* Patches from Microsoft, Cisco, Apple, others * Beware new variants of the Mytob mailer/IRC worm * In-depth investigation of the 'Cabir-in-Cars' myth
Today’s bug patches and security alerts:
Microsoft’s new patch fixes remote code-execution hole
Microsoft Tuesday released its monthly security update with a patch to repair a newly discovered “important” vulnerability in Windows that can allow remote code execution in Windows Explorer. Both Windows 2000 Service Pack 3 and Windows 2000 Service Pack 4 are affected by the security bulletin. The vulnerability is not found in Windows XP or 64-bit XP, or in Windows Server 2003 and Server 2003 64-bit operating systems, according to the company. Computerworld, 05/10/05.
http://www.networkworld.com/news/2005/051005-microsoft-patch.html
Microsoft advisory:
https://www.microsoft.com/technet/security/Bulletin/MS05-024.mspx
**********
Cisco patches Firewall Services Module
According to an alert from Cisco, “The Cisco Firewall Services Module (FWSM) is a high-speed, integrated firewall module for Catalyst 6500 series switches and Cisco 7600 series routers. A vulnerability exists in the Cisco Firewall Services Module when URL, FTP, or HTTPS filtering is enabled in which inbound TCP packets can bypass access-list entries intended to explicitly filter them.” For more, go to:
https://www.cisco.com/warp/public/707/cisco-sa-20050511-url.shtml
**********
Secunia warns of Firefox vulnerabilities
Two serious flaws have been found in the Mozilla-based Firfox Web browser, according to security experts at Secunia. An attacker could exploit the flaws to run malicious JavaScript code with elevated system privileges. Workarounds and a fix are available. For more, go to:
Secunia advisory:
https://secunia.com/advisories/15292/
Mozilla advisory:
https://www.mozilla.org/security/announce/mfsa2005-42.html
**********
Apple patches popular iTunes
A buffer overflow vulnerability in Apple’s popular iTunes player could be exploited with a specially crafted MPEG-4 file. This could cause the application to crash and potentially allow the attacker to run malicious code. Users should upgrade to iTunes 4.8. For more, go to:
https://docs.info.apple.com/article.html?artnum=301596
**********
Macromedia issues fix for ColdFusion’s JRun Web Server
The JRun Web Server that comes bundled with Macromedia’s ColdFusion MX 7 contains a default error page that is vulnerable to a cross-scripting attack. Normally, the affected product is not run in a manner that would allow this flaw to be exploited, but Macromedia is releasing a fix nonetheless. For more, go to:
http://www.networkworld.com/go2/0509bug2b.html
**********
NISCC warns of IPSec vulnerabilities
The U.K’s National Infrastructure Security Co-ordination Centre (NISCC) is warning that IPSec traffic could be decrypted and read without much effort. NISCC says that there are three potential attacks that could impact certain IPSec configurations. For more, go to:
https://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en
**********
Gentoo patches Horde Framework
A flaw in the Horde Framework, a PHP-based system for building applications, could be exploited in a cross-scripting attack to run malicious HTML and script code in the target user’s browser. For more, go to:
https://www.gentoo.org/security/en/glsa/glsa-200505-01.xml
Gentoo releases fix for phpMyAdmin
The phpMyAdmin tool, which allows Web-based access to MySQL administration settings, does not delete its SQL install script. This could be exploited by a local user to gain the database’s password and gain further access to data. For more, go to:
https://security.gentoo.org/glsa/glsa-200504-30.xml
**********
Debian, Trustix issue fixes for Squid
A flaw in Squid 2.5, a proxy server, could be exploited by an attacker to bypass the system’s access control list. For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-721
Trustix:
https://www.trustix.org/errata/2005/0021/
**********
Debian patches smartlist
A flaw in the confirm add-on of smartlist, a mailing list manager, could allow arbitrary addresses to be added to the database without the user’s knowledge. For more, go to:
https://www.debian.org/security/2005/dsa-720
**********
Today’s roundup of virus alerts:
W32/Mytob-CC – A new variant of the Mytob mailer/IRC worm. (One group reports there are now some 100+ Mytob variants). This one exploits the Windows LSASS vulnerability and installs itself as “taskgmr.exe” in the Windows System directory. It can block access to security-related Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Mytob-CE – Very similar to Mytob-CC above. It too can harvest e-mail addresses from the infected machine. It spreads through an e-mail attachment with an extension of BAT, CMD, PIF, SCR, EXE or ZIP. (Sophos)
W32/Mytob-AJ – Another Mytob variant that uses similar characteristics to the two above. It looks like it comes from the FBI, Symantec, Microsoft or Yahoo. (Sophos)
W32/Mytob-BC – This Mytob variant uses an e-mail that looks like an account termination message. It too attempts to block access to security sites by modifying the Windows HOSTS file. (Sophos)
W32/Mytob-CF – Another Mytob that tries to mimic an account termination message. This one drops “1hellbot.exe” on the infected machine. (Sophos)
Troj/Viper-A – A downloader application that attempts to install “WMPLAYER.EXE” and “WMPLAYER2.EXE” on the infected machine. (Sophos)
W32/Sdbot-YB – An Sdbot variant that spreads through network shares and allows backdoor access via IRC. It drops “dewa.exe” in the Windows System folder. (Sophos)
W32/Rbot-ABX – An Rbot variant that spreads through network shares by exploiting one of three known Windows vulnerabilities. It drops “atiupdxx.exe” in the Windows System folder. It can allow backdoor access through IRC and be used for a number of malicious purposes. (Sophos)
Kedebe.C – This worm spreads via e-mail using variable message characteristics. It disables access to security-related Web sites and terminates anti-virus processes running on the infected machine. (Panda Software)
Bck/BotMail.C – A worm that operates similar to the SDBot variants, spreading through network shares and acting as a proxy for other malicious activity. (Panda Software)
Troj/LanFilt-J – This Trojan installs itself as “mshost.exe” in the Windows System folder and can be used to steal information from the infected machine. It sends the bounty to a remote Web site. (Sophos)
W32/Nopir-B – A Windows worm that displays an anti-piracy message/image on the infected machine. As it does, it attempts to delete all .COM and .MP3 files as well as disable a number of Window utilities, such as task manager. (Sophos)
**********
From the interesting reading department:
In-depth investigation of the ‘Cabir-in-Cars’ myth
The security guys at F-Secure decided to find out if Bluetooth-equipped vehicles can be infected by the Cabir virus. Here’s what they found and how they did the test:
http://www.networkworld.com/go2/0509bug2a.html




