* Patches from Debian, Mandrake Linux, Gentoo, others * Beware worm that uses MSN Messenger to spread via file named "funnyashell.scr"
Today’s bug patches and security alerts:
Cisco warns of DoS flaws in two devices
Cisco is warning of denial-of-service vulnerabilities in its Catalyst 6500 Series Switch devices and Cisco 7600 Series Internet Router devices. A remote attacker could exploit this to crash the affected device. Fixes are available:
https://www.cisco.com/warp/public/707/cisco-sa-20040408-vpnsm.shtml
**********
New bugs found in Outlook, Internet Explorer
Microsoft is investigating a new set of potentially serious security flaws in Internet Explorer and Outlook reported by security company eEye Digital Security, the software maker said Friday. The two flaws in the Web browser and e-mail client could let an attacker take control over a system with minimal action from the user, eEye said in two security alerts posted on its page of upcoming advisories. The company ranks the flaws “high” risk.
https://www.nwfusion.com/news/2005/0401newbugs.html?nl
**********
DNS pharming attacks target .com domain
The SANS Institute’s Internet Storm Center (ISC) issued a warning Thursday about the new attacks, which corrupt some DNS servers so that requests for .com sites sent to those servers connect users instead to Web sites maintained by the attackers. News of the new attacks comes amid increasing reports of pharming scams, and statistics that show at least 1,300 Internet domains were redirected to compromised Web servers in a similar attack in early March. IDG News Service, 04/01/05.
https://www.nwfusion.com/news/2005/0401dnspharm.html?nl
**********
Debian, Mandrake Linux patch ImageMagick
A number of flaws in ImageMagick, an image editing application, have been patched by both Debian and Mandrake Linux. The most serious of the flaws could be exploited to run any code on the affected machine. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-702
Mandrake Linux:
https://www.nwfusion.com/go2/0404bug1f.html
**********
Conectiva releases kernel update
Several flaws in the Conectiva Linux kernel have been fixed in this release. Attackers could exploit this to crash the affected machine or potentially run malicious code. For more, go to:
https://www.nwfusion.com/go2/0404bug1e.html
**********
Debian updates Samba
A buffer overflow in Samba, a print server for Linux, could be exploited to run arbitrary code on the affected machine. The attacker would have root privileges. For more, go to:
https://www.debian.org/security/2005/dsa-701
**********
Gentoo releases fix for netkit-telnetd, telnet-bsd
As we reported last week, a number of telnet clients are vulnerable to a buffer overflow that could be exploited to run arbitrary code on the affected machine. Gentoo has released related fixes:
netkit-telnetd:
https://security.gentoo.org/glsa/glsa-200503-36.xml
telnet-bsd:
https://security.gentoo.org/glsa/glsa-200504-01.xml
**********
Mandrake Linux patches libexif
According to an alert from Mandrake Linux, “A buffer overflow was discovered in the way libexif parses EXIF tags. An attacker could exploit this by creating a special EXIF image file which could cause image viewers linked against libexif to crash.” For more, go to:
https://www.nwfusion.com/go2/0404bug1d.html
Mandrake Linux issues patch for ipsec-tools
A the racoon daemon included with ipsec-tools does not properly handle incoming ISAKMP packets. It is possible to crash the affected machine when exploiting this. For more, go to:
https://www.nwfusion.com/go2/0404bug1c.html
Mandrake Linux releases fix for htdig
A cross-scripting flaw in htdig has been patched by Mandrake Linux. Get the patch here:
https://www.nwfusion.com/go2/0404bug1b.html
Mandrake Linux patches grip
According to a Mandrake Linux advisory, ” A buffer overflow bug was found by Dean Brettle in the way that grip handles data returned by CDDB servers. If a user connected to a malicious CDDB server, an attacker could execute arbitrary code on the user’s machine.” For more, go to:
https://www.nwfusion.com/go2/0404bug1a.html
**********
Today’s roundup of virus alerts:
Troj/HideDial-E – A Trojan horse that attempts to dial out to “premium-rate” porn phone numbers. It installs itself as “tibs3.exe” on the infected machine. (Sophos)
W32/Sdbot-WK – An Sdbot variant that spreads through network shares by exploiting a number of known Windows vulnerabilities. It drops “PC.EXE” in the Windows System foldeer and can be used for a number of malicious purposes. (Sophos)
W32/Sdbot-WM – Another Sdbot variant that spreads through network shares. This variant drops “MSNMSGR.EXE” in the Windows System folder and can log keystrokes to the file “KEYLOG.TXT”. (Sophos)
W32/Sdbot-WN – This Sdbot variant installs itself as “winamp62.exe” in the Windows System directory. It too allows backdoor access via IRC and can be used for a number of malicious applications. (Sophos)
W32/Kelvir-F – A worm that uses MSN Messenger to spread. The infected file is named “funnyashell.scr”. It can reduce the level of security on an infected machine. (Sophos)
W32/Elitper-E – This worm spreads via an e-mail message that looks like an Windows XP Service Pack 2 upgrade. Among the infected file it drops is “XPStartUp.exe”. It can limit access to security related sites by modifying the Windows HOSTS file. (Sophos)
W32/Rbot-LD – An Rbot variant that spreads via network shares with weak or no password protection and drops the file “spools.exe” in the Windows System folder. It allows backdoor access via IRC. (Sophos)
Troj/PcClient-D – A Trojan that can be used to steal information off the infected machine. No word on how it spreads, but it does drop “CCPCCORTR.DLL” on its target. (Sophos)
W32/Ahker-F – Another mass-mailing worm that looks like an XP SP2 upgrade. It may also spread through mirc. It can disable security applications and limit access to related web sites. (Sophos)
**********




