* Patches from SCO, Gentoo, SuSE, others * Beware Sober variant tricking users in German
A reader passed this site along through one of our editors: http://sarcaprj.wayreth.eu.org/
A reader passed this site along through one of our editors:
https://sarcaprj.wayreth.eu.org/
It claims to be a Windows password cracker. Use at your own risk!
Today’s bug patches and security alerts:
Apple releases security fix for iSync 1.5
A buffer overflow in one of the iSync functions could lead to privilege escalation on the affected machine. The attacker could then run malicious code on the affected machine. For more, go to:
https://docs.info.apple.com/article.html?artnum=301326
**********
SCO patches overflow in OpenServer
A buffer overflow in the Home environment variable could cause a number of applications to crash. A fix is available.
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.15
SCO releases fix for UnixWare’s CDE dtlogin
According to an alert from SCO, “By sending a specially-crafted XDMCP packet to a vulnerable system, a remote attacker could obtain sensitive information, cause a denial of service or execute arbitrary code on the system.” For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.18
SCO issues patch for UnixWare’s libtiff
A number of buffer and integer overflows have been found in libtiff, an image handling application. An attacker could run malicious code via a specially crafted TIFF file. For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.19
SCO patches UnixWare’s cdrecord
The cdrecord application, when installed with root privileges, does not properly drop those privileges after the installation is complete. An attacker could exploit this to gain root privileges on the affected machine. For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.20
SCO offers patch for OpenServer’s cscope
A local attacker could exploit the temporary files created by cscope to gain elevated privileges on the affected machine. For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.20
SCO patches telnet client for UnixWare
According to an alert from SCO, “Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.” For more, go to:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.21
**********
Gentoo patches GnomeVFS, libcdaudio
A buffer overflow in the way CDDB (metadata about music) is handled by GnomeVFS and libcdaudio could be exploited to run malicious applications on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-07.xml
Gentoo releases fix for phpMyAdmin
A cross-scripting vulnerability has been found in the phpMyAdmin code. An attacker could exploit this to run malicious script code. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-08.xml
Gentoo warns of flaws in Gld
Gld, a greylist server for Postfix, contains a number of vulnerabilities that could be exploited by an attacker to run any code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-10.xml
Gentoo patches multiple flaws in JunkBuster
Flaws in JunkBuster, a filtering HTTP proxy, could be exploited to modify the applications setting. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-11.xml
Gentoo releases patch for rsnapshot
A vulnerability in rsnapshot, a backup and restore utility, could be exploited by an attacker to take control of files on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-12.xml
**********
FreeBSD patches iconf
A flaw in iconf, a tool for auditing kernel memory, could leak sensitive information to an attacker. For more, go to:
https://www.nwfusion.com/go2/0418bug2a.html
**********
Gentoo, SuSE patch CVS
A number of vulnerabilities in CVS, a version control system, could be exploited to take control of the server or cause a denial of service. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200504-16.xml
SuSE:
https://www.novell.com/linux/security/advisories/2005_24_cvs.html
**********
Gentoo, Mandriva (formerly Mandrake Linux) patch PHP
A number of vulnerabilities have been found in the popular PHP scripting language. The flaws could be exploited in a denial-of-service attack or to potentially run arbitrary code. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200504-15.xml
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:072
**********
Conectiva, OpenPKG release patch for MySQL
A couple of vulnerabilities have been found in the popular MySQL database. An attacker could exploit this to gain access to another user’s account and to potentially run malicious code on the affected machine. For more, go to:
Conectiva:
https://www.nwfusion.com/go2/0418bug2b.html
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2005.006-mysql.html
**********
Today’s roundup of virus alerts:
New Sober variant tricks users in German
W32.Sober.N@mm sends e-mail messages with the subject headers “I’ve got your EMail on my account!” and “FwD: Ich bin’s nochmal” and carries attachments with names like your_text.zip, according to Helsinki security firm F-Secure. When opened, the attachment scans files on the infected computer to harvest e-mail addresses that enable the worm to spread. IDG News Service, 04/19/05.
https://www.nwfusion.com/news/2005/0419newsober.html?nl
W32/Kelvir-J – Another worm that spreads via the Windows Messenger client by sending a URL to all users listed in the infected user’s contact list. (Sophos)
Troj/Kelvir-P – A similar Windows Messenger worm that attempts to get the target user to visit a malicious Web site. (Sophos)
W32/Tirbot-D – This bot spreads through network shares by exploiting the Windows LSASS vulnerability. It can allow backdoor access and be used for a number of malicious applications, including sniffing for data, execute files and act as a proxy server. (Sophos)
Troj/DoomSend-A – A MyDoom derivative that looks like a message claiming to be from a Web site visitor having link problems and the Mozilla browser. The attached ZIP file is supposed to hold a screen capture of the problem, but is really malicious code. (Sophos)
W32/Agobot-RM – A new Agobot variant that drops “CRSS.exe” in the Windows System folder after spreading through a network share. It can allow backdoor access via IRC, delete network shares, launch DoS attacks, sniff network packets and more. It can also limit access to security-related Web sites by modifying the Windows System folder. (Sophos)
W32/Agobot-RN – This Agobot variant installs “ip7.exe” in the Windows System folder and allows backdoor access via IRC. It modifies the Windows HOSTS file to limit access to security Web sites. (Sophos)
Troj/Dloader-LR – A Trojan that injects code into explorer and downloads tried to download the file “NORTAN2122.EXE”. (Sophos)
Troj/Dloader-LW – Another Trojan that is similar to Dloader-LR above, except it downloads “service.exe” in to the target machine’s system directory. (Sophos)
Troj/Banker-CH – A password stealing Trojan that targets Brazilian banking sites. It uses a random filename for the infected executable. (Sophos)
Troj/Delbot-B – A Trojan that makes the infected machine a zombie for a remote attacker. It drops “cftmon.exe” in the Windows System folder and can disable anti-virus applications. (Sophos)
W32/Sdbot-XH – A bot that drops “windesktop.exe” in the infected machine’s Windows System folder. It spreads via network shares by exploiting a number of known Windows vulnerabilities. (Sophos)




