Linux vendors patch Kerberos 5

Opinion
Jun 21, 20045 mins

* Patches from Gentoo, Mandrake Linux, SGI, others * Beware Rbot variants * Cisco set to unleash security plan, and other interesting reading

Today’s bug patches and security alerts:

Linux vendors patch Kerberos 5

A buffer overflow in the MIT Kerberos 5 network authentication tool’s “krb5_aname_to_localname()” library function could be exploited to gain root privileges on the affected machine. For more, go to:

Debian:

https://www.debian.org/security/2004/dsa-520

Mandrake Linux:

https://www.nwfusion.com/go2/0621bug1a.html

Trustix:

https://www.trustix.org/errata/2004/0036

**********

More Linux kernel fixes

A floating point exception in the Linux kernel could be triggered to create a denial-of-service attack against the affected machine. For more, go to:

SuSE:

https://www.suse.com/de/security/2004_17_kernel.html

Trustix:

https://www.trustix.org/errata/2004/0035

**********

Gentoo patches mailman

A bug in the mailman application could allow a third party to retrieve another user’s password. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=183625

**********

HP-UX ftp flaw found

A bug in the ftp daemon used in HP-UX could allow a remote user to gain unauthorized access to the affected machine. For more, go to:

https://www.kb.cert.org/vuls/id/258721

**********

Mandrake Linux patches ksymoops

The ksymoops-gznm script that ships with Mandrake Linux does not properly copy files to a temporary directory. This could be exploited by an attacker in a symlink attack to gain root privileges. For more, go to:

https://www.nwfusion.com/go2/0621bug1b.html

**********

SGI releases IRIX patch

According to an alert from SGI, “Adam Gowdiak from the Poznan Supercomputing and Networking Center has reported that under certain conditions non privileged users can use the syssgi system call SGI_IOPROBE to read and write kernel memory which can be used to obtain root user privileges.” For more, go to:

https://www.nwfusion.com/go2/0621bug1c.html

SuSE issues subversion patch

Subversion, a version control system, is potentially vulnerable to a denial-of-service attack or may be exploited to run malicious code on the affected machine. For more, go to:

https://www.suse.com/de/security/2004_18_subversion.html

**********

Today’s roundup of virus alerts:

W32/Rbot-AV – An Rbot variant that spreads via network shares and installs itself as “PIDSERV.EXE” in the Windows System folder. The virus contains backdoor functionality accessible via IRC and may also try to delete access to shared drives. (Sophos)

W32/Rbot-AX – Another Rbot variant that exploits weak passwords on network shares to spread. It installs itself in the Windows System directory as “WUAGMSD.EXE”. It has backdoor functionality, but no word on how it is accessed (whether by IRC or by open port.) (Sophos)

W32/Rbot-AY – This Rbot variant spreads by exploiting various operating system flaws as well as holes opened by other virus infections. Installed as “video_32D.exe” in the Windows System directory, a backdoor installed by the virus can be access via IRC. The virus also tries to terminate certain security-related applications running on the infected machine. (Sophos)

W32/Korgo-H – Another Korgo variant that uses network shares to spread and installs itself using a random filename in the Windows System directory. The virus does have backdoor access via IRC and may try to prevent a system shutdown. (Sophos)

W32/Agobot-KB – A worm that spreads by exploiting weak passwords on network shares and installing itself in the Windows System directory with the filename “msft32.exe.” It allows backdoor access via IRC, terminates security-related applications and prevents access to certain security Web sites by modifying the HOSTS file. (Sophos)

**********

From the interesting reading department:

Cisco set to unleash security plan

Cisco next week will announce availability of its Network Admission Control security technology for Cisco routers, and lay out a road map for adding NAC capabilities to its lines of LAN switches. Network World, 06/18/04.

https://www.nwfusion.com/news/2004/0618cisconac.html?nl

Cisco, Avaya respond to our Tester’s Challenge on VoIP security tools

In their formal responses printed here, Avaya and Cisco agreed with Mier’s assertions in general, but were quick to defend measures they’ve already taken in these directions. What neither company offered, though, were detailed plans for improving the overall state of VoIP security. Network World, 06/21/04.

https://www.nwfusion.com/news/2004/062104tester.html?nl

Technology Update: Personal firewalls protect vulnerable PCs

A personal firewall complements traditional defenses such as gateway firewalls and anti-virus efforts. Network World, 06/21/04.

https://www.nwfusion.com/news/tech/2004/062104techupdate.html?nl

Compliance, phishing top user concerns

Finding cost-effective ways to comply with new regulatory requirements and safeguarding data in e-commerce are among today’s most vexing issues for security managers, according to those attending two confabs last week. Network World, 06/21/04.

https://www.nwfusion.com/news/2004/062104secwrap.html?nl

Companies team to reel in phishing

A new consortium of companies from different industries has formed to tackle the problem of online identity fraud, better known as “phishing.” Network World, 06/21/04.

https://www.nwfusion.com/news/2004/0621gophish.html?nl

BigFix bringing security to laptops

BigFix next month plans to upgrade its patch and configuration management software to support mobile laptops and help customers check computers for security holes before letting any devices onto a network. Network World, 06/21/04.

https://www.nwfusion.com/news/2004/0621bigfix.html?nl

Microsoft unwraps Win XP Service Pack

After a few notable delays, Microsoft finally has shipped the latest beta version of Windows XP Service Pack 2, which the company has touted as a major milestone toward developing more secure software. Network World, 06/21/04.

https://www.nwfusion.com/news/2004/0621msoft.html?nl

U.S. House subcommittee approves spyware bill

A U.S. House subcommittee has approved a spyware bill that would allow fines up to $3 million for collecting personal information, diverting browsers and delivering some pop-up advertisements to computer users without their consent. IDG News Service, 06/17/04.

https://www.nwfusion.com/news/2004/0617ushouse.html?nl

Symbol buys into stronger mobile security

Symbol Technologies wants to help secure data and applications on handheld devices via the acquisition of Trio Security, a privately held software vendor in Colorado Springs, Colo., the company announced Thursday. IDG News Service, 06/17/04.

https://www.nwfusion.com/news/2004/0617symbobuys.html?nl