* Patches from Trustix, HP, SuSE, others * Spread of new Sober variant slowing
Today’s bug patches and security alerts:
Apple releases massive security patch
A new update from Apple fixes 20 different applications in the Mac OS X operating system. Sounds more like Windows than Mac. The release patches problems in Apache, AppKit, AppleScript, Bluetooth, Directory Services, Finder, Foundation, Help Viewer, LDAP, libXpm, lukemftpd, NetInfo, Server Admin, sudo, Terminal and VPN. For more, go to:
https://docs.info.apple.com/article.html?artnum=301528
**********
Trustix patches postgresql
Multiple buffer overflows have been found in the postgresql object-relational database. These flaws could be exploited to run malicious code on the affected machine. For more, go to:
https://www.trustix.org/errata/2005/0015/
**********
Gentoo issues fix for eGroupWare
A number of cross scripting and SQL injection vulnerabilities have been discovered in eGroupWare, an open source groupware application for e-mail, calendars and address books. An attacker could exploit these flaws to gain access to the underlying database or potentially run damaging code. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-24.xml
Gentoo releases patch for Rootkit Hunter
Rootkit Hunter, a tool for detecting potential security risks, is itself vulnerable to a symlink attack. An attacker could exploit this to potentially gain root privileges on the affected system. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-25.xml
Gentoo patches Convert-UUlib
According to an alert from Gentoo, “A vulnerability has been reported in Convert-UUlib where a malformed parameter can be provided by an attacker allowing a read operation to overflow a buffer. The vendor credits Mark Martinec and Robert Lewis with the discovery. Successful exploitation would permit an attacker to run arbitrary code with the privileges of the user running the Perl application.” For more, go to:
https://security.gentoo.org/glsa/glsa-200504-26.xml
**********
Hewlett-Packard patches HP-UX TCP/IP Remote Denial of Service
According to an alert from HP, “Certain network traffic can result in a Denial of Service (DoS) for HP-UX systems running TCP/IP (IPv4). Receiving a certain packet on any open TCP/IP connection can result in a Denial of Service (DoS) condition which can only be corrected by a reboot of the affected system.” For more, go to:
http://www.networkworld.com/go2/0502bug2c.html
HP fixes OpenView Radia Management Portal and Radia Management Agent
A flaw in the HP Radia Management Portal (RMP) and Radia Management Agent (RMA) could be exploited to gain elevated privileges on the affected machine and potentially cause a denial of service. A patch is available by logging into the HP Support site:
https://itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01138
**********
Debian patches kdelibs
A flaw in the way kdelibs handles certain image formats could be exploited to run malicious code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-714
Debian releases fix for cvs
A new update for cvs, the open source change management system, fixes two flaws. One flaw could be exploited to bypass cvs’ password protection and the other could be exploited in a denial-of-service attack. For more, go to:
https://www.debian.org/security/2005/dsa-715
**********
SuSE releases update for Mozilla Firefox
A new update for the open source Mozilla Firefox browser fixes a number of security vulnerabilities that could leave an affected machine open to attack, including having malicious code run on it. For more, go to:
http://www.networkworld.com/go2/0502bug2b.html
**********
Today’s roundup of virus alerts:
Spread of new Sober variant slowing down
A new variant of the Sober e-mail worm is still spreading on the Internet, but at a much slower rate than on Monday when it was the most prevalent worm on the ‘Net. The worm was first discovered on Monday at about 9 a.m. Pacific time, according to McAfee, a vendor of anti-virus products. McAfee rates the worm a “medium” risk for home users, but sees less risk for corporate users, said Craig Schmugar, a virus research manager at the Santa Clara, Calif.-based company. IDG News Service, 05/03/05
http://www.networkworld.com/go2/0502bug2a.html
W32/MyDoom-BN — A new MyDoom variant that spreads via e-mail opens Notepad to display random strings. It drops “taskmon.exe” in the Windows System folder and can allow backdoor access. The infected attachment will have an extension of bat, cmd, exe, pif, scr and zip. (Sophos)
W32/Kelvir-D — A Windows Messenger worm that tries to get the targeted user to visit a malicious Web site. If successful, the worm will try to download “ME.JPG” and “FILE.EXE”. (Sophos)
W32/Agobot-RV — A backdoor Trojan that can be used for a number of applications, including acting as a proxy, starting an FTP server, opening a command shell and more. The virus exploits the Windows RPC DCOM and MSSQL vulnerabilities, and can shut down anti-virus software. (Sophos)
W32/Rbot-ABO — This Rbot variant looks for target machines on Port 445. It exploits weak passwords and drops “winmys.exe” in the Windows system directory. It can terminate security applications running on the infected machine. (Sophos)
Troj/PcClient-R — This backdoor Trojan installs itself as the service “Task Scheduler”. It uses a random file name and can bypass firewall implementations. (Sophos)
W32/Mytob-E — This mass-mailer/backdoor Trojan drops “taskgmr.exe” in the Windows System folder. In e-mail, it spreads through an infected .scr file. It can limit access to security Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Sdbot-XV — An Sdbot variant that installs “mskev.exe” in the Windows System folder. It allows backdoor access via IRC and can be used to scan for network vulnerabilities as well as download and execute code. (Sophos)
W32/Sdbot-XW — Similar to Sdbot-XV above, except this variant drops “run.exe” in the Windows system directory. (Sophos)
Troj/LegMir-DR — A password-stealing Trojan that installs “wsock32.dll” on the infected machine. It stores its data in “C:mir2.txt” and sends information to its author via FTP. (Sophos)




