* Patches from Gentoo, Conectiva, Fedora, others * Beware mass-mailer worm that looks like a security or account warning
Today’s bug patches and security alerts:
More Mozilla updates: Fedora, Gentoo, SCO
A problem with the way permissions are set when XPI packages installed may leave a system vulnerable. A local user could steal information or potentially run malicious code. For more, go to:
Fedora:
http://www.networkworld.com/go2/0516bug2i.html
Gentoo:
https://security.gentoo.org/glsa/glsa-200505-11.xml
SCO:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.25
**********
Gentoo patches gzip
A race condition in gzip, an open source compression program, could be exploited to run arbitrary commands on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-05.xml
Gentoo releases fix for libTIFF
A buffer over flow in the TIFF image handling application libTIFF’s BitsPerSample function could be exploited to run malicious code. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-07.xml
Gentoo issues patch for HT Editor
Two overflow vulnerabilities have been found in HT Editor, a Hex editor application. The flaws could be exploited by an attacker to run any application on the infected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-08.xml
phpBB fix available for Gentoo users
A cross-scripting vulnerability in phpBB, an open source bulletin board system, could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-10.xml
PostgreSQL patch for Gentoo
A denial-of-service flaw have been found in PostgreSQL, an open source object-relational database. An attacker could exploit the flaw to gain elevated privileges as well. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-12.xml
Gentoo patches FreeRADIUS
The open source RADIUS authentication server FreeRADIUS is vulnerable to buffer overflow and SQL injection attacks. An attacker may exploit this to run malicious applications on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200505-13.xml
**********
Conectiva patches KDE
A new KDE update from Conectiva fixes five vulnerabilities in the popular GUI desktop system. The most serious of the flaws could be used to take control of the system and run malicious applications. For more, go to:
http://www.networkworld.com/go2/0516bug2h.html
**********
Fedora releases QT update
A heap overflow in the BMP decoder that comes with QT, a GUI desktop development tool, could be exploited to run malicious code on the affected machine. For more, go to:
http://www.networkworld.com/go2/0516bug2g.html
Fedora patches ruby
A flaw in the CGI module of Ruby could be exploited in a denial-of-service attack against the affected system. For more, go to:
http://www.networkworld.com/go2/0516bug2f.html
Fedora updates openmotif
Several overflow flaws in the XPM image handling code that is included with openmotif. The flaws could be exploited to crash the affected system or to potentially run malicious code. For more, go to:
http://www.networkworld.com/go2/0516bug2e.html
Fedora releases fix for sudo
A flaw in the way sudo sanitized certain user input could be exploited to can elevated privileges on the affected machine. For more, go to:
http://www.networkworld.com/go2/0516bug2d.html
Fedora patches nfs-utils
A vulnerability in nfs-utils could be exploited in a denial-of-service attack against the affected machine. The flaw is in the way the statd daemon handles “sigpipe” signals. For more, go to:
http://www.networkworld.com/go2/0516bug2c.html
Fedora issus fix for imap
According to an alert from Fedora, “A buffer overflow flaw was found in the c-client IMAP client. An attacker could create a malicious IMAP server that if connected to by a victim could execute arbitrary code on the client machine.” For more, go to:
http://www.networkworld.com/go2/0516bug2b.html
Fedora patches cvs
A buffer overflow in cvs, a version control system, could be exploited to run malicious code on the affected machine. For more, go to:
http://www.networkworld.com/go2/0516bug2a.html
**********
Debian patches phpsysinfo
According to a Debian advisory, “Maksymilian Arciemowicz discovered several cross site scripting issues in phpsysinfo, a PHP based host information application.” For more, go to:
https://www.debian.org/security/2005/dsa-724
**********
Today’s roundup of virus alerts:
W32/Forbot-AR – A backdoor Trojan that spreads through network shares, dropping “securitychk.exe” on the infected machine. It creates a service called “Microsoft Secure Messenger.NET Service” and allows backdoor access through IRC. (Sophos)
W32/Bagz-D – A mass-mailing worm that can also allows an attacker to send down additional components through a backdoor. The attachment will be a .zip or .exe file and it will create a service called “RPC32”. (Sophos)
W32/Anzae-A – A mass-mailing worm with a Spanish twist. The message text is in Spanish and the infected attachment is a .zip. It drops sw.exe, sx.exe, sz.exe and Inzax.exe on the infected machine. (Sophos)
Troj/Banker-HC – Another password-stealing Trojan that targets Brazilian banking sites. (Sophos)
W32/Agobot-SJ – This Agobot variant can be used for a number of purposes, including using the infected machine as proxy, stealing local information, and more. It spreads through network shares by exploiting one of four Windows vulnerabilities and drops “hmlsvc32.exe” on the infected machine. (Sophos)
Troj/Whistler-F – A worm that attempts to delete the contents of the infected machine’s hard drive. It first drops “whismng.exe” on the infected machine. (Sophos)
W32/Mytob-AZ – A mass-mailer worm that looks like a security or account warning. The attached file will be ZIP, EXE, PIF, SCR or CMD and the virus will install “LienVandeKelder.exe” on infected machines. (Sophos)
W32/Mytob-CI – Very similar to Mytob-AZ with the added bonus of being able to kill anti-virus software running on the infected machine. (Sophos)
W32/Mytob-CJ – Another similar Mytob variant. This one uses “sky.exe” as the infected file. (Sophos)
Troj/Haxdoor-Y – A Trojan that provides backdoor access to the infected machine. It sets up the service “AVPX32”. (Sophos)
W32/Eyeveg-G – A backdoor Trojan that spreads through e-mail with an infected ZIP file. The ZIP itself contains a number of SCR files. It can be used for key logging, sending e-mail and monitoring Web traffic. (Sophos)
W32/Oscabot-E – This Trojan tries to spread through AOL Instant Messenger. It sends a link in a message. If followed, the file “userint32.exe” will be installed on the target machine. (Sophos)
Troj/Kelvir-P -A new Kelvir worm that spreads like Oscabot above, except Kelvir uses MSN Messenger. (Sophos)
Troj/Vidlo-J – A downloading Trojan that attempts to grab “prev.exe” from a predefined site. (Sophos)




