* Patches from Sun, Gentoo, Mandriva, others * Beware virus that spreads through e-mail, displaying the image of an ape
Today’s bug patches and security alerts:
Sun patches Solaris’ automountd
The “automountd” service in Solaris is vulnerable to a denial-of -ervice attack. A local user could kill the automountd process, impacting a number of other applications. For more, go to:
https://sunsolve.sun.com/search/document.do?assetkey=1-26-57786-1
**********
Gentoo patches Oops!
Good name for an application that needs a patch: Oops! A format string vulnerability in the Oops! proxy server could be exploited to run arbitrary code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-02.xml
**********
Fedora, Mandriva patch OpenOffice
A heap overflow in the OpenOffice process used to open DOC files could be exploited to run malicious code on the affected machine. For more, go to:
Fedora:
http://www.networkworld.com/go2/0516bug1a.html
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:082
**********
Gentoo, Mandriva, Ubuntu patch gaim
A couple of vulnerabilities in gaim, an open source instant messaging client, could be exploited to crash the application and to run malicious code on the affected machine. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200505-09.xml
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:086
Ubuntu:
https://www.ubuntulinux.org/support/documentation/usn/usn-125-1
**********
Debian, Mandriva release patch for XFree86
According to the alert from Debian, “A buffer overflow has been discovered in the Xpm library which is used in XFree86. A remote attacker could provide a specially crafted XPM image that could lead to the execution or arbitrary code.” For more, go to:
Debian:
https://www.debian.org/security/2005/dsa-723
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:081
**********
Mandriva, Ubuntu issue fix for Mozilla
A number of vulnerabilities have been found in the Mozilla Firefox browser, which could be exploited to gain elevated privileges and run malicious JavaScript code. For more, go to:
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:088
Ubuntu:
https://www.ubuntulinux.org/support/documentation/usn/usn-124-1
**********
Gentoo, Mandriva, Ubuntu patch gnutls
According to a Mandriva advisory, “Two vulnerabilities were discovered in the GnuTLS library. The first is a vulnerability in the way GnuTLS does record packet parsing; the second is a flaw in the RSA key export functionality. These could be exploited by a remote attacker to cause a Denial of Service to any program using the GnuTLS library.” For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200505-04.xml
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:084
Ubuntu:
https://www.ubuntulinux.org/support/documentation/usn/usn-126-1
**********
Mandriva issues fix for ethereal
A new update for Ethereal (Version 0.10.11), the popular network analysis tool, fixes a number of flaws found in previous releases. These flaws could be exploited to crash the affected machine and to potentially run malicious code. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:083
Mandriva releases patch for kdelibs
The PCX image handling code inside kde could be exploited to run malicious code on the affected machine. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:085
**********
Gentoo, Mandriva fixes DoS flaw in tcpdump
A flaw in the way certain packets are handled by tcpdump could be exploited to crash the application. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200505-04.xml
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:087
**********
Debian patches smail
Malicious code could be run on systems by attackers taking advantage of a buffer overflow in smail, an e-mail transport system. For more, go to:
https://www.debian.org/security/2005/dsa-722
**********
Today’s roundup of virus alerts:
W32/Mytob-CG – A Mytob variant that spreads via e-mail and IRC, dropping “winsvc32.exe” on the infected machine. The infected e-mail message will have a PIF, SCR, EXE or ZIP attachment. It can limit access to security Web sites by modifying the Windows HOSTS file. (Sophos)
W32/Mytob-CH – Another Mytob variant. It acts much like its predecessors and installs “iexplorer.exe” on the infected machine. (Sophos)
W32/Mytob-CA – The third Mytob of the day installs “shell.exe” on the infected machine. (Sophos)
W32/Wurmark-K – A virus that spreads through e-mail, displaying the image of an ape on the infected machine’s screen. The malicious message will have .pif or .scr attachment and the virus can overwrite a number of utility files, including regedit. (Sophos)
W32/Rbot-ACC – This backdoor Trojan spreads by exploiting three known Windows vulnerabilities. It drops “trmupdate.exe”, allows backdoor access via IRC and can be used as a launching point for other attacks. (Sophos)
W32/Rbot-ACE – Another Rbot variant. This one drops “windowsupdate.exe” on the infected machine. (Sophos)
W32/Rbot-AAY – This Rbot variant drops “MSAOL32.exe” in the infected machine’s Windows System folder. (Sophos)
W32/Rbot-ACH – Yet another variant. This one exploits five different Windows flaws in an attempt to infect the machine. It can be used for a number of malicious purposes. (Sophos)
Troj/Whistler-F – A Trojan that drops “whismng.exe” on the infected machine then tries to delete files. (Sophos)
W32/Agobot-SE – A new Agobot variant that spreads through network shares by exploited four known Windows vulnerabilities. It drops “system.exe” in the Windows System folder and provides backdoor access via IRC. (Sophos)
W32/Agobot-SF – Another Agobot worm. Similar to Agobot-SE above, this version drops “holsvc32.exe” on its target. (Sophos)
Troj/Goldun-T – A password stealing Trojan that targets users of the e-gold service. It drops two files on the infected machine: “BOSKGJE.EXE” and “PINCH.EXE”. It spreads via e-mail, looking like an official correspondence from e-gold. (Sophos)
W32/Eyeveg-F – An e-mail worm that spreads through an infected ZIP file. The ZIP will have a number of .scr files in it. It can be used for keylogging and to steal passwords. (Sophos)
Troj/Sqdrop-A – A Trojan that drops two files on the infected machine: “divxenc.exe” and “msld.dll”. No word on what kind of damage it can cause. (Sophos)




