Experts warn of CA License Manager flaw

Opinion
Mar 3, 20056 mins

* Patches from CA, Trend Micro, HP, others * New Bagle variant on the loose

Today’s bug patches and security alerts:

Experts warn of CA License Manager flaw

Experts at EEye and iDefense are warning of flaws in the Computer Associates License Manager software, which is installed by default in a number of CA applications. The licensing protocol does not properly accept incoming text. This could be exploited to run commands on the affected machine. A fix is available from CA:

https://www.nwfusion.com/go2/0228bug2a.html

**********

ISS warns of overflow in TrendMicro anti-virus

A heap overflow in the process used to import the Trend Micro anti-virus libraries could be exploited to compromise the affected machine, according to a warning from ISS. Trend Micro has released a patch for this problem:

https://www.nwfusion.com/go2/0228bug2b.html

ISS advisory:

https://xforce.iss.net/xforce/alerts/id/189

**********

HP patches OpenVMS

According to an alert from HP, “A potential security vulnerability has been identified with HP OpenVMS VAX Version 7.x and 6.x and OpenVMS Alpha Version 7.x or 6.x that may allow a local authorized user to gain unauthorized privileged access to data and system resources.” A fix is available via the HP IT Resource Center:

https://www2.itrc.hp.com/service/cki/enterService.do

**********

Gentoo patches xli, xloadimage

Multiple security vulnerabilities have been found in the xli and xloadimage image handling applications. An attacker could exploit some of the flaws to run malicious code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-05.xml

Gentoo releases patch for phpWebSite

Gentoo has released a patch for phpWebSite, a content management system. A remote attacker could exploit flaws in older versions to upload and execute arbitrary code on an affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-04.xml

Gentoo issues fix for gaim

A new update for gaim, an open source IM client, is available. The release fixes a number of bugs and security flaws. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-03.xml

Gentoo releases fix for phpBB

According to an alert from Gentoo, “Several vulnerabilities allow remote attackers to gain phpBB administrator rights or expose and manipulate sensitive data.” A fix is available:

https://security.gentoo.org/glsa/glsa-200503-02.xml

Gentoo releases fix for qt

A vulnerability in the qt GUI toolkit for Gentoo may be exploited to load non-trusted libraries onto the affected system. This could lead to malicious code being executed. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-01.xml

Gentoo patches MediaWiki

MediaWiki, a collaborative editing tool in the mold of Wikipedia, is vulnerable to a cross-scripting attack, which could be exploited to view restricted information on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200502-33.xml

**********

NGSSoftware warns of RealPlayer vulnerability

A flaw in the way the RealPlayer media client handles WAV files could result in an exploitable heap overflow. NGSSoftware, which discovered the issue, is not releasing details for three months to allow time for patches to propagate. An update is available from Real:

https://service.real.com/help/faq/security/050224_player

**********

SCO releases fix for TCP

If a large Window size is used in a TCP configuration, it makes it easier for attackers to guess the numbering sequence. This could be exploited in a denial-of-service attack against the affected machine. An update is available:

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3

**********

KDE issues fix for kppp

A flaw in kppp, if installed with root privileges, could be exploited to hijack a system’s domain name resolution function. For more, go to:

https://www.kde.org/info/security/advisory-20050228-1.txt

**********

Fedora Legacy updates XFree86

Multiple security vulnerabilities have been found in the Xfree86 X-Windows system for the Fedora Legacy Core. For more, go to:

https://bugzilla.fedora.us/show_bug.cgi?id=2314

**********

Conectiva patches mod_python

An information leak has been found in the publisher handle in mod_python. An attacker could exploit this via a specially crafted URL. A fix is available:

https://www.nwfusion.com/go2/0228bug2c.html

**********

Today’s roundup of virus alerts:

New Bagle variant combines spam, Trojans

Anti-virus software companies are warning their customers about the appearance of at least one new version of the Bagle worm that doesn’t try to spread, but installs malicious remote monitoring software on systems it infects. IDG News Service, 03/01/05.

https://www.nwfusion.com/news/2005/0301newbagle.html?nl

W32/Rbot-UC — A new backdoor variant that provides backdoor access via IRC. It spreads via network shares by exploiting a number of well-known Windows vulnerabilities. It drops “msdiag32.exe” on the infected machine and can be used for a number of malicious purposes. (Sophos)

W32/Bropia-S — Another Bropia variant that tries to spreads through MSN Messenger using the files “bot.exe” and “botz.exe”. It drops “doit.exe” in the Windows System folder and displays a non-English message on the screen. (Sophos)

W32/MyDoom-BG — A new MyDoom e-mail worm variant that offers backdoor access via IRC. This version drops “wfdmgr.exe” on the infected machine. (Sophos)

W32/Forbot-CW — This Forbot variant installs “scman.exe” in the Windows System directory of the infected machine. It provides backdoor access by logging on to a predefined IRC server. (Sophos)

W32/Agobot-QL — A new Agobot network worm that drops “IEXPL0RER.EXE” (note it’s a zero, not a letter) in the infected machine’s Windows System folder. In addition to providing backdoor access via IRC, this virus limits access to security-related Web sites by modifying the Windows HOSTS file. (Sophos)

W32/Agobot-OV — This Agobot variant can carry out multiple tasks after infecting a machine via a weakly protected network share. It can be used a launching point for a number of attacks, steal information and limit security resources. It installs “nksvc32.exe” in the Windows System folder. (Sophos)

Troj/Kelebek-G — A Trojan that spreads via network shares and allows backdoor access via IRC. It drops a number of DLL files to the infected machine. (Sophos)

W32/Mytob-C — A Trojan that exploits the Windows LSASS vulnerability as it spreads through network shares. It installs “wfdmgr.exe” in the Windows System directory. (Sophos)

W32/Assiral-B — A mass-mailing worm that spreads with the spoofed ‘from’ address of “MSLarissa@Admin.com“. It appears to contain a message to the Bropia virus author. (Sophos)

Mitglieder.BO  — This Trojan attempts to disable security applications on the infected machine. Every six hours it attempts to download code from different Web sites. It drops “WINSHOST.EXE” on the infected system as well. (Panda Software)

W32/Francette-Q — A keylogging Trojan that exploits the Windows RPC-DCOM vulnerability to spread. It overwrites the Windows HOSTS file to redirect traffic to a handful of sites. (Sophos)