* Patches from Mandrake Linux, SuSE, SCO, others * Beware the neverending variants of Rbot * Leaked memos link spammers to ISP Savvis, and other interesting reading
The virus writer (or writers) responsible for the recent MyDoom-V variant have put a cleartext message in the code, according to an alert from BitDefener. The notes states: “We searching 4 work in AV industry”. Maybe they should stop spreading viruses first, then look for a job…
Today’s bug patches and security alerts:
Mandrake Linux, SuSE patch zlib
A data handling error in zlib’s ‘inflate’ function could be exploited in a denial-of-service against the machine running the compression application. For more, go to:
Mandrake Linux:
https://www.nwfusion.com/go2/0906bug2a.html
SuSE:
https://www.suse.com/de/security/2004_29_zlib.html
**********
SCO, SuSE release patches for Apache2
Both SCO and SuSE have released patches for the popular Apache Web server applications. SuSE is patching a flaw in the mod_ssl code that could be exploited in a denial-of-service attack. SCO’s patch is for OpenServer and fixes a problem in the mod_digest code, which could be exploited by an unauthorized user to gain authentication. For more, go to:
SCO:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.14
SuSE:
https://www.suse.com/de/security/2004_30_apache2.html
**********
Gentoo, Mandrake Linux release fixes for imblib, imlib2
A buffer overflow in the BMP image handling code for ImageMagick (imlib). The vulnerability is similar to the one reported in the QT image handler. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200409-12.xml
Mandrake Linux:
https://www.nwfusion.com/go2/0906bug2b.html
**********
SCO patches OpenSSL for OpenServer
Several vulnerabilities in the OpenSSL implementation for OpenServer have been fixed. For more, go to:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10
SCO issues fix for Squid on OpenServer
A null character vulnerability in “%xx” decoding function in certain versions of Squid could be exploited bypass the application’s access control list. For more, go to:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.13
**********
Mandrake Linux patches cdrecord
The cdrecord application does not properly drop its root access when it launches. This could exploited by a local user to gain elevated privileges. For more, go to:
https://www.nwfusion.com/go2/0906bug2c.html
**********
Gentoo patches star
A root vulnerability has been found in star, a tape archive application. A local user could exploit this to gain root access. For more, go to:
https://security.gentoo.org/glsa/glsa-200409-11.xml
Gentoo fixes lha
According to an alert from Gentoo, “Several buffer overflows and a shell metacharacter command execution vulnerability have been found in LHa. These vulnerabilities can be used to execute arbitrary code.” For more, go to:
https://security.gentoo.org/glsa/glsa-200409-13.xml
**********
Siemens releases patch for series 65 phones
Siemens Tuesday said it has received the green light from operators to offer a patch for a software defect in some of its 65 series mobile phones that could cause hearing damage. IDG News Service, 09/08/04.
https://www.nwfusion.com/news/2004/0908siemerelea.html?nl
**********
Today’s roundup if virus alerts:
W32/Rbot-IE – A “standard issue” Rbot variant that spreads via network shares and used IRC for backdoor access. This version infects “mswctl32.exe” in the Windows System directory. (Sophos)
W32/Rbot-IH – Similar to Rbot-IE, except that it uses the filename “windll.exe”. It also has the ability to steal CD keys for popular applications. (Sophos)
W32/Rbot-CZ – Same as the above Rbot variants with the added ability to delete network shares. This variant uses the filename “WINSYS32.EXE”. (Sophos)
W32/Rbot-FL – This Rbot variant can be used as proxy and spam relay or as an FTP server. Like other Rbot variants, it spreads via network shares and infects the file “ati2vid.exe” in C:. (Sophos)
W32/Rbot-IP – Another standard issue Rbot variant (see Rbot-IE above). It uses the filename “DVLDR.EXE”. (Sophos)
W32/Forbot-C – This worm spreads via shared network drives, uses IRC for backdoor access and can terminate certain security related applications running on the infected machine. It uses “winitr32.exe” in the Windows System directory as its infection point. (Sophos)
W32/Britney-B – A worm that spreads via the A: drive using the file name “Britney.exe”. No word on what kind of damage it may cause. (Sophos)
W32/Nyxem-C – A virus that spreads via network shares, e-mail, Yahoo Messenger and Yahoo Pager. It creates a number of files on the infected machine and launches Windows Media Player to mask its activities. (Sophos)
W32/Neveg-C – An old-school virus that spreads via mass-mailing email. It copies itself to the Windows System folder as “services.exe”. (Sophos)
**********
From the interesting reading department:
Leaked memos link spammers to ISP Savvis
Internal e-mail messages from Savvis Communications have surfaced on the Internet that show that the St. Louis-based ISP catered to online e-mail marketing companies it suspected of sending out unsolicited commercial (“spam”) e-mail, even using “subversive business methods” to help spammers stay online after their Internet address was blacklisted. IDG News Service, 09/08/04.
https://www.nwfusion.com/edge/news/2004/0908leakmemos.html?nl
Microsoft offers more time to test XP Service Pack 2
Microsoft is giving users more time to prepare for Windows XP Service Pack 2 by doubling the time a special registry key will prevent PCs from automatically downloading and installing the mammoth update. IDG News Service, 09/07/04.
https://www.nwfusion.com/news/2004/0907microoffer.html?nl
Totally Unplugged: Wireless insecurity rising
Today, anyone can create a wireless network or wirelessly extend an enterprise network using inexpensive wireless routers and client adapters from major retail chains. But making it easier for hackers to access enterprise data is by no means the only security risk that companies face. Individuals intent on stealing music or uploading porn prefer to borrow someone else’s network. And unauthorized wireless nodes can cause interference to authorized nodes, disrupting network operations. Network World, 09/06/04.
https://www.nwfusion.com/columnists/2004/090604brodsky.html?nl




