* Patches from SCO, Conectiva, Fedora Legacy, others * New IM worms target MSN users
Today’s bug patches and security alerts:
HP patches Tru64 Unix bug
According to an HP advisory, “There is a potential security vulnerability on HP Tru64 UNIX systems message queue where a local unprivileged user may cause a local Denial of Service (DoS). The vulnerability may impact processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.” A patch is available from the HP IT Resource Center:
https://www.itrc.hp.com/service/patch/mainPage.do
**********
Microsoft updates code removal tool, passes on patches
Microsoft released a new version of a software tool that removes infections from common computer viruses and worms, but held off from issuing any software patches Tuesday. The updated tool adds features to detect and remove malicious code placed on computers infected with the Bagle, Bropia, Sober, Sobig and Goweh worms, as well as 160 new variants of the Gaobot Trojan horse program and 11 new versions of MyDoom, according to information provided by the company. IDG News Service, 03/08/05.
https://www.nwfusion.com/news/2005/0308microupdat.html?nl
**********
SCO patches Samba for UnixWare
A number of vulnerabilities have been found in Samba for UnixWare, a utility for providing file and print services to Windows machines. The vulnerabilities could be exploited in denial-of-service attacks or to potentially execute arbitrary code on the affected machine. For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17
**********
Conectiva, SCO release update for Squid
Several flaws in squid, an open source proxy server, have been patched by Conectiva and SCO. Many of the flaws could be exploited in denial-of-service attacks against the affected server. For more, go to:
Conectiva:
https://www.nwfusion.com/go2/0307bug2a.html
SCO:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16
General Squid advisory:
https://www.nwfusion.com/go2/0307bug2b.html
**********
Conectiva issues kernel update
This is a general bug fix update to the Conectiva Linux kernel that repairs a range of bugs in previous releases. For more, go to:
https://www.nwfusion.com/go2/0307bug2c.html
**********
Debian patches kppp
A flaw in kppp, if installed with root privileges, could be exploited to hijack a system’s domain name resolution function. For more, go to:
https://www.debian.org/security/2005/dsa-692
Debian patches Abuse game
The Abuse action game creates insecure temporary files and contains several buffer overflows. These could be exploited to run malicious code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-691
**********
Gentoo patches KDE dcopidlng
KDE dcopidlng, a DCOP helper script, is vulnerable to a symlink attack. An attacker could use this to overwrite files on the affected system. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-14.xml
Gentoo releases fix for mlterm
An integer overflow in mlterm, a terminal emulator application, could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-13.xml
Gentoo issues patch for Hashcash
A format string vulnerability could be exploited to run any code on the affected machine. According to Gentoo, “Hashcash is a utility for generating Hashcash tokens, a proof-of-work system to reduce the impact of spam.” For more, go to:
https://security.gentoo.org/glsa/glsa-200503-12.xml
Gentoo fixes ImageMagick
A format string vulnerability in ImageMagick, a toolset for image viewing and editing, could be exploited by an attacker to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-11.xml
**********
Fedora Legacy release fix for subversion
A number of security issues in subversion, a version control system, have been patched by the Fedora Legacy team. Some of the vulnerabilities could be exploited to run code on the affected machine. For more, go to:
http:/www.nwfusion.com/go2/0307bug2d.html
Fedora Legacy updates php package
Various security flaws in the popular PHP scripting engine have been fixed. Users could view unauthorized information or potentially execute malicious PHP scripts on the affected machine. For more, go to:
http:/www.nwfusion.com/go2/0307bug2e.html
Fedora Legacy issues ‘less’ patches
A patch for the less package for Red Hat 9 caused another buffer overflow issue. A fix is available:
https://bugzilla.fedora.us/show_bug.cgi?id=2404
**********
Today’s roundup of virus alerts:
New IM worms target MSN users
Anti-virus companies are warning users of Microsoft ‘s popular MSN Messenger application about a host of new worms that spread using instant messages over that network. New versions of the Bropia and Kelvir worms appeared on Monday and are spreading over MSN Messenger, according to alerts issued by leading anti-virus companies. Also on Monday, anti-virus companies warned customers about the first in a new family of worms, dubbed “Sumom,” or “Serflog,” which also spreads over MSN. The spate of IM worms is evidence that virus writers are finally realizing the potential of IM to quickly disseminate malicious code, according to one anti-virus expert. IDG News Service, 03/08/05.
https://www.nwfusion.com/news/2005/0308newimwo.html?nl
W32/Forbot-EP — A new Forbot variant that spreads via network shares and provides backdoor access via IRC. This variant installs itself as “windns.exe” in the Windows System folder. It can be used for a number of malicious purposes. (Sophos)
W32/Forbot-ER — This Forbot variant exploits the Windows LSASS vulnerability as it spreads through network shares. It drops two files on the infected machine: “mousedrive.exe” and “instantmsgrs.exe”. (Sophos)
W32/Rbot-WX — This Rbot variant can be used for a number of malicious purposes and spreads via network shares, exploiting a number of known Windows vulnerabilities. It drops “lsassx.exe” in the Windows System folder. (Sophos)
W32/Sober-L — A new variant of the Sober e-mail worm, which usually spreads through an infected ZIP or PIF file. The virus will open Notepad when it infects a machine. (Sophos)
W32/Sober-O – Another new Sober variant. This one too opens Notepad with a bunch of gibberish text and drops the file “SMSS.EXE” on the infected machine. (Panda Software)
W32/Tibick-C — A peer-to-peer worm that copies itself into “svcnet.exe” in the Windows System folder of the infected machine. It has some backdoor capability and may try downloading an executable from a remote site. (Sophos)
W32/Radbot-A — A network worm that drops three files on the infected machine: “1.EXE”, “2.EXE” and “Z.BAT “. No word on what kind of damage it may cause. (Sophos)
**********




