Novell patches Netware vulnerability

Opinion
Mar 21, 20054 mins

* Patches from Novell, IBM, Mandrake Linux, others * Beware latest slew of Rbot variants

Today’s bug patches and security alerts:

Novell patches Netware vulnerability

A flaw in Novell’s xvesa code could be exploited to gain access to a Netware Xwindows session without authentication. Novell has issued a patch for the issue. For more, go to:

NetWare 6.5 SP2:

https://www.nwfusion.com/go2/0321bug1a.html

Security Tracker advisory:

https://www.securitytracker.com/alerts/2005/Mar/1013460.html

**********

IBM fixes WebSphere Commerce flaw

Flaws in IBM’s WebSphere Commerce could be exploited to view confidential information. A patch is available:

https://www-1.ibm.com/support/docview.wss?uid=swg21199839

**********

Michal Zalewski warns of Linux handling flaws

According to an alert from security guru Michal Zalewski, “There appears to be a fair number of kernel-level range checking flaws in ISO9660 filesystem handler (and Rock Ridge / Juliet extensions) in Linux up to and including 2.6.11. These bugs range from DoS conditions to potentially exploitable memory corruption – all this whenever a specially crafted filesystem is mounted or directories are examined.” Zalewski says such flaws may exist in other operating systems as well.

https://www.nwfusion.com/go2/0321bug1b.html

**********

Gentoo, Mandrake Linux patch KDE

A vulnerability in KDE’s DCOP function could be exploited in a denial of service attack against the affected machine. It looks as if only a local user can exploit the flaw. For more, go to:

Gentoo:

https://security.gentoo.org/glsa/glsa-200503-22.xml

Mandrake Linux:

https://www.nwfusion.com/go2/0321bug1c.html

**********

Conectiva releases update for cyrus-imapd

According to Conectiva’s advisory, “Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via an off-by-one error in the imapd annotate extension, an off-by-one error in cached header handling a stack-based buffer overflow in fetchnews, or a stack-based buffer overflow in imapd.” For more, go to:

https://www.nwfusion.com/go2/0321bug1d.html

**********

Gentoo issues fix for Grip

A flaw in Grip, a CD player/ripper, could be exploited to run malicious code on the affected machine. To exploit the flaw, the client has to be given a large CDDB response. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-21.xml

**********

Mandrake Linux patches evolution

A flaw in evolution, a mail client, could cause the application to crash if certain message types are received. A patch is available:

https://www.nwfusion.com/go2/0321bug1e.html

**********

Today’s roundup of virus alerts:

Troj/BagDl-Gen – A family of worms that drop malicious DLL files on the target system and limit access to security-related Web sites. (Sophos)

W32/Rbot-YB – An Rbot variant that spreads via network shares by exploiting a number of known Windows vulnerabilities. It drops a random .exe file on the system, allows backdoor access through IRC and terminates security-related applications. (Sophos)

W32/Rbot-YY – Another Rbot variant. This one installs “dos.exe” on the infected machine. It exploits a number of Windows vulnerabilities to spread between machines. (Sophos)

W32/Rbot-YN – Another Rbot variant similar to the two above. This one uses “msnshed.exe” as its infection point. (Sophos)

W32/Rbot-YO – See the above Rbot variants and replace the infected file with “mcafe32.exe”. (Sophos)

W32/Domwis-I – A network worm that installs “SYSCFG16.EXE” in the Windows System folder. It can be used for a number of malicious purposes, including denial-of-service attacks, keystroke logging and webcam captures. (Sophos)

W32/Sdbot-SB – A new Sdbot worm variant. Not much details available, other than it drops “winprotect.exe” on the infected machine. (Sophos)

W32/Sumom-C – An MSN Messenger worm that drops three files on the infected machine: “CSNSS.EXE” and “MCSV.COM” in the Windows System folder and “SVHOST.EXE” in the Windows directory. The virus spreads via a file that looks to be a photo or game. It can disable access to security Web sites. (Sophos)

Troj/Banker-BZ – A Trojan that is designed to steal online banking information for customers of E-Gold banking sites. (Sophos)

Troj/HideDial-D — A dialer Trojan that calls out to premium-rate porn services. It installs itself as “TIBS3.EXE” in the Windows System directory. (Sophos)

W32/Poebot-K – An IRC backdoor worm that exploits a number of known Windows vulnerabilities in order to infect a machine. It copies itself into “winamp.exe” in the Windows System directory. (Sophos)

**********