Windows Server gets security boost with Service Pack

Opinion
Mar 31, 20055 mins

* Patches from Cisco, Debian, Gentoo, others * Beware malicious worm that installs itself as "windrives.exe" in the Windows System directory

Today’s bug patches and security alerts:

Microsoft ships first Server 2003 service pack, x64 editions of server, desktop 

Microsoft late Wednesday released Windows Server 2003 Service Pack 1, a collection of security enhancements that aligns the server with the latest release of the Windows XP desktop client. Network World Fusion, 03/31/05.

https://www.nwfusion.com/news/2005/0331windoserve.html?nl

Get Windows Server 2003 SP1:

https://www.nwfusion.com/go2/0328bug2j.html

**********

iDefense warns of flaws in Telnet clients

A number of Telnet clients are vulnerable to buffer overflow vulnerabilities, which could be exploited to run any code on the affected machine, according to an alert from iDefense. For more, go to:

https://www.nwfusion.com/go2/0328bug2d.html

Related patches:

Apple:

https://docs.info.apple.com/article.html?artnum=301061

Debian (netkit-telnet):

https://www.debian.org/security/2005/dsa-697

Debian (netkit-telnet-ssl):

https://www.debian.org/security/2005/dsa-699

FreeBSD:

https://www.nwfusion.com/go2/0328bug2e.html

Mandrake Linux:

https://www.nwfusion.com/go2/0328bug2f.html

MIT Kerberos:

https://www.nwfusion.com/go2/0328bug2g.html

Red Hat Enterprise Linux – telnet:

https://rhn.redhat.com/errata/RHSA-2005-330.html

Red Hat Enterprise Linux – krb5:

https://rhn.redhat.com/errata/RHSA-2005-327.html

**********

Cisco patches VPN 3000 Concentrator

A denial-of-service vulnerability has been found in the Cisco VPN 3000 Concentrator. An attacker could send special SSL packets to the device repeatedly, causing it to crash. A free update is available to Cisco customers to fix the flaw.

https://www.cisco.com/warp/public/707/cisco-sa-20050330-vpn3k.shtml

**********

Debian releases fix for mc

A buffer overflow in Midnight Commander (mc) has been patched with this latest update. The release also fixes a regression from a previous release. For more, go to:

https://www.debian.org/security/2005/dsa-698

Debian issues patch for mailreader

A cross-scripting vulnerability has been found in the mailreader client for Debian. For more, go to:

https://www.debian.org/security/2005/dsa-700

**********

Gentoo patches smarty

A template security feature in Smarty, a template engine for PHP, could be bypassed by an attacker. This could be exploited to run malicious code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-35.xml

Gentoo issues patch for mpg321

A flaw in the way the mpg321 media player handles ID3 tags (metadata for MP3 files) could be exploited to run code on the affected machine. A fix is available.

https://security.gentoo.org/glsa/glsa-200503-34.xml

**********

Conectiva patches ethereal

The Ethereal protocol analyzer tool is vulnerable to a number of security flaws. These flaws could exploited to run arbitrary code on the affected system. A patch is available.

https://www.nwfusion.com/go2/0328bug2h.html

**********

Code insertion in Blogger?

According to a post on the BugTraq mailing list, attackers could be able to insert scripting code into the comment field of Blogger-based Weblog posts. Comments have to be turned on and the server running Blogger must support server-side processing. Blogger has not responded.

https://www.nwfusion.com/go2/0328bug2i.html

**********

Today’s roundup of virus alerts:

W32/Radbot-A – A worm that spreads via network shares, dropping three files on the infected machine: “1.EXE”, “2.EXE” and “Z.BAT”. The virus may try to delete network shares. (Sophos)

W32/Rbot-DP – An Rbot variant that spreads through network shares, installing itself in the system registry as a DirectX component. It allows backdoor access via IRC. (Sophos)

W32/Agobot-RB – A malicious worm that can be used for a number of applications, including stealing local data and lauching denial-of-service attacks against third parties. It installs itself as “windrives.exe” in the Windows System directory and can limit access to security Web sites by modifying the Windows HOSTS file. (Sophos)

W32/Agobot-RE – Another Agobot variant. This version installs “lMAPl.exe” in the Window System folder. In addition to carrying out many different tasks, the virus can shutdown anti-virus software running on the infected machine and limit access to related security sites by modifying the Windows HOSTS file. (Sophos)

W32/Sdbot-WG – An Sdbot family member that drops “SearchNDestrou.exe” on the affected machine. It connects to a predefined IRC server to await commands. (Sophos)

W32/Mytob-D – A worm that spreads via e-mail and IRC, dropping “msgmr.exe” in the infected machine’s Windows System directory. It limits access to security vendor sites by modifying the Windows HOSTS file. (Sophos)

W32/Mytob-E – Another Mytob variant that is similar to Mytob-D above. This one drops “taskgmr.exe” in the Windows System folder. (Sophos)

W32/Mytob-G – Yet another Mytob variant. This one drops “tagmr.exe” in the Windows System folder. (Sophos)

W32/Mytob-H — This one installs “taskgmr.exe” in the Windows System folder. (Sophos)

W32/Mytob-K – This variant adds the twist of trying to spread to network shares by exploiting the Windows LSASS vulnerability. It’s e-mail characteristics looks like some sort of automated report or bounce-back message. (Sophos)

W32/Mytob-N – It’s the Mytob week. Version “N” installs “ccsrs.exe” in the Windows System folder. It too can limit access to security related Web sites. (Sophos)