XP SP2 is on the way

Opinion
Aug 9, 20045 mins

* Patches from Gentoo * Beware PDA virus found in the wild * Small security firm puts spotlight on big vendor bugs, and other interesting reading

Microsoft wraps up Windows XP Service Pack 2

Microsoft has finished work on Service Pack 2 (SP2) for Windows XP, the company said Friday. The software maker now begins the process of delivering the large, security-focused update to users.

SP2 for Windows XP is more than the usual roll-up of bug fixes and updates. It also makes significant changes to Windows to improve security of the operating system. Analysts have called the service pack a Windows upgrade instead of a simple update.

Changes to Windows XP made by SP2 fall into four main areas: network protection, memory protection, e-mail security and browsing security. For example, the service pack will install and turn on the Windows Firewall, an improved successor to the Internet Connection Firewall. Also, Internet Explorer (IE) users will receive alerts when visiting Web sites that use potentially malicious ActiveX scripts and IE now has a pop-up blocker that is switched on by default.

https://www.nwfusion.com/news/2004/0806microwraps.html?nl

jmeserve@nww.com

What are your plans for rolling out XP 2? Will you set for automatic update or take a wait-and-see approach? Drop me a line at

Today’s bug patches and security alerts:

Opera still vulnerable

GreyMagic Software has updated a February warning that says Opera is vulnerable to a location write vulnerability. An attacker could exploit this to access any Web page script. For more, go to:

https://www.greymagic.com/security/advisories/gm008-op/

Gentoo Opera patch:

https://forums.gentoo.org/viewtopic.php?t=206845

**********

Gentoo patches Pavuk

A buffer overflow in Pavuk, a Web spider and Web site mirroring tool, could be exploited by an attacker to run arbitrary code. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=202579

Gentoo releases patch for Subversion

A flaw in Gentoo, a version control system, could allow users with write access to certain areas of the repository to bypass restrictions and have read access to the entire database. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=202709

Gentoo fixes libapache-mod-ssl

Two vulnerabilities have been found in the SSL module, part of Gentoo’s Apache implementation. An attacker could exploit this to take control of the machine and run the code of choice on the machines. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=201203

Gentoo patches multiple flaws in phpMyAdmin

Flaws in phpMyAdmin, a Web-based admin tool for MySQL, could allow any user with a valid account “to alter configuration variables and execute arbitrary PHP code.” For more, go to:

https://forums.gentoo.org/viewtopic.php?t=204282

Gentoo issues fix for MPlayer

MPlayer, an application that plays multiple media formats, contains a remote exploitable buffer overflow. No word on what an attacker could do with the flaw. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=205018

Gentoo patches PuTTY

As we reported last week, Core Security Technologies is warning of vulnerabilities in PuTTY and PSCP. PuTTY is a free implementation of telnet and SSH

for Win32 and Unix, and PSCP is a application for remote login to network server systems. The flaws could be exploited by a remote attacker to run the code of choice on the affected machine. For more, go to:

**********

More libpng updates

A number of vulnerabilities have been found in libpng, a popular image viewer application. According to CERT, the most serious of the flaws could be exploited to take control of an affected system. For more, go to:

Conectiva:

https://www.nwfusion.com/go2/0809bug1a.html

Debian:

https://www.debian.org/security/2004/dsa-536

Gentoo:

https://forums.gentoo.org/viewtopic.php?t=206647

Trustix:

https://www.trustix.org/errata/2004/0040

**********

Today’s roundup of virus alerts:

PDA virus found in the wild

Anti-virus companies have been warning for years that viruses will afflict handheld devices, and the day has apparently arrived: Both Symantec and Kaspersky Labs have detected a backdoor Trojan horse program that can give an attacker complete control over a Pocket PC mobile device. PC World, 08/06/04.

https://www.nwfusion.com/news/2004/0806pdavirus.html?nl

OF97/Toraja-I – An Excel virus that uses the file “start25.xls” in the xlstart directory. No word on any damage caused. (Sophos)

VBS/Cata-A – A mass-mailer that deletes image files from network shares. No word on the e-mail characteristics it uses to spread. (Sophos)

W32/Lovgate-AD – Yet another Lovegate variant that spreads via e-mail, network shares and peer-to-peer networks. It can be used to allow backdoor access via IRC and turns off anti-virus applications on the infected machine. (Sophos)

W32/Nachi-K – This virus attempts to infect machines already infected with MyDoom. It spreads via network shares and could delete files on the infected machine. (Sophos)

W32/Doep-A – A peer-to-peer virus that infects the file “poet.exe” in the Windows System directory. (Sophos)

W32/Gobot-C – Another virus that uses peer-to-peer networks to spread. It could allow backdoor access via IRC. (Sophos)

**********

From the interesting reading department:

Corporate America slow to adopt biometric technologies

Biometric authentication technologies, which were expected to be widely adopted soon after the Sept.11 terrorist attacks in 2001, are still struggling to gain broad acceptance in corporate America. Computerworld, 08/06/04.

https://www.nwfusion.com/news/2004/0806biometric.html?nl

Small security firm puts spotlight on big vendor bugs

News earlier this week that Oracle was sitting on patches for 34 undisclosed vulnerabilities in its database software may have come as a surprise to some, but not to David Litchfield, the researcher who discovered the holes. IDG News Service, 08/06/04.

https://www.nwfusion.com/news/2004/0806smallsecur.html?nl

Security cavities ail Bluetooth

Serious flaws discovered in Bluetooth technology used in mobile phones can let an attacker remotely download contact information from victims’ address books, read their calendar appointments or peruse text messages on their phones to conduct corporate espionage. Wired, 08/06/04.

https://www.wired.com/news/privacy/0,1848,64463,00.html

Onion Routing Averts Prying Eyes

The Navy built a networking technology, called onion routing, to mask the online activities of intelligence employees. Now open-source programmers are using the same system to let users surf the Web anonymously. Wired, 08/05/04.

https://www.wired.com/news/privacy/0,1848,64464,00.html