* Patches from Apple, CA, Veritas, others * Beware Trojan that installs itself as "IExplorer.exe"
A little self-promotion off the top with a feature that I wrote in this week’s issue of Network World:
Is your cell phone at risk?
Not at the moment, although new strains of viruses that infect smartphones pose yet another network security problem that you’ll have to worry about in the future. Network World, 04/18/05.
https://www.nwfusion.com/research/2005/041805-mobile-virus.html?nl
We also have a related Radio “broadcast” on the subject:
https://www.nwfusion.com/research/2005/0418radio.html?nl
Today’s bug patches and security alerts:
Apple patches kernel, Safari for Mac OS X
Apple has released a new update that fixes a number of flaws in the Mac OS X kernel. The most serious of these vulnerabilities could be exploited by an attacker to gain elevated privileges on the affected machine. Also included in the release is an update for the Safari browser that closes a loophole that would allow JavaScript to run in the local domain. For more, go to:
https://docs.info.apple.com/article.html?artnum=301327
**********
Computer Associates patches BrightStor ARCserve
A buffer overflow vulnerability has been found in CA’s BrightStor ARCserve Backup UniversalAgent. An attacker could exploit this to gain access to the affected system and potentially any other system that connects to it. The attacker could also run malicious code. For more, go to:
https://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32727
ISS advisory:
https://xforce.iss.net/xforce/alerts/id/194
iDefense advisory:
https://www.nwfusion.com/go2/0418bug1a.html
**********
IBM releases fix for Domino flaw
NGSSoftware is warning of a “high risk” vulnerability in IBM Lotus Domino. An attacker could run malicious code via a POST request. NGSSoftware is not releasing full details for three months. For more, go to:
https://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21202431
NGSSoftware advisory:
https://www.ngssoftware.com/advisories/lotus-01.txt
**********
Veritas issues patch for i3 Focalpoint Server
A “critical vulnerability” has been found in Vertias’ i3 Focalpoint Server by NGSSoftware, which is used in Oracle and other applications. NGSSoftware is not publishing details for three months to allow time for patches to be distributed and installed. A fix is available:
https://seer.support.veritas.com/docs/276119.htm
NGSSoftware advisory:
https://www.ngssoftware.com/advisories/veritas-01.txt
**********
Oracle releases patch for Database 10g
NGSSoftware is reporting multiple vulnerabilities in the Oracle Database 10g. Again, they’re not reporting the details for three months, but a fix is available:
https://www.nwfusion.com/go2/0418bug1b.html
NGSSoftware advisory:
https://www.ngssoftware.com/advisories/oracle-03.txt
**********
Vulnerabilities found, patched in PHP
NGSSoftware is reporting a number of “medium risk” flaws in the PHP scripting engine. Despite PHP being open source, the company is not releasing full details for three months. An update can be downloaded here:
https://www.php.net/downloads.php
NGSSoftware advisory:
https://www.ngssoftware.com/advisories/php-01.txt
Debian PHP update:
https://www.debian.org/security/2005/dsa-708
**********
Mandriva (formerly Mandrake Linux) patches gaim
Gaim, an open source instant messaging client, contains a number of denial-of-service vulnerabilities. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:071
**********
Gentoo patches OpenOffice
A buffer overflow in the OpenOffice suite could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-13.xml
**********
Today’s roundup of virus alerts:
W32/Mytob-E – A new Mytob variant that spreads through e-mail and IRC. It installs itself as “taskgmr.exe” and comes in a .scr attachment. It can limit access to security related Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Mytob-BA – Another Mytob variant that is very similar to Mytob-E above. It exploits the Windows LSASS vulnerability when it spreads through IRC and a .scr attachment in e-mail. (Sophos)
Troj/Bancos-CD – A Trojan that installs itself as “IExplorer.exe” and can be used to monitor a user’s browser activity, looking for information related to online banking. (Sophos)
Troj/Bancos-CG – Another Trojan targeting banking sites. This variant installs itself as “jdbgmgrnt.exe”. (Sophos)
W32/Codbot-K – This network worm spreads by exploiting the Windows LSASS vulnerability. It drops “SCardClnt.exe” on the infected machine and can be used to steal local information. (Sophos)
Troj/Agent-DI – A Trojan that spreads via network shares and installs itself as “svchost.exe”. It can limit the Windows firewall and disable anti-virus warnings. (Sophos)
Gaobot.EYP – This Trojan spreads via network shares by exploiting a number of known vulnerabilities in Windows. It drops “MSNMESSAG.EXE” in the Windows System folder. It provides backdoor access via IRC and can be used for a number of malicious purposes. (Panda Software)
SymbOS/Hobbes.A – A mobile virus (see links at the top of this newsletter) that spreads to Symbian phones through an infected SIS file. Hobbes.A disables the application menu. (F-Secure)
W32/Sdbot-XC – A new bot that spreads by exploiting a number of known Windows vulnerabilities. It drops “systeminfos.exe” in the Windows System folder and can allow backdoor access via IRC. It can be used for a number of purposes, including starting a stealth FTP server. (Sophos)
Troj/BagleDl-N – A Bagle variant that spreads via an infected RAR archive file sent through e-mail. It drops malware on the infected machine. (Sophos)
**********




