* Patches from SuSE,Trustix, FreeBSD, others * Beware Web postcards bearing greetings
Today’s bug patches and security alerts:
Cisco warns of two IOS vulnerabilities
Cisco issued advisories on two vulnerabilities that affect the IOS operating system used in many of the company’s devices. First, a denial-of-service vulnerability was found in the Secure Shell implementation when it’s used with Terminal Access Controller Access Control System Plus (TACACS+). An attacker can cause the service to crash and reload.
The second flaw is in the way certain versions of IOS handle Internet Key Exchange (IKE) Xauth messages when configured with an Easy VPN Server. An attack may exploit this to bypass authorization and gain access to network resources. For more, go to:
SSH/TACACS+ advisory:
https://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtml
IKE Xauth advisory:
https://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml
**********
Security experts warn of Mozilla JavaScript vulnerability
A flaw in the Versions 1.0.1 and 1.0.2 of the Mozilla browser could be used to disclose “sensitive” information. The flaw exists in the open source browser’s JavaScript engine. Currently, no fix is available. The workaround is to disable JavaScript. For more, go to:
https://secunia.com/advisories/14820/
**********
SuSE, Trustix release kernel updates
Several flaws in the Linux kernel have been fixed in these releases from SuSE and Trustix. Attackers could exploit this to crash the affected machine or potentially run malicious code. For more, go to:
SuSE:
https://www.nwfusion.com/go2/0404bug2a.html
Trustix:
https://www.trustix.org/errata/2005/0011/
**********
FreeBSD patches amd64 flaws
A flaw in the way FreeBSD provides access to hardware resources on the AMD64 platform could be exploited in a denial-of-service attack. For more, go to:
https://www.nwfusion.com/go2/0404bug2b.html
FreeBSD releases fix for sendfile
A flaw in the way sendfile truncates an aborted file transfer could result in random parts of kernel memory being sent to the far-end site. For more, go to:
https://www.nwfusion.com/go2/0404bug2c.html
**********
Debian, Gentoo patch krb5
Two buffer overflows in the MIT Kerberos 5 implementation could be exploited to run malicious code on the affected machine. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-703
Gentoo:
https://security.gentoo.org/glsa/glsa-200504-04.xml
**********
Gentoo patches LimeWire
LiveWire, a peer-to-peer client for sharing files, could be exploited to display sensitive system information. An attacker could use the GET command to read arbitrary files on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-37.xml
**********
HP releases software fix for h6315 PDA phone
HP released a software update last week for its troubled iPaq h6315 handheld that promises to fix several issues that left users frustrated and caused retail partner T-Mobile USA to remove the device from its stores. The 23.8M-byte ROM update is available for download from the support section of HP’s Web site. IDG News Service, 04/04/05.
https://www.nwfusion.com/news/2005/0404hprelea.html?nl
**********
Today’s roundup of virus alerts:
Web postcards hide Trojan horse programs
Beware of Web postcards bearing greetings. That’s the advice from The SANS Institute’s Internet Storm Center, which is warning about e-mail messages that pose as Web postcards, then direct recipients to a Web site that installs a Trojan horse program. IDG News Service, 04/05/05.
https://www.nwfusion.com/news/2005/0405webpostc.html?nl
Mabir.A – A new worm that targets Nokia Series 60 phones that run the Symbian operating system. This worm is based on the Cabir mobile Trojan but adds the twist of spreading by MMS as well as Bluetooth. And, it does not randomly target numbers in the infected phone’s address book, instead replying to any incoming MMS message with a copy of the infected SIS file. (F-Secure)
Fontal.A – Another Symbian Trojan that can infect Nokia Series 60 phones. This file must be downloaded by the user and does not spread via Bluetooth or MMS messages. It can disable the phone and require a complete system reset. (F-Secure)
W32/Sdbot-WQ – This bot spreads through network shares by exploiting the Windows LSASS and RPC DCOM vulnerabilities. It drops “winsvcmgr.exe” in the Windows System folder and can be used to launch DoS attacks, as a proxy, and to download code from remote sites. (Sophos)
W32/Sdbot-WS – This bot spreads to network shares with no or easily guessed passwords and to machines already infected with a previous Sdbot variant. It allows backdoor access via IRC and can be used for a number of malicious purposes. (Sophos)
W32/Rbot-APR – A Trojan that exploits a number of known Windows vulnerabilities as it spreads via network shares. It installs itself as “vrsprtc.exe” in the Windows System directory, allows backdoor access via IRC and disables certain security-related applications. (Sophos)
W32/Rbot-ZN – Another Rbot variant that exploits various known Windows flaws as it spreads through network shares. This variant drops “init3.exe” in the Windows System folder. (Sophos)
W32/Rbot-ZQ – Similar to the above Rbot variants. It can be used for a number malicious purposes. (Sophos)
W32/Mytob-O- An e-mail worm that spreads via messages that look like a returned e-mail. It installs “taskgmr.exe” in the Windows System folder and can harvest e-mail address from the infected machine. (Sophos)
Troj/Bancos-BY – A Trojan that targets customers of Brazilian banking sites. It installs itself as “taskmgrnt.exe” in the Windows System folder and records data to a text file called “rumlog.dat”. (Sophos)
W32/Stubbot-A – A new Trojan that spreads through network shares and backdoors left open by the MyDoom worm. It drops “stubbish.exe” in the Windows folder and allows backdoor access through IRC. It can also spread via e-mail with attachments that end in .pif or .scr. (Sophos)
Troj/BankAsh-F – A Trojan that logs information entered into certain banking Web sites, including user name and password data. The information is stored locally and FTPed to a remote site periodically. (Sophos)
Troj/StartPa-FM – This worm changes the Internet Explorer start page and modifies other settings. No word on how it spreads. (Sophos)
**********




