* Alerts from Microsoft, CERT, Core Security Technologies * 'Net virus posing as Berg video * Security expert says the virus writers are winning, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Oracle, under fire, admits to database security holes
Oracle has acknowledged the existence of multiple security holes in its database software and said it plans to issue a security alert shortly. The U.K. security expert who found the holes criticized Oracle’s conduct, saying that it has been sitting on patches that would fix the holes for about two months. IDG News Service, 08/03/04.
https://www.nwfusion.com/news/2004/0803oraclunder.html?nl
**********
Microsoft issues alert on CRM suite
Microsoft has issued an alert about incompatibility issues in its customer relationship management suite caused by installing Windows XP Service Pack 2. Computerworld, 08/04/04.
https://www.nwfusion.com/news/2004/0804microissue.html?nl
**********
CERT warns of flaw in libpng
A number of vulnerabilities have been found in libpng, a popular image viewer application. According to CERT, the most serious of the flaws could be exploited to take control of an affected system. For more, go to:
https://www.us-cert.gov/cas/techalerts/TA04-217A.html
Mandrake Linux:
https://www.nwfusion.com/go2/0802bug2a.html
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.035-png.txt
SuSE:
https://www.suse.com/de/security/2004_23_libpng.html
**********
Flaws in PuTTY and PSCP
Core Security Technologies is warning of vulnerabilities in PuTTY and PSCP. PuTTY is a free implementation of telnet and SSH for Win32 and Unix, and PSCP is a application for remote login to network server systems. The flaws could be exploited by a remote attacker to run the code of choice on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0802bug2b.html
**********
Mandrake Linux patches wv
According to Mandrake Linux, “iDefense discovered a buffer overflow vulnerability in the wv package which could allow an attacker to execute arbitrary code with the privileges of the user running the vulnerable application.” For more, go to:
https://www.nwfusion.com/go2/0802bug2c.html
**********
Trustix patches samba, apache and mod_php4
Trustix has rolled out a sort of service pack that fixes flaws in three applications: samba, apache and mod_php4. Most of the flaws revolve around potential denial-of-service attacks. For more, go to:
https://www.trustix.org/errata/2004/0039/
**********
Today’s roundup of virus alerts:
‘Net virus posing as Berg video
A virus purporting to show video of Nick Berg alive has been released on the Internet, warn security experts. The virus is in a message post to tens of thousands of newsgroups, said anti-virus firm Sophos. BBC News, 08/03/04.
https://news.bbc.co.uk/1/hi/technology/3531252.stm
W32/MyDoom-O — Another MyDoom variant that uses e-mail to spread and search engines to dig for more potential targets. Doesn’t seem to have the same impact as MyDoom-M. (Sophos)
W32/Stewon-A — A peer-to-peer virus that spreads via the likes of Kazaa using a compressed .zip file. The virus installs itself as “genoxial.exe” in the Windows System folder. (Sophos)
Troj/CmjSpy-Z — A keylogging Trojan that installs itself as “hpserver.exe” in the Windows system folder and records its captured info in “hlicense.vxd”. No word on how it spreads. (Sophos)
W32/Agobot-LM — Another Agobot variant that spreads via network shares, which allows backdoor access via IRC and kills security applications as well as access to related sites. It installs itself as “LSAS.EXE”. (Sophos)
W32/Agobot-LL — Hey, another Agobot variant. Similar to Agobot-LM above, except that infects the file “SVCSYS32.EXE” in the Windows System folder. This one could also be used in a DoS attack against third-party sites. (Sophos)
W32/Scaner-A — A virus that tries to attempt the Windows LSASS vulnerability, for which there’s been a patch available for a few months. The virus attempts to report back its findings via an HTTP POST. (Sophos)
W32/Febelneck-A — This virus spreads via a .zip file. It tries to change the name of the infected machine to “Nebelfleck” and delete certain files on the affected system. (Sophos)
**********
From the interesting reading department:
Security expert Q&A: The virus writers are winning
Mikko Hypponen has made a name for himself as a computer security expert in directing anti-virus research at Finland’s F-Secure, a $45 million company that regularly issues alerts warning of network threats. He spoke recently with Network World News Editor Bob Brown and Features Editor Neal Weinberg about the latest viruses and what enterprise network executives are up against. Network World Fusion, 08/04/04.
https://www.nwfusion.com/news/2004/0804fsecure.html?nl
Mozilla to pay bounty on bugs
The Mozilla Security Bug Bounty Program, launched yesterday, promises a reward of $500 to anyone who finds a “critical” security bug in Mozilla. What constitutes critical will be judged by the Mozilla Foundation staff. Linux software developer Linspire and entrepreneur Mark Shuttleworth have issued seed funding to support the initiative, to be supplemented by donations from Mozilla supporters. The first $5,000 in community contributions will be matched dollar-for-dollar by Shuttleworth. The Register, 08/03/04.
https://www.theregister.co.uk/2004/08/03/mozilla_bug_bounty/
70% of 2004 virus activity down to one man
According to a report produced by anti-virus software provider Sophos, 70% of anti-virus activity in the first half of this year can be blamed on Sven Jaschan, an 18-year-old German who wrote the Netsky and Sasser worms. Slashdot, 08/02/04.




