New Squid proxy update

Opinion
Oct 18, 20046 mins

* Patches from Debian, Conectiva * Beware new Netsky variant * Feds declare war on spyware scams, and other interesting reading

Today’s bug patches and security alerts:

New Squid update fixes flaws

A flaw in the Squid proxy’s “asn_parse_header()” function could be exploited in a denial-of-service attack against the affected machine. Patches are available. For more, go to:

https://www.nwfusion.com/go2/1018bug1a.html

**********

Debian releases patch for mysql vulnerabilities

A new Debian update for mysql fixes a number of flaws i the database application. Most of the flaws could be exploited to crash the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-562

Debian updates python2.2

A bug in Versions 2.2 and 2.2.1 of Python could allow a remote attacker with an IPv6 address to overwrite part of the memory stack. For more, go to:

https://www.debian.org/security/2004/dsa-458

Debian releases fix for mpg123

The multimedia player mpg123 does not properly check the headers in MPEG files, which may contain code that could be executed on the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-564

Debian releases new sox update

According to Debian, “Ulf Harnhammar has reported two vulnerabilities in SoX, a universal sound sample translator, which may be exploited by malicious people to compromise a user’s system with a specially crafted .wav file.” For more, go to:

https://www.debian.org/security/2004/dsa-565

**********

Conectiva, Debian issues fix for CUPS

According to an alert from Debian, “An information leak has been detected in CUPS, the Common UNIX Printing System, which may lead to the disclosure of sensitive information, such as user names and passwords which are written into log files.” For more, go to:

Conectiva:

https://www.nwfusion.com/go2/1018bug1b.html

Debian:

https://www.debian.org/security/2004/dsa-566

**********

Conectiva patches samba

A two denial-of-service vulnerabilities have been found in Samba and have been patched by Conectiva. For more, go to:

https://www.nwfusion.com/go2/1018bug1c.html

**********

Today’s roundup of virus alerts:

W32/Snoop-A – A worm that spreads via peer-to-peer networks using random filenames. No word on any permanent damage caused. (Sophos)

W32/Funner-A – This worm targets MSN Messenger instant messaging users. It installs itself as “rundll32.exe” in the Windows folder and to the Windows system folder as “explorer.exe”, “iexplore.exe” and “userinit32.exe.” It seems to deny access to a number of pre-defined sites by modifying the infected machine’s HOSTS file. (Sophos,

W32/Apribot-C – A bot that provides backdoor access to the infected machine via IRC. It spreads via network shares and uses random filenames for its infection point. It can be used as a proxy, to steal information, and launch DDoS attacks. (Sophos)

W32/Sdbot-QF – An Sdbot variant that spreads via network shares and installs itself in the Windows System folder as “service.exe”. It exploits the Windows LSASS vulnerability and can be used to steal CD keys for popular applications. (Sophos)

W32/Sdbot-QG – This Sdbot variant installs itself as “msgfix.exe” in the Windows System directory after spreading through a network share. It can be used in a DDoS attack, to steal CD keys and download files from the Internet. (Sophos)

W32/Sdbot-QH – Another Sdbot variant that exploits the DCOM and LSASS vulnerabilities in Windows as it spreads via network shares. It installs itself as “msfirewall.exe” in the Windows System directory. It can be used to monitor applications running on the infected machine. (Sophos)

W32/Bagz-B – An e-mail worm that spreads via a zip or binary file. The infected message can have a variety of subject and attachment names. It looks like it installs itself as “syslogin.exe”. (Sophos)

W32/Netsky-AD – A new Netsky variant that uses network shares, e-mail and peer-to-peer networks to spread and installs itself as “MsnMsgrs.exe”. No word on what kind of damage the virus can cause. (Sophos)

**********

From the interesting reading department:

Feds declare war on spyware scams

Last week’s federal complaint against an alleged spyware purveyor is only an opening salvo in what promises to be an all-out effort against spyware-related scams on the Web, according to regulators and industry experts. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804spyware.html?nl

Technology update: Patch management goes automatic

Automated patch-management software offers a solution for aggregating, and distributing and installing patches and software updates for multiple computing platforms. The core functions of the system are an accurate patch management detection and inventory process, and automatic patch deployment across platforms. Network World, 10/18/04.

https://www.nwfusion.com/news/tech/2004/101804techupdate.html?nl

Foundry switch software secures WLANs

Foundry Networks is adding features for its wireless LAN switch software that the company says will help customers make WLANs more secure and easier to manage while allowing for increased wireless client roaming. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804foundry.html?nl

ISS to proactively thwart attacks

Internet Security Systems is scheduled to announce plans for a system that prevents network attacks before threats are publicly identified. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804iss.html?nl

Blue Coat, CA on the spyware patrol

With spyware looming larger as a security threat, vendors are rolling out products aimed at combating the menace. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804spywareside.html?nl

EnKoo fattens up remote SSL appliances

EnKoo this week is introducing SSL remote-access gear it says supports more users and lets them connect to more applications with less administrative work involved. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804-enkoo.html?nl

Sprint gussying up security offerings

Sprint last week launched two security services that it says will help customers mitigate distributed denial-of-service attacks and better enforce security policies. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804-sprint.html?nl

Equant expands VPN access services

Equant is offering customers new choices when it comes to accessing their VPN from around the world whether they are tethered or not. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804-equant.html?nl

SANS Institute names Top 20 vulnerabilities

The Unix kernel and databases that run on that operating system, along with security sub-systems and instant messaging that run on Windows, are the newest additions to the SANS Institute’s annual list of Top 20 vulnerabilities most exploited by hackers. Network World, 10/18/04.

https://www.nwfusion.com/news/2004/101804sans.html?nl

‘Trustworthiness’ still a goal for Microsoft

January 15, 2005 – a Saturday – will almost certainly pass quietly on the bucolic Redmond, Wash., campus of Microsoft. But for those in the field of information technology security, who often make a sport of following the company’s struggles to secure its products, the date is certain to attract some notice: it’s the third anniversary of a now-famous internal Microsoft e-mail dubbed the “Trustworthy Computing” memo.  IDG News Service, 10/14/04.

https://www.nwfusion.com/news/2004/1013trusstill.html?nl