* Patches from RealNetworks,Debian, Gentoo, others * Beware 52 new Symbian Trojans
Audio: DNS cache poisoning
There’s a new type of attack taking place on the Internet and it may me dropping spyware, adware and other malicious code on your machine. The attack, first discovered by the SANS Internet Security Center nearly two months, uses “poisoned” DNS servers to redirect unsuspecting users to hacker controlled sites. Here to explain what all this means and how you can protect yourself is Ken Dunham, director of malicious code intelligence at iDefense in Reston, Va. Listen in:
https://www.nwfusion.com/research/2005/0425radio.html?nl
Widespread attack cripples computers with spyware, 04/22/05
https://www.nwfusion.com/news/2005/0422widesattac.html?nl
Today’s bug patches and security alerts:
RealNetworks patches RealPlayer
A buffer overflow in the way RAM files are handled by multiple versions of the RealPlayer could be exploited by an attacker to run any code on the targeted machine. RealNetworks has released a patch for the problem. For more, go to:
https://service.real.com/help/faq/security/050419_player/EN/
Related advisories:
Gentoo:
https://security.gentoo.org/glsa/glsa-200504-21.xml
Novell/SuSE:
https://www.nwfusion.com/go2/0425bug1a.html
**********
Debian releases patch for libexif
A buffer overflow in libexif, a tool for parsing EXIF meta information for images, could be exploited to run malicious code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-709
Debian issues fix for gtkhtml
A denial-of-service vulnerability has been discovered in gtkhtml, a HTML widget for the Evolution mail client. An attacker could exploit this to crash the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-710
Debian patches info2www
A cross-scripting vulnerability has been found in info2www, a tool for converting .info files into HTML. An attacker could put a link on a Web site that could trigger this flaw, which would allow malicious code to be run on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-711
Debian releases fix for geneweb
A flaw in the way geneweb, a genealogy application, handles maintainer scripts could be exploited to modify arbitrary files on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-712
**********
Gentoo warns of flaws in monkeyd
According to an alert from Gentoo, “Format string and Denial of Service vulnerabilities have been discovered in the monkeyd HTTP server, potentially resulting in the execution of arbitrary code.” For more, go to:
https://security.gentoo.org/glsa/glsa-200504-14.xml
Gentoo patches XV
Multiple flaws have been found in XV, an image editing application. These could be exploited to run an attacker’s code of choice on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-17.xml
Gentoo fixes overflows in MPlayer
Two buffer overflows have been found in MPlayer, a multimedia player for Gentoo. They could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-19.xml
**********
iDefense warns of flaws in McAfee Internet Security Suite 2005
A flaw in the Access Control List installed by McAfee Internet Security Suite 2005 could be exploited by a local non-Administrator to gain elevated privileges on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0425bug1b.html
**********
SuSE patches postgresql
Multiple buffer overflow vulnerabilities have been found in some of postgresql’s parsing routines. These could be exploited to run malicious code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0425bug1c.html
**********
Mandriva patches xli
A number of buffer overflows have been found in xli, an image handling application. This could be exploited to crash the affected application. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:076
Mandriva issues patches for gnome-vfs2, libcdaudio
A buffer overflow in the way CDDB (metadata about music) is handled by GnomeVFS and libcdaudio could be exploited to run malicious applications on the affected machine. For more, go to:
Gnome-vfs2:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:074
Libcaudio:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:075
**********
Today’s roundup of virus alerts:
52 new Symbian Trojans?
We received the sample set of the 52 files that were claimed to be new Symbian Trojans. And we confirm that, yes the files are malicious. After brief examination it seems that the Trojans are variants of Skulls Trojan, modifications based on Skulls.D. F-Secure Weblog, 04/21/05.
https://www.nwfusion.com/go2/0425bug1d.html
Troj/Dloader-MK – A downloader Trojan that pops up a fake Windows Security message upon infecting a target machine. It can be used to download malicious code from remote sites. (Sophos)
W32/Sdbot-XH – An Sdbot variant that drops “windesktop.exe” after spreading through a network share and exploiting one of three known Windows vulnerabilities. It allows backdoor access via IRC and can limit access to security Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Rbot-AAY – Another network worm that exploits a number of known Windows vulnerabilities in an attempt to infect a machine. It installs “MSAOL32.exe” in the Windows System directory and allows backdoor access via IRC. It can be used to steal information from the infected machine. (Sophos)
W32/Nopir-B – A worm that displays an anti-piracy message on the infected machine as it attempts to delete all COM and MP3 files. It can also disable a number of Windows administration applications such as Task Manager. (Sophos)
W32/Mytob-AG – A new Mytob mass mailing/network worm. This variant drops “w32NTupdt.exe” on the infected machine. The infected message has an attachment with the file types of pif, scr, exe, cmd, or bat. (Sophos)
W32/Mytob-AH – Very similar to Mytob-AG above, except this variant installs “hostdrvXP.exe” on the infected machine. (Sophos)
Troj/Kelvir-R – A new Kelvir variant that spreads via MSN Messenger. It tries to get the targeted user to visit a malicious Web site. (Sophos)




