* Patches from Novell, IBM, Mandrake Linux, others * Beware latest slew of Rbot variants
Today’s bug patches and security alerts:
Novell patches Netware vulnerability
A flaw in Novell’s xvesa code could be exploited to gain access to a Netware Xwindows session without authentication. Novell has issued a patch for the issue. For more, go to:
NetWare 6.5 SP2:
https://www.nwfusion.com/go2/0321bug1a.html
Security Tracker advisory:
https://www.securitytracker.com/alerts/2005/Mar/1013460.html
**********
IBM fixes WebSphere Commerce flaw
Flaws in IBM’s WebSphere Commerce could be exploited to view confidential information. A patch is available:
https://www-1.ibm.com/support/docview.wss?uid=swg21199839
**********
Michal Zalewski warns of Linux handling flaws
According to an alert from security guru Michal Zalewski, “There appears to be a fair number of kernel-level range checking flaws in ISO9660 filesystem handler (and Rock Ridge / Juliet extensions) in Linux up to and including 2.6.11. These bugs range from DoS conditions to potentially exploitable memory corruption – all this whenever a specially crafted filesystem is mounted or directories are examined.” Zalewski says such flaws may exist in other operating systems as well.
https://www.nwfusion.com/go2/0321bug1b.html
**********
Gentoo, Mandrake Linux patch KDE
A vulnerability in KDE’s DCOP function could be exploited in a denial of service attack against the affected machine. It looks as if only a local user can exploit the flaw. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200503-22.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0321bug1c.html
**********
Conectiva releases update for cyrus-imapd
According to Conectiva’s advisory, “Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via an off-by-one error in the imapd annotate extension, an off-by-one error in cached header handling a stack-based buffer overflow in fetchnews, or a stack-based buffer overflow in imapd.” For more, go to:
https://www.nwfusion.com/go2/0321bug1d.html
**********
Gentoo issues fix for Grip
A flaw in Grip, a CD player/ripper, could be exploited to run malicious code on the affected machine. To exploit the flaw, the client has to be given a large CDDB response. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-21.xml
**********
Mandrake Linux patches evolution
A flaw in evolution, a mail client, could cause the application to crash if certain message types are received. A patch is available:
https://www.nwfusion.com/go2/0321bug1e.html
**********
Today’s roundup of virus alerts:
Troj/BagDl-Gen – A family of worms that drop malicious DLL files on the target system and limit access to security-related Web sites. (Sophos)
W32/Rbot-YB – An Rbot variant that spreads via network shares by exploiting a number of known Windows vulnerabilities. It drops a random .exe file on the system, allows backdoor access through IRC and terminates security-related applications. (Sophos)
W32/Rbot-YY – Another Rbot variant. This one installs “dos.exe” on the infected machine. It exploits a number of Windows vulnerabilities to spread between machines. (Sophos)
W32/Rbot-YN – Another Rbot variant similar to the two above. This one uses “msnshed.exe” as its infection point. (Sophos)
W32/Rbot-YO – See the above Rbot variants and replace the infected file with “mcafe32.exe”. (Sophos)
W32/Domwis-I – A network worm that installs “SYSCFG16.EXE” in the Windows System folder. It can be used for a number of malicious purposes, including denial-of-service attacks, keystroke logging and webcam captures. (Sophos)
W32/Sdbot-SB – A new Sdbot worm variant. Not much details available, other than it drops “winprotect.exe” on the infected machine. (Sophos)
W32/Sumom-C – An MSN Messenger worm that drops three files on the infected machine: “CSNSS.EXE” and “MCSV.COM” in the Windows System folder and “SVHOST.EXE” in the Windows directory. The virus spreads via a file that looks to be a photo or game. It can disable access to security Web sites. (Sophos)
Troj/Banker-BZ – A Trojan that is designed to steal online banking information for customers of E-Gold banking sites. (Sophos)
Troj/HideDial-D — A dialer Trojan that calls out to premium-rate porn services. It installs itself as “TIBS3.EXE” in the Windows System directory. (Sophos)
W32/Poebot-K – An IRC backdoor worm that exploits a number of known Windows vulnerabilities in order to infect a machine. It copies itself into “winamp.exe” in the Windows System directory. (Sophos)
**********




