Critical Microsoft patches coming this week

Opinion
Apr 11, 20054 mins

* Patches from Microsoft, OpenPKG, Gentoo, others * Beware new Mytob variants

Today’s bug patches and security alerts:

Critical Microsoft patches coming this week

Microsoft Tuesday plans to issue eight security alerts with patches, some critical, for Windows, Office, MSN Messenger and Exchange. Five of the security bulletins apply to Windows and at least one of those is deemed critical, Microsoft said in a notice posted to its Web site. Office, MSN Messenger and Exchange, will get one bulletin each, all deemed critical, the company said. IDG News Service, 04/08/05.

https://www.nwfusion.com/news/2005/0408critimicro.html?nl

**********

Macromedia releases workaround for ColdFusion flaw

ColdFusion 6.1 Updater 1 contains a flaw that could allow users to download Java .class files that are not normally accessible. ColdFusion 7.0 is not affected and a workaround is available:

https://www.macromedia.com/go/mpsb05-02

**********

OpenPKG patches imapd

Several flaws have been found in the OpenPKG implementation of imapd. An attacker could exploit these to run malicious code on the affected machine and potentially take control of it. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2005.005-imapd.txt

**********

Conectiva issues fix for MySQL

Multiple vulnerabilities have been found in MySQL, a popular database application. Attackers could exploit this to overwrite arbitrary files and potentially run malicious code. For more, go to:

https://www.nwfusion.com/go2/0411bug1a.html

**********

Gentoo patches Dnsmasq

According to an alert from Gentoo, “Dnsmasq (a DNS forwarder and DHCP server) is vulnerable to DNS cache poisoning attacks and a potential Denial of Service from the local network.” For more, go to:

https://security.gentoo.org/glsa/glsa-200504-03.xml

Gentoo issues fix for Gaim

Gaim, an open source instant messaging client, contains a number of denial-of-service vulnerabilities. For more, go to:

https://security.gentoo.org/glsa/glsa-200504-05.xml

**********

Gentoo, Mandriva (formerly Mandrake Linux) fix sharutils

The unshar utility included in the sharutils suite is vulnerable to a symlink attack. An attacker could exploit this to overwrite arbitrary files on the affected machine. For more, go to:

Gentoo:

https://security.gentoo.org/glsa/glsa-200504-06.xml

Mandrake Linux:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:067

**********

Mandriva releases fixes for gtk+2.0 and gdk-pixbuf

Flaws in the way BMP images are handled by gdk-pixbuf and gtk+2.0 could be exploited in a denial-of-service attack against the affected machine. Patches are available. For more, go to:

gtk+2.0:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:068

gdk-pixbuf:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:069

**********

Today’s roundup of virus alerts:

W32/Mytob-Q – A mass-mailing worm that also uses IRC to spread. It drops “msnmsgs.exe” on the infected machine and can limit security resources. (Sophos)

W32/Mytob-R – This Mytob variant drops three files on the infected machine: “taskgmr.exe”, “bingoo.exe” and “nethell.exe”. It too limits security resources on the infected Windows system. (Sophos)

W32/Mytob-W – Another Mytob variant. This one exploits the Windows LSASS and RPC-DCOM vulnerabilities as it spreads via e-mail and IRC. It drops “NETHELL.EXE” and “TASKGMR.EXE”. It limits access to security-related Web sites by modifying the Windows HOSTS file. (Sophos)

Troj/Bdoor-ZAT – A backdoor Trojan that offers shell access to the infected machine via port 63714. It installs “explorer.exe” and “userinit.dll” in the Windows System folder. (Sophos)

Troj/Agent-CZ – A Trojan horse the redirects Internet traffic to potentially malicious sites. It copies itself to “csrss.exe” in the Windows System folder. (Sophos)

Beliu.A – Another backdoor Trojan horse. This one connects to the site “liubei.8866.org” and allows an attacker to take control of the infected machine. It spreads via an infected Word document and exe file. (Panda Software)

W32/Reper-A – A worm that copies itself to network drives as “reper.exe”. It can terminate regedit.exe, cmd.exe and taskmgr.exe if they’re running on the infected machine. (Sophos)

W32/Rbot-AAC – A new Rbot variant that installs “msnmsgs.exe” in the Windows System folder after spreads via a connected network share. It can be used to scan ports, launch DoS attacks and run files. (Sophos)

Troj/Nuclear-F – This backdoor Trojan that gives attackers access to the infected machine. It uses two files on the machine: “logger.php” and “settings.in”. (Sophos)

WM97/Xaler-A – A Word macro virus that displays a message saying that you should relax while all your files are deleted. Don’t worry, the worm just displays the message and does NOT delete anything. (Sophos)

W32/Agobot-RJ – Another bot that spreads via network shares and can do a number of things on the infected machine, including launch Dos attacks, download and run files, and more. It allows backdoor access via IRC and installs “updateXPSPC.exe” on the infected machine. (Sophos)