Sun patches Java Web Start vulnerability

Opinion
Mar 28, 20054 mins

* Patches from SuSE, Fedora, Gentoo, others * Beware mass-mailing worm that spreads through messages that look like a returned e-mail

Today’s bug patches and security alerts:

Sun patches Java Web Start vulnerability

A flaw in the Java Web Start platform could be exploited to allow any Java applet to read, write and run on the affected machine. The flaw is in the way Java applications are handled in the “sandbox.” A fix is available.

https://java.sun.com/j2se/1.4.2/download.html

Related fix for Gentoo Linux users:

https://security.gentoo.org/glsa/glsa-200503-28.xml

**********

SuSE releases fix for ImageMagick

A number of flaws in ImageMagick, an image editing application, have been patched by SuSE. The most serious of the flaws could be exploited to run any code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0328bug1a.html

SuSE fixes kernel vulnerabilities

Several flaws in the SuSE Linux kernel have been fixed in this release from SuSE. Attackers could exploit this to crash the affected machine or potentially run malicious code. For more, go to:

https://www.nwfusion.com/go2/0328bug1b.html

**********

Fedora, SuSE issues MySQL update

Three vulnerabilities have been found in the popular MySQL database. Attackers may exploit these to run their own code on the affected system. Patches are available:

Fedora Legacy:

https://www.nwfusion.com/go2/0328bug1c.html

SuSE:

https://www.novell.com/linux/security/advisories/2005_19_mysql.html

**********

Fedora patch for shareutils available

A number of buffer overflows have been found in the shareutils application for the Fedora Legacy operating systems (Red Hat). These vulnerabilities could be exploited to run malicious code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0328bug1d.html

Fedora releases spamassassin fix

According to an alert from the Fedora Legacy group, “A denial of service bug has been found in SpamAssassin versions below 2.64. A malicious attacker could construct a message in such a way that would cause spamassassin to stop responding, potentially preventing the

delivery or filtering of email.” For more, go to:

https://www.nwfusion.com/go2/0328bug1e.html

**********

Gentoo patches GnuPG

Systems using GnuPG, an open source version of PGP, may leak encrypted data as plaintext. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-29.xml

Gentoo releases Mozilla Suite update

A number of vulnerabilities have been found in the Gentoo implementation of the Mozilla Suite, a browser, news reader and e-mail client in one. These flaws could be exploited to crash the affected machine or potentially run malicious code. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-30.xml

Gentoo issues fix for IPsec-Tools

The racoon network monitoring tool that comes with IPSec-Tools is vulnerable to a denial-of-service attacks. A fix is available:

https://security.gentoo.org/glsa/glsa-200503-33.xml

**********

Today’s roundup of virus alerts:

Troj/Bdoor-FW – A backdoor Trojan that attempts to download files from a pre-defined URL. No word on how it spreads between machines. (Sophos)

Troj/Bancos-BV – Another Trojan that targets customers of Brazilian banking sites. It installs itself as “REGCAIOFT.EXE” in the Windows System directory and looks for passwords entered into the targeted banking sites. (Sophos)

W32/Mytob-B – A mass-mailing worm that spreads through messages that look like a returned e-mail. It drops “TASKGMR.EXE” in the Windows System folder and could allow backdoor access via IRC. It also modifies the Windows HOSTS file to limit access to security Web sites. (Sophos)

W32/Catc-A – A worm that tries to spread by copying itself to the A: drive. How many people still have a floppy drive and if they do, actually use it? One of the files it drops is “folder.exe” in the Windows StartUp folder. (Sophos)

W32.Crowt.B – A mass-mailing worm that uses variable message characteristics to spread. It drops “SERVICES.EXE” in the Startup folder and can be used as a keylogger and opens a backdoor. (Panda Software)

Trj/Downloader.BHV – A virus written in Assembler language that cannot spreads on its own – it requires the user to do something. It drops two files on the infected machine: “4584.EXE” and “BOOT.OLD”. (Panda Software)

Troj/PurScan-W – A Trojan that drops “installer.exe” and “mt-uninstaller.exe” on the infected machine, changes the browser security settings and attempts to download files from a predefined URL. (Sophos)

W32/Agobot-RC – A new Agobot variant that spreads via network shares – those with no or easily guessed passwords – and drops “smrs.exe” on the infected machine. It modifies the Windows HOSTS file to prevent access to security Web sites and allows backdoor access via IRC. (Sophos)

**********