* Patches from Mandrake Linux, Conectiva, Debian, others * Beware latest Bofra (formerly MyDoom variant) going around * AOL upgrade packs security tools, and other interesting reading
endif; ?>Virtual Showdown: How best to patch
Shavlik, BigFix, Altiris, Configuresoft, Citadel Security Software and Symantec reps are in our showdown waiting to take your questions on patch management. Get your questions answered and watch them field those on patch testing, agent vs. agent-less approach, building secure code and more.
https://www.nwfusion.com/cgi-bin/forum/gforum.cgi?post=1964
Today’s bug patches and security alerts:
Samba buffer overflow patched
A buffer overflow vulnerability in Samba, an open source file/print server application, could be exploited by an attacker to run any code they wished on the affected machine. Version 3.08 of Samba is said to fix the problem. For more, go to:
e-Matters advisory:
https://security.e-matters.de/advisories/132004.html
Samba download page:
https://us1.samba.org/samba/download/
Gentoo:
https://security.gentoo.org/glsa/glsa-200411-21.xml
Mandrake Linux:
https://www.nwfusion.com/go2/1115bug2a.html
SuSE:
https://www.suse.com/de/security/2004_40_samba.html
Trustix (update also fixes flaws in sudo, gd and sqlgrey):
https://www.trustix.org/errata/2004/0058/
**********
Updated Apache packages available
Problems with the get_tag() function of mod_include module for Apache have been fixed by a number of vendors. The flaw could be used to “run arbitrary code with the rights of an httpd child process.” For more, go to:
Conectiva:
https://www.nwfusion.com/go2/1115bug2b.html
Debian:
https://www.debian.org/security/2004/dsa-594
Gentoo:
https://security.gentoo.org/glsa/glsa-200411-18.xml
Mandrake Linux (apache):
https://www.nwfusion.com/go2/1115bug2c.html
Mandrake Linux (apache2):
https://www.nwfusion.com/go2/1115bug2d.html
**********
Mandrake Linux, OpenPKG patch gd
A buffer overflow in the gd graphics library could be exploited in a denial-of-service attack against the affected machine or to potentially run any code. For more, go to:
Mandrake Linux:
https://www.nwfusion.com/go2/1115bug2e.html
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.049-gd.txt
**********
Mandrake Linux patches sudo
A new sudo update fixes a flaw in the way “bash” functions are exported to other applications. A user could exploit the flaw to run arbitrary commands on the affected machine. For more, go to:
https://www.nwfusion.com/go2/1115bug2f.html
**********
Conectiva, OpenPKG release patch for libxml
Multiple buffer overflows have been found in the various libxml image handling libraries. These could be exploited in a denial-of-service attack or to potentially run an attacker’s code of choice on the affected machine. For more, go to:
Conectiva:
https://www.nwfusion.com/go2/1115bug2g.html
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.050-libxml.txt
**********
Debian patches ImageMagick
A flaw in the ImageMagick graphics package could be exploited to execute arbitrary code on the affected machine, according to a Debian advisory. For more, go to:
https://www.debian.org/security/2004/dsa-593
**********
OpenPKG patches mysql
Several flaws in the MySQL application for OpenPKG could be exploited to gain elevated privileges or any application/malicious code on the affected machine. For more, go to:
https://www.openpkg.org/security/OpenPKG-SA-2004.045-mysql.txt
**********
Skype update fixes two flaws
Skype, which makes an IP softphone application, is urging users to upgrade to Version 1.0.0.100 to fix two vulnerabilities in the initial 1.0 release. One flaw revolves around internal data handling and the other is a buffer overflow. No word on how these could be exploited.
Download page:
https://www.skype.com/products/skype/windows/
Change log:
https://www.skype.com/products/skype/windows/changelog.html
**********
Today’s roundup of virus alerts:
IFRAME.BoF – This exploits an iFrame vulnerability in Internet Explorer 6.0. Users are directed to a malicious Web page where this code is hidden. It causes a buffer overflow, which can be used to take control of the affected machine. Unfortunately, no patch is available yet. (Panda Software)
W32/Bofra-G – Yet another Bofra (formerly MyDoom variant) going around. It too spreads via e-mail using a couple different messages, but all with attachments ending in 32.exe. It also opens a backdoor on port 6667 and will stop working on December 15th.(Sophos)
W32/Forbot-CJ – This bot spreads via network shares and installs itself as “regexpress.exe”. It allows backdoor access via IRC and can be used for denial-of-service attacks, as a proxy server, to steal passwords and more. (Sophos)
W32/Rbot-PU – An Rbot variant that infects the file “wuamgrd32.exe” in the Windows System directory. It allows backdoor access via IRC, but no word on other damage it can inflict. (Sophos)
W32/Rbot-NK – This Rbot variant tries to hide itself as the RealOne Player executable, “realplay.exe”. The worm can be controlled via IRC and used for a number of malicious purposes. (Sophos)
W32/Ssik-A – Hey, a new name! This worm uses a random filename to infect a Windows machine and displays the message “LoRz reborn!!”. It also tries to move the Task Manager application to make the worm harder to stop. (Sophos)
W32/Agobot-NX – A new Agobot variant that uses the file “bmsvc32.exe” as its infection point in the Windows System folder. The virus modifies the HOSTS file in an attempt to block access to popular anti-virus and security sites. (Sophos)
Troj/Mirchack-D – This is a hacked version of the mIRC chat application. It can be used in a denial of service attack or to install a backdoor on the infected machine. (Sophos)
W32/Protoride-W – A backdoor Trojan that listens for commands via IRC. It spreads via network shares using the file “msupdate.exe”. (Sophos)
W32/Mofei-E – A backdoor application that spreads via network shares. It installs itself as “ALERTER.EXE” and runs as the service “Net Login Helper”. It also copies itself in a number of popular applications. (Sophos)
**********
From the interesting reading department:
AOL upgrade packs security tools
AOL subscribers Thursday will receive a raft of new and enhanced security services as part of their standard package with the launch of AOL 9.0 Security Edition, the latest upgrade of the company’s fee-based, consumer-focused online service. IDG News Service, 11/18/04.
https://www.nwfusion.com/news/2004/1118aolupgra.html?nl
Newsletter: Linux is ‘most breached’ OS on the ‘Net, security research firm says.
According to London security analysis and consulting firm mi2g, Linux is the most commonly breached operating system on computers connected to the Internet 24/7. Network World Linux Newsletter, 11/10/04.
https://www.nwfusion.com/newsletters/linux/2004/1108linux2.html?nl
Internet Security Intelligence Briefing
The VeriSign Internet Security Intelligence Briefing reports current trends for Internet growth, usage, security, and online fraud. This briefing includes data and intelligence drawn from VeriSign’s Internet infrastructure services, including DNS services, digital certificates (SSL and PKI), Managed Security Services (MSS), Payments, and Fraud Protection Service. VeriSign, November 2004.
https://www.verisign.com/static/017574.pdf
Microsoft releases management tools, expands on DSI model
Microsoft Tuesday released a handful of software products that are key elements in its drive to develop a comprehensive management platform for Windows. The company also released the first beta of its newest corporate patch server. Network World Fusion, 11/16/04.
https://www.nwfusion.com/news/2004/1116msdsi.html?nl
AMD readies security, virtualization features for 2006
Advanced Micro Devices plans to build security and virtualization features into its server processors by 2006, the company said Friday during its annual analyst event. IDG News Service, 11/15/04.
https://www.nwfusion.com/news/2004/1115amdreadi.html?nl
Panel: Gov’t can’t mandate security
Now is not the time for the U.S. government to mandate cybersecurity standards to private industry, despite significant threats and a lack of understanding by many company executives. So concluded a panel of government officials that met to discuss the issue in September. IDG News Service, 11/15/04.




