RealPlayer security update available

Opinion
Oct 4, 20046 mins

* Patches from Gentoo, Debian, others * Beware Bagle variant that spreads via an infected attachment named "joke.cpl" or "price.cpl" * Microsoft leaves colleges vulnerable, and other interesting reading

Today’s bug patches and security alerts:

RealPlayer security update available

A new version of RealNetworks’ RealPlayer media client is available that fixes three flaws in previous versions. Earlier versions could be vulnerable to code execution or file deletion via code inserted in a RM (Real Media) or HTML file. Users should upgrade to Version 10.5 (6.0.12.1053).

https://www.service.real.com/help/faq/security/040928_player/EN/

**********

Samba vulnerability patched

A bug in Samba for Unix/Linux could be exploited by a remote user to gain access to arbitrary files on the affected machine. For more, go to:

https://www.nwfusion.com/go2/1004bug1a.html

Samba download area:

https://us4.samba.org/samba/ftp/patches/security/

Related patches:

Mandrake Linux:

https://www.nwfusion.com/go2/1004bug1b.html

Trustix:

https://www.trustix.org/errata/2004/0051/

**********

Gentoo patches GTK+ 2, gdk-pixbuf

A flaw in one of the gdk-pixbuf code libraries could be exploited by a remote user to run any code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200409-28.xml

Gentoo releases patch for glFTPd

A buffer overflow has been found in the glFTPd server that could be exploited by a local user to run any code they want on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200409-27.xml

Gentoo issues fix for xine-lib

Gentoo’s xine-lib, a library used in building multimedia interfaces, contains a number of vulnerabilities that could be used to execute malicious code on a system. For more, go to:

https://security.gentoo.org/glsa/glsa-200409-30.xml

**********

Debian, Gentoo patch getmail

A flaw in getmail could be exploited by a local user to overwrite any file on the affected system. For more, go to:

Debian:

https://www.debian.org/security/2004/dsa-553

Gentoo:

https://security.gentoo.org/glsa/glsa-200409-32.xml

**********

Debian issues fix for lukemftpd

A flaw in the LukFTP daemon could be exploited to run arbitrary code on the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-551

**********

Flaw in Netscape Network Security Services (NSS) library

According to an advisory from Sun, “A buffer overflow vulnerability exists in the Netscape Network Security Services (NSS) library. This vulnerability may allow a remote unprivileged user to execute arbitrary code on vulnerable systems during SSLv2 connection negotiation.” For more, go to:

https://www.nwfusion.com/go2/1004bug1c.html

Related ISS advisory:.

https://xforce.iss.net/xforce/alerts/id/180

**********

Today’s roundup of virus alerts:

W32/Bagle-AZ – A Bagle variant that spreads via e-mail and peer-to-peer networks. The infected attachment is named “joke.cpl” or “price.cpl”. The virus attempts to delete certain registry entries as well. (Sophos)

W32/Rbot-LB – An Rbot variant that acts as a keystroke logger on the infected machine. It spreads via network shares and installs itself as “COMPLIANT.EXE”. It terminates security related applications. (Sophos)

W32/Spybot-CZ – Another keystroke logger. This one allows backdoor access after spreading through network shares and installing itself as “DLL32SYS.EXE”. (Sophos)

Troj/Bdoor-CHR – A backdoor program that spreads via network shares and installs itself as “dx32hhlp.exe” in the Windows System directory. It tries to limit access to security-related Web sites. (Sophos)

Troj/Winflux-B – A Trojan horse program that hides itself in the code of IE, MSN Messenger or any other application specified by the author. The virus can turn on the PC’s webcam, steal passwords, log keystrokes, kill process and act as a proxy. (Sophos)

W32/Xbot-D – A bot that uses a variety of filenames (all with a .dll extension) to infect a machine. It spreads via network shares and can be used a DoS zombie or to download code. (Sophos)

W32/Bugbear-J – This worm has its own SMTP engine to spread itself via e-mail and terminates a number of security-related applications running on a target machine. (Sophos)

**********

From the interesting reading department:

Review: Cracking the wireless security code

Is it possible to deploy a secure wireless LAN with technology available today? We assembled 23 wireless products from 17 vendors and ran them through a battery of tests aimed at getting the answer. Network World, 10/04/04.

https://www.nwfusion.com/reviews/2004/1004wirelessmain.html?nl

Microsoft leaves colleges vulnerable

Microsoft’s licensing policies and legal restrictions that forbid schools from distributing software patches to many students are leaving IT executives at universities with potentially thousands of unmanaged desktops that pose a serious security risk. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404highered.html?nl

Security management wares get smarts

A slew of security event management vendors are set to offer products that address everything from how security problems affect applications to ensuring network devices comply with internal and regulatory policies. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404secmgmt.html?nl

Start-up takes new anti-virus tack

Start-up Avinti is putting a virtual server twist on a well-known concept – quashing viruses that use e-mail as their delivery vehicle. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404avinti.html?nl

Citadel, Preventsys sharpen vulnerability-assessment tools

A pair of vulnerability-assessment and remediation tool vendors are separately upgrading their products so that customers more easily can prioritize which networked systems need to be fixed. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404secwrap.html?nl

Entrust targets improper e-mail

Entrust, best known for its encryption technology, last week introduced an appliance that works alongside e-mail servers to scan for inappropriate content entering or leaving an organization. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404entrust.html?nl

SurfControl turns a trick on phishers

In response to the growing threat that phishing poses to e-mail users, SurfControl plans to upgrade its e-mail filter to catch these attacks, and flag more spam and other abuses. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404surfcontrol.html?nl

Postal Service delivers single sign-on

The USPS’ IT department is enjoying the first fruit of a nearly two-year effort that has resulted in the rollout of SSO capabilities to nearly 150,000 users who access nearly 1,000 applications on the agency’s network. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/100404postal.html?nl

Vendors tout SSL remote-access gear

Three Secure Sockets Layer remote-access vendors are upgrading their equipment, one with software enhancements and two with new hardware. Network World, 10/04/04.

https://www.nwfusion.com/news/2004/1004004vpnprods.html?nl

U.S. cybersecurity chief resigns

Amit Yoran, the government’s cybersecurity chief, abruptly resigned Thursday after one year with the U.S. Department of Homeland Security (DHS), a move that raised serious questions about the Bush administration’s ability to quickly improve the nation’s cybersecurity. IDG News Service, 10/01/04.

https://www.nwfusion.com/news/2004/1001cyber.html?nl