RealNetworks patches RealPlayer

Opinion
Apr 25, 20055 mins

* Patches from RealNetworks,Debian, Gentoo, others * Beware 52 new Symbian Trojans

Audio: DNS cache poisoning

There’s a new type of attack taking place on the Internet and it may me dropping spyware, adware and other malicious code on your machine. The attack, first discovered by the SANS Internet Security Center nearly two months, uses “poisoned” DNS servers to redirect unsuspecting users to hacker controlled sites.  Here to explain what all this means and how you can protect yourself is Ken Dunham, director of malicious code intelligence at iDefense in Reston, Va. Listen in:

https://www.nwfusion.com/research/2005/0425radio.html?nl

Widespread attack cripples computers with spyware, 04/22/05

https://www.nwfusion.com/news/2005/0422widesattac.html?nl

Today’s bug patches and security alerts:

RealNetworks patches RealPlayer

A buffer overflow in the way RAM files are handled by multiple versions of the RealPlayer could be exploited by an attacker to run any code on the targeted machine. RealNetworks has released a patch for the problem. For more, go to:

https://service.real.com/help/faq/security/050419_player/EN/

Related advisories:

Gentoo:

https://security.gentoo.org/glsa/glsa-200504-21.xml

Novell/SuSE:

https://www.nwfusion.com/go2/0425bug1a.html

**********

Debian releases patch for libexif

A buffer overflow in libexif, a tool for parsing EXIF meta information for images, could be exploited to run malicious code on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-709

Debian issues fix for gtkhtml

A denial-of-service vulnerability has been discovered in gtkhtml, a HTML widget for the Evolution mail client. An attacker could exploit this to crash the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-710

Debian patches info2www

A cross-scripting vulnerability has been found in info2www, a tool for converting .info files into HTML. An attacker could put a link on a Web site that could trigger this flaw, which would allow malicious code to be run on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-711

Debian releases fix for geneweb

A flaw in the way geneweb, a genealogy application, handles maintainer scripts could be exploited to modify arbitrary files on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-712

**********

Gentoo warns of flaws in monkeyd

According to an alert from Gentoo, “Format string and Denial of Service vulnerabilities have been discovered in the monkeyd HTTP server, potentially resulting in the execution of arbitrary code.” For more, go to:

https://security.gentoo.org/glsa/glsa-200504-14.xml

Gentoo patches XV

Multiple flaws have been found in XV, an image editing application. These could be exploited to run an attacker’s code of choice on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200504-17.xml

Gentoo fixes overflows in MPlayer

Two buffer overflows have been found in MPlayer, a multimedia player for Gentoo. They could be exploited to run malicious code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200504-19.xml

**********

iDefense warns of flaws in McAfee Internet Security Suite 2005

A flaw in the Access Control List installed by McAfee Internet Security Suite 2005 could be exploited by a local non-Administrator to gain elevated privileges on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0425bug1b.html

**********

SuSE patches postgresql

Multiple buffer overflow vulnerabilities have been found in some of postgresql’s parsing routines. These could be exploited to run malicious code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0425bug1c.html

**********

Mandriva patches xli

A number of buffer overflows have been found in xli, an image handling application. This could be exploited to crash the affected application. For more, go to:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:076

Mandriva issues patches for gnome-vfs2, libcdaudio

A buffer overflow in the way CDDB (metadata about music) is handled by GnomeVFS and libcdaudio could be exploited to run malicious applications on the affected machine. For more, go to:

Gnome-vfs2:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:074

Libcaudio:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:075

**********

Today’s roundup of virus alerts:

52 new Symbian Trojans?

We received the sample set of the 52 files that were claimed to be new Symbian Trojans. And we confirm that, yes the files are malicious. After brief examination it seems that the Trojans are variants of Skulls Trojan, modifications based on Skulls.D. F-Secure Weblog, 04/21/05.

https://www.nwfusion.com/go2/0425bug1d.html

Troj/Dloader-MK – A downloader Trojan that pops up a fake Windows Security message upon infecting a target machine. It can be used to download malicious code from remote sites. (Sophos)

W32/Sdbot-XH – An Sdbot variant that drops “windesktop.exe” after spreading through a network share and exploiting one of three known Windows vulnerabilities. It allows backdoor access via IRC and can limit access to security Web sites by modifying the Windows HOSTS file. (Sophos)

W32/Rbot-AAY – Another network worm that exploits a number of known Windows vulnerabilities in an attempt to infect a machine. It installs “MSAOL32.exe” in the Windows System directory and allows backdoor access via IRC. It can be used to steal information from the infected machine. (Sophos)

W32/Nopir-B – A worm that displays an anti-piracy message on the infected machine as it attempts to delete all COM and MP3 files. It can also disable a number of Windows administration applications such as Task Manager. (Sophos)

W32/Mytob-AG – A new Mytob mass mailing/network worm. This variant drops “w32NTupdt.exe” on the infected machine. The infected message has an attachment with the file types of pif, scr, exe, cmd, or bat. (Sophos)

W32/Mytob-AH – Very similar to Mytob-AG above, except this variant installs “hostdrvXP.exe” on the infected machine. (Sophos)

Troj/Kelvir-R – A new Kelvir variant that spreads via MSN Messenger. It tries to get the targeted user to visit a malicious Web site. (Sophos)