* Patches from Oracle, Novell, Netscape others * Beware new Mytob variants
Today’s bug patches and security alerts:
Multiple flaws found in MySQL MaxDB
Three flaws have been found in the popular MySQL MaxDB database application. An attacker could exploit these to run malicious code on the affected machine. For more, go to:
https://dev.mysql.com/downloads/maxdb/7.5.00.html
Related iDefese advisories:
MySQL MaxDB Webtool Remote Lock-Token Stack Overflow Vulnerability
http://www.networkworld.com/go2/0502bug1a.html
MySQL MaxDB Webtool Remote Stack Overflow Vulnerability
http://www.networkworld.com/go2/0502bug1b.html
MySQL MaxDB Webtool Remote ‘If’ Stack Overflow Vulnerability
http://www.networkworld.com/go2/0502bug1c.html
**********
CERT warns of Oracle flaws
Oracle released an update last month that covers some 70-odd flaws in different applications. CERT is urging Oracle customers to download and install relevant patches. For more, go to:
CERT advisory:
https://www.us-cert.gov/cas/techalerts/TA05-117A.html
Oracle’s April advisory:
http://www.networkworld.com/go2/0502bug1d.html
**********
Critical flaw reported in Netscape
A “highly critical” unpatched vulnerability in the Netscape browser could potentially allow hackers to compromise Internet users’ systems, according to an advisory from a Danish security firm. The buffer overflow vulnerability could cause the browser to crash. In addition, hackers could create Web sites to exploit the flaw, executing code of their choice on visitors’ computers to gain access to users’ systems, security company Secunia warned. IDG News Service, 04/27/05.
https://www.nwfusion.com/news/2005/0427critiflaw.html
Secunia advisories:
Netscape GIF Image Netscape Extension 2 Buffer Overflow
https://secunia.com/advisories/15103/
Netscape DOM Nodes Validation Vulnerability
https://secunia.com/advisories/15135/
**********
Novell releases fix for Nsure Audit
According to an advisory from Panda Software, “A remote user could construct a brute force attack against ‘webadmin.exe’ in TCP port 449 to cause the system under attack not to respond. The problem lies in the fact that Novell Nsure Audit does not adequately handle ASN.1 messages sent via SSL. A remote user could run a tool to carry out brute force ASN.1 attacks over OpenSSL and in this way cause the system to crash.” A fix from Novell is available:
http://www.networkworld.com/go2/0502bug1e.html
**********
Input validation flaw in BEA WebLogic
SecurityTracker is warning of an input validation flaw in the BEA WebLogic administration console. The “JndiFramesetAction” function is vulnerable to a cross-scripting attack. An attacker could exploit this to take action with administrator privileges on the affected system. For more, go to:
https://www.securitytracker.com/alerts/2005/Apr/1013817.html
**********
Adobe patches Reader ActiveX control
A flaw in the Adobe Reader ActiveX control could be exploited by an attacker to see if certain files are present on the target machine. Adobe has fixed the problem in Version 7.0.1. For more, go to:
https://www.adobe.com/support/techdocs/331465.html
**********
Conectiva, Debian patch gaim
A flaw in gaim, an open source instant messenger client, could be exploited by sending malformed SNAC packets. Gaim could be put into an infinite loop when it gets one of these malformed packets. For more, go to:
Conectiva:
http://www.networkworld.com/go2/0502bug1f.html
Debian:
https://www.debian.org/security/2005/dsa-716
**********
Conectiva, Mandriva patch Squid
A flaw in Squid 2.5, a proxy server, could be exploited by an attacker to bypass the system’s access control list. For more, go to:
Conectiva:
http://www.networkworld.com/go2/0502bug1g.html
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:078
**********
Today’s roundup of virus alerts:
W32/Mytob-AI — A new Mytob variant that spreads via e-mail and IRC. It exploits the Windows LSASS vulnerability and drops “svchost32.exe” in the Windows System folder. The infected e-mail attachment will be a .scr file. (Sophos)
W32/Mytob-AJ — Very similar to Mytob-AI above, except this variant uses “taskgmr.exe” as its infection point. (Sophos)
W32/Mytob-AK — Yet another Mytob variant. This one drops “taskgmr32.exe” on the infected machine. (Sophos)
W32/Mytob-BW — A fourth Mytob variant to report. Again, similar to its predecessors, but uses “EXPLORER.exe” as the infected Windows System folder. (Sophos)
W32/Mytob-BT — Number five on the day. This one installs “taskgmrs.exe” on the infected machine. (Sophos)
W32/Sdbot-WM — An Sdbot variant that tries to pass itself off as a “Microsoft Windows Update”. It spreads through network shares and installs “MSNMSGR.EXE” on the infected machine. It can be used to log keystrokes, storing the captured data in “KEYLOG.TXT”. (Sophos)
W32/Sdbot-ZC — This Sdbot variant drops “wnmgre.exe” on the infected machine and can be controlled remotely via IRC. An attacker can use this to launch DoS attacks against remote sites and download malicious code. (Sophos)
W32/Antiman-A — A worm that spreads through e-mail by pretending to be a new screen saver. It drops “startwin.exe” in the Windows Startup folder. The infected attachment will be an .exe file. (Sophos)
W32/Icpass-A — A Windows worm that installs “system.exe” in the system folder and creates a number of ZIP archives on the infected machine. (Sophos)
W32/Kassbot-C — This Trojan looks to steal information entered into specific banking Web sites. It spreads through network shares, installs “spools.exe” and allows backdoor access via IRC. (Sophos)
W32/Banish-A — An e-mail worm that looks like a reply to a query the targeted user made. It drops smss.exe, lsass.exe, csrss.exe, services.exe, and winlogon.exe on the infected machine. It will attempt to delete files in the Windows Repair directory. (Sophos)




