No March madness for Microsoft

Opinion
Mar 7, 20054 mins

* Patches from Mandrake Linux, Gentoo, Conectiva, others * Beware "Christina Aquilera" VBS worm

Today’s bug patches and security alerts:

Microsoft says no new security patches this month

Microsoft does not plan to release any security bulletins or patches this month despite claims from IT security companies that flaws require fixing. IDG News Service, 03/04/05.

https://www.nwfusion.com/news/2005/0304microsays2.html?nl

**********

Mandrake Linux patches gftp

According to an advisory from Mandrake Linux, “A vulnerability in gftp could allow a malicious FTP server to overwrite files on the local system as the user running gftp due to improper handling of filenames containing slashes.” For more, go to:

https://www.nwfusion.com/go2/0307bug1a.html

New kdegraphics package from Mandrake Linux

A new kdegraphics package update fixes an integer overflow in the included xpdf code, which is used to display PDF files. For more, go to:

https://www.nwfusion.com/go2/0307bug1b.html

Mandrake Linux updates cyrus-imapd

A number of vulnerabilities have been fixed in Mandrake Linux’s implementation of cyrus-imapd. An attacker could exploit the flaws to run code with the permissions of the authenticated user. For more, go to:

https://www.nwfusion.com/go2/0307bug1c.html

Mandrake Linux patches gaim

A new update for gaim, an open source IM client, is available. The release fixes a number of bugs and security flaws. For more, go to:

https://www.nwfusion.com/go2/0307bug1d.html

Mandrake Linux releases curl fix

A buffer overflow in curl’s NTLM authorization base64 decoding could be exploited by an attacker to execute applications with the permissions of the user running curl. For more, go to:

https://www.nwfusion.com/go2/0307bug1e.html

**********

Gentoo issues Firefox update

This update to the popular Mozilla Firefox browser fixes a file deletion flaw and changes the way sites are handled, which previously could have been exploited to get users to visit fake sites. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-10.xml

Gentoo patches xv

XV, an image manipulation tool for X11, contains a format string vulnerability. This flaw could be exploited to run code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-09.xml

Gentoo patches OpenMotif, LessTif

The image-handling applications OpenMotif and LessTif are vulnerable to buffer overflows found in the common libXpm code. An attacker could exploit this to run malicious code on the affected machine. Patches are available:

https://security.gentoo.org/glsa/glsa-200503-08.xml

Gentoo issues fix for BidWatcher

BidWatcher, a tool for monitoring eBay auctions, contains a format string vulnerability, which could be exploited remotely by a faked eBay site. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-06.xml

**********

Conectiva patches ClamAV

A new update to Conectiva’s ClamAV implementation fixes a formatting issue with the way the application updates itself and a denial-of-service vulnerability. For more, go to:

https://www.nwfusion.com/go2/0307bug1f.html

**********

Today’s roundup of virus alerts:

VBS/Speery-A — A Visual Basic Script worm that spreads via e-mail, dropping “Christina_Aquilera.jpg.vbs” and “gsw332.exe.vbs” on the infected machine. The infected message is entitled “Tolong dong…” with attachments called “gsw332.rar” and “Christina_Aquilera.rar”. (Sophos)

W32/Agobot-QO — This IRC backdoor Trojan spreads via network shares and installs “IP.EXE” in the Windows System folder. It can prevent access to security Web sites by modifying the HOSTS file. (Sophos)

W32/Myfip-G / W32/Myfip-H — Similar worms that spread via network shares, drop “kernel32dll.exe” on the infected machine and can be used to mine data from the infected machine, sending what it finds to a pre-configured IP address. (Sophos)

W32/Rbot-WV — An Rbot variant that spreads through network shares by exploiting a number of known Windows vulnerabilities. It drops “P3.EXE” in the Windows System directory and can provide access to the infected machine via IRC. (Sophos)

W32/Rbot-WW — Similar to Rbot-WV above, except this variant uses “npprotect.exe” as its infection point, and the worm can be used to steal information or launch attacks against third parties. (Sophos)

W32/Wurmark-F — An e-mail worm that displays the file “uglym.jpg” on the infected machine. It spreads through an attachment called “attached.zip”. To see the image displayed, go here and click the “Advanced” tab:

https://www.sophos.com/virusinfo/analyses/w32wurmarkf.html

Troj/Goldun-O — A Trojan that looks for HTTP traffic going to banking sites and attempts to extract account information. It drops “csrss.dll” on the infected machine. (Sophos)

Dampig.A — A new worm that attempts to infect the Symbian mobile operating system. It spreads through an infected SIS file and can disable third-party applications. If it’s like Cabir, it takes some doing on the user’s part to actually get infected. (F-Secure)

**********