyrus-sasl

According to an alert from the Fedora Core team, “The Cyrus IMAP Server is affected by several overflow vulnerabilities which could potentially lead to the remote execution of arbitrary code.” For more, go to:

Fedora:

https://bugzilla.fedora.us/show_bug.cgi?id=2137

Gentoo:

https://security.gentoo.org/glsa/glsa-200502-29.xml

**********

Fedora Legacy updates cdrtools

A privilege escalation vulnerability has been found in cdrtools for older versions of Red Hat Linux. For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=2058

Sox patch for Fedora Legacy users

A buffer overflow exists in the way WAV file headers are processed by Sox. This could be exploited to run arbitrary code on the affected Red Hat Linux system. For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=1945

Fedora patches GNOME VFS

A bug in the GNOME VFS implementation for Red Hat Linux, which has several scripts that could be exploited in an attack. For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=1944

**********

Debian, Gentoo release fix for squid

A denial-of-service vulnerability has been found in the open source squid proxy. Patches are available:

Debian:

https://www.debian.org/security/2005/dsa-688

Gentoo:

https://security.gentoo.org/glsa/glsa-200502-25.xml

**********

Debian, Gentoo patch mod_python

An information leak has been found in the publisher handle in mod_python. An attacker could exploit this via a specially crafted URL. Patches are available:

Debian:

https://www.debian.org/security/2005/dsa-689

Gentoo:

https://security.gentoo.org/glsa/glsa-200502-14.xml

**********

Today’s roundup of virus alerts:

New virus being distributed in fake FBI e-mail

A fake e-mail that purports to be from the FBI is circulating on the Internet with a computer virus as its payload. Computerworld, 02/23/05.

https://www.nwfusion.com/news/2005/0223newvirus.html

F-Secure advisory:

https://www.europe.f-secure.com/v-descs/sober_k.shtml

W32/Sober.M – Another Sober virus that spreads via e-mail, pretending to offer Paris Hilton photos and videos. It displays a fake Winsock error as it infects the machine. (Sophos)

W32/Derdero-A – A worm that spreads via e-mail and peer-to-peer networks. It drops “SysHeal.exe” and “thunk32.exe” on the infected machine and usually spreads through an attachment with an extension of zip, scr, pif, cmd, exe, doc.pif, txt.exe, or bmp.cmd. (Sophos)

W32/Forbot-EG – Another Forbot variant that uses IRC for backdoor access and spreads through network shares. It drops “snapple.exe” in the Windows System folder and can be used for a number of malicious purposes. (Sophos)

W32/MyDoom-BE – The new MyDoom variant drops “services.exe” on the infected machine after spreading via e-mail. It too tries to ping various search engines in a quest to find more target e-mail. (Sophos)

W32/Bropia-P – A Windows Messenger worm that displays a photo of a naked woman on the infected machine. It also drops the file “winis.exe” in the Windows System folder. (Sophos)

W32/Bropia-Q – A new Bropia variant that tries to download bot.exe from a remote source. (Sophos)

W32/Bropia-R – Another Bropia variant that spreads through MSN Messenger and drops three files on the infected machine “game.exe”, “ms64.exe”, and “loud.exe”. All are basically backdoor Trojans. (Sophos)

W32/Sdbot-VL – An Sdbot variant that spreads through a file called “KERENEBO.EXE” and drops “UWANAH.EXE” in the Windows System folder. It can allow backdoor access via IRC. (Sophos)

W32/Domwis-G – A backdoor Trojan (IRC) that runs out of the file “SYSCFG16.EXE”. It can be used in DoS attacks against third parties. (Sophos)

W32/Sdranck-A – A worm that spreads through networks shares and drops two files on the infected machine: “DAQUWU32.EXE” and G58S2A1.EXE”. One of the files help propagate the worm, the other in an Sdbot variant. (Sophos)