* Patches from Debian, Mandriva, Gentoo, others * Beware Trojan that looks to steal information entered into banking Web sites
endif; ?>Today’s bug patches and security alerts:
Linux vendors patch cvs
A number of vulnerabilities in CVS, a version control system, could be exploited to take control of the server or cause a denial of service. For more, go to:
FreeBSD:
https://www.nwfusion.com/go2/0425bug2a.html
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:073
Trustix:
https://www.trustix.org/errata/2005/0013/
**********
Debian patches samba
A bug in a previous fix for samba, a print/file server, caused the module to crash when it was reloaded. This update fixes that problem. For more, go to:
https://www.debian.org/security/2005/dsa-701
Debian issues fix for junkbuster
Flaws in JunkBuster, a filtering HTTP proxy, could be exploited to modify the applications setting. For more, go to:
https://www.debian.org/security/2005/dsa-713
**********
Mandriva patches cdrecord
The cdrecord application, when installed with root privileges, does not properly drop those privileges after the installation is complete. An attacker could exploit this to gain root privileges on the affected machine. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:077
**********
Gentoo releases patch for openMosixview
According to a Gentoo advisory, “openMosixview and the openMosixcollector daemon are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.” For more, go to:
https://security.gentoo.org/glsa/glsa-200504-20.xml
**********
KDE warns of flaw in Kommander
The Kommander visual editor may execute code without user intervention. This could be exploited to run malicious scripts on the affected machine. For more, go to:
https://www.kde.org/info/security/advisory-20050420-1.txt
Related patch from Gentoo:
https://security.gentoo.org/glsa/glsa-200504-23.xml
**********
KDE patches kimgio
A flaw in the way PCX images are handled by kimgio could be exploited to run malicious code on the affected machine. For more, go to:
https://www.kde.org/info/security/advisory-20050421-1.txt
Related Gentoo patch:
https://security.gentoo.org/glsa/glsa-200504-22.xml
**********
Today’s roundup of virus alerts:
Troj/CashGrab-A – A Trojan that looks to steal information entered into banking Web sites, such as user name and password. It installs a number of files on the infected machine including “WINSETUP.EXE” and “MSUPDATE.DLL”. (Sophos)
Troj/CashGrab-B – Very similar to CashGrab-A above, except the installed files have different names. The two key files are “IAINST.EXE” and “IA.DLL”. (Sophos)
W32/LegMir-AD – A password stealing Trojan that sends its captured information to a hard coded e-mail address. It drops “folder.exe” in the infected machine’s root directory. (Sophos)
W32/Rbot-ABB – A backdoor Trojan that spreads via network shares by exploiting a couple of known Windows vulnerabilities. It installs “msaol32.exe” in the infected machine’s root directory. It provides access via IRC and can be used as a proxy, keystroke logger, denial-of-service zombie and more. (Sophos)
W32/Wurmark-I – A mass-mailing worm that spreads through an attachment called “attachment.zip”. It harvests new e-mail address to target from the infected host and can block system utilities from running by writing dummy files to the hard drive. (Sophos)




