* Patches from Apple, Gentoo, Conectiva, others * Beware password stealing Trojan that targets banking sites * Something from the interesting reading department
Today’s bug patches and security alerts:
Mozilla patches Firefox image handling flaw
Mozilla is urging users to download a new Firefox browser update that fixes a flaw in the way GIF images are handled. A heap overflow in previous Firefox releases could be exploited to run malicious code on the affected machine. For more, go to:
https://www.mozilla.org/security/announce/mfsa2005-30.html
**********
Apple releases update that patches 11 flaws
A new update for Mac OS fixes flaws in a number of applications, including AFP Server, Bluetooth Setup Assistant, Core Foundation, Cyrus IMAP, Cyrus SASL, folder permissions, Mailman, Safari, Samba and SquirrelMail. For more, go to:
https://docs.info.apple.com/article.html?artnum=301061
**********
Gentoo issues fix for rxvt-unicode
Rxvt-unicode, a terminal emulator clone, is vulnerable to a buffer overflow. This could be exploited by an attacker to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-23.xml
Gentoo patches LTris
A buffer overflow has been discovered in LTris, a Tetris game clone. Attackers could use this to run code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-24.xml
Gentoo releases patches for Sylpheed, Sylpheed-claws
A vulnerability in Sylpheed and Sylpheed-claws, an e-mail and newsreader client, could be exploited with a specially crafted message. Exploiting this could cause the application to crash and potentially allow for malicious code to run on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-26.xml
Gentoo fixes OpenSLP
A number of serious flaws have been found in the Gentoo implementation of OpenSLP, an open source version of the Service Location Protocol. The flaws could be exploited by a remote attacker. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-25.xml
Gentoo patches Xzabite dyndnsupdate
According to an alert from Gentoo, “Xzabite’s dyndnsupdate software suffers from multiple vulnerabilities, potentially resulting in the remote execution of arbitrary code.” For more, go to:
https://security.gentoo.org/glsa/glsa-200503-27.xml
**********
Conectiva issues fix for curl
A buffer overflow in curl’s NTLM authorization base64 decoding could be exploited by an attacker to execute applications with the permissions of the user running curl. For more, go to:
https://www.nwfusion.com/go2/0328bug2a.html
**********
Trustix releases ‘multi’ fix
A new update for the Trustix Linux operating system fixes flaws in the kernel and MySQL database server. Flaws in these items could be exploited in a denial-of-service attack against the affected machine. For more, go to:
https://www.trustix.org/errata/2005/0009/
**********
Debian patches xli flaws
A number of overflows have been found and fixed in Debian’s implementation for xli, an image viewer. The flaws could be exploited to run any code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-695
Debian fixes perl design flaw
A flaw in the remove tree (rmtree) function in Perl could be exploited to cause a race condition on the affected machine. A fix is available:
https://www.debian.org/security/2005/dsa-696
**********
Mandrake Linux releases patch for MySQL
It is possible for a local user to load arbitrary code into the MySQL database using the ‘Insert’ command. Mandrake Linux has released a fix for this issue:
https://www.nwfusion.com/go2/0328bug2b.html
**********
Today’s roundup of virus alerts:
W32/Poebot-K- A backdoor worm that provides attackers access to the infected machine via IRC. It spreads via network shares by exploiting a number of known Windows vulnerabilities. The virus can be used to steal passwords. (Sophos)
Troj/Dloader-JQ – A Trojan that drops “smiissm.exe” in the Windows System folder. It attempts to tunnel through the Windows firewall to access an outside site. (Sophos)
Troj/Banker-HE – A password stealing Trojan that targets banking sites. This one drops the file “winllogon.exe” in one of the Windows folder. (Sophos)
W32/MyDoom-BH – A new MyDoom variant that displays a dialog box titled “AVToolKitPro” and message of “Operation completed”. The infected message is titled “Virus Alert id:
W32/Sdbot-WE – This backdoor worm spreads via weakly protected network shares. It installs “IPCONN.EXE” in the Windows System and registers itself as “Logitech Desktop”. It attempts to delete network shares from the exploited machine. (Sophos)
Troj/Feutel-B – Another backdoor Trojan that spreads via network shares. It installs itself as “svchost.exe” in the Windows System directory. No word on what kind of damage it can cause. (Sophos)
W32/Rbot-YV – An Rbot variant that can be used to steal CD keys, launch DoS attacks and download files from a remote site. It spreads via network shares, installs “winsys32.exe” in the Windows System directory and allows backdoor access via IRC. (Sophos)
W32/Rbot-ZA – Similar to Rbot-YV above, except this variant uses the file “svchost323.exe” has its infection point. (Sophos)
W32/Netsky-AD – A new Netsky variant that spreads through network shares and e-mail. In drops “MsnMsgrs.exe” in the Windows System folder. In e-mail, it spreads via an attachment with an “.scr” extension. (Sophos)
Troj/Bancos-BU – A password-stealing Trojan that targets Brazilian banking sites. It drops the file “iservice.exe” in the Windows System folder. (Sophos)
**********
From the interesting reading department:
The Trustworthy Computing Security Development Lifecycle
Before software developed under the SDL can be released, it must undergo a Final Security Review by a team independent from its development group. When compared to software that has not been subject to the SDL, software that has undergone the SDL has experienced a significantly reduced rate of external discovery of security vulnerabilities. This paper describes the SDL and discusses experience with its implementation across Microsoft software. Microsoft, March 2005.




