Samba buffer overflow patched

Opinion
Nov 18, 20047 mins

* Patches from Mandrake Linux, Conectiva, Debian, others * Beware latest Bofra (formerly MyDoom variant) going around * AOL upgrade packs security tools, and other interesting reading

Virtual Showdown: How best to patch

Shavlik, BigFix, Altiris, Configuresoft, Citadel Security Software and Symantec reps are in our showdown waiting to take your questions on patch management. Get your questions answered and watch them field those on patch testing, agent vs. agent-less approach, building secure code and more.

https://www.nwfusion.com/cgi-bin/forum/gforum.cgi?post=1964

Today’s bug patches and security alerts:

Samba buffer overflow patched

A buffer overflow vulnerability in Samba, an open source file/print server application, could be exploited by an attacker to run any code they wished on the affected machine. Version 3.08 of Samba is said to fix the problem. For more, go to:

e-Matters advisory:

https://security.e-matters.de/advisories/132004.html

Samba download page:

https://us1.samba.org/samba/download/

Gentoo:

https://security.gentoo.org/glsa/glsa-200411-21.xml

Mandrake Linux:

https://www.nwfusion.com/go2/1115bug2a.html

SuSE:

https://www.suse.com/de/security/2004_40_samba.html

Trustix (update also fixes flaws in sudo, gd and sqlgrey):

https://www.trustix.org/errata/2004/0058/

**********

Updated Apache packages available

Problems with the get_tag() function of mod_include module for Apache have been fixed by a number of vendors. The flaw could be used to “run arbitrary code with the rights of an httpd child process.” For more, go to:

Conectiva:

https://www.nwfusion.com/go2/1115bug2b.html

Debian:

https://www.debian.org/security/2004/dsa-594

Gentoo:

https://security.gentoo.org/glsa/glsa-200411-18.xml

Mandrake Linux (apache):

https://www.nwfusion.com/go2/1115bug2c.html

Mandrake Linux (apache2):

https://www.nwfusion.com/go2/1115bug2d.html

**********

Mandrake Linux, OpenPKG patch gd

A buffer overflow in the gd graphics library could be exploited in a denial-of-service attack against the affected machine or to potentially run any code. For more, go to:

Mandrake Linux:

https://www.nwfusion.com/go2/1115bug2e.html

OpenPKG:

https://www.openpkg.org/security/OpenPKG-SA-2004.049-gd.txt

**********

Mandrake Linux patches sudo

A new sudo update fixes a flaw in the way “bash” functions are exported to other applications. A user could exploit the flaw to run arbitrary commands on the affected machine. For more, go to:

https://www.nwfusion.com/go2/1115bug2f.html

**********

Conectiva, OpenPKG release patch for libxml

Multiple buffer overflows have been found in the various libxml image handling libraries. These could be exploited in a denial-of-service attack or to potentially run an attacker’s code of choice on the affected machine. For more, go to:

Conectiva:

https://www.nwfusion.com/go2/1115bug2g.html

OpenPKG:

https://www.openpkg.org/security/OpenPKG-SA-2004.050-libxml.txt

**********

Debian patches ImageMagick

A flaw in the ImageMagick graphics package could be exploited to execute arbitrary code on the affected machine, according to a Debian advisory. For more, go to:

https://www.debian.org/security/2004/dsa-593

**********

OpenPKG patches mysql

Several flaws in the MySQL application for OpenPKG could be exploited to gain elevated privileges or any application/malicious code on the affected machine. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2004.045-mysql.txt

**********

Skype update fixes two flaws

Skype, which makes an IP softphone application, is urging users to upgrade to Version 1.0.0.100 to fix two vulnerabilities in the initial 1.0 release. One flaw revolves around internal data handling and the other is a buffer overflow. No word on how these could be exploited.

Download page:

https://www.skype.com/products/skype/windows/

Change log:

https://www.skype.com/products/skype/windows/changelog.html

**********

Today’s roundup of virus alerts:

IFRAME.BoF – This exploits an iFrame vulnerability in Internet Explorer 6.0. Users are directed to a malicious Web page where this code is hidden. It causes a buffer overflow, which can be used to take control of the affected machine. Unfortunately, no patch is available yet. (Panda Software)

W32/Bofra-G – Yet another Bofra (formerly MyDoom variant) going around. It too spreads via e-mail using a couple different messages, but all with attachments ending in 32.exe. It also opens a backdoor on port 6667 and will stop working on December 15th.(Sophos)

W32/Forbot-CJ – This bot spreads via network shares and installs itself as “regexpress.exe”. It allows backdoor access via IRC and can be used for denial-of-service attacks, as a proxy server, to steal passwords and more. (Sophos)

W32/Rbot-PU – An Rbot variant that infects the file “wuamgrd32.exe” in the Windows System directory. It allows backdoor access via IRC, but no word on other damage it can inflict. (Sophos)

W32/Rbot-NK – This Rbot variant tries to hide itself as the RealOne Player executable, “realplay.exe”. The worm can be controlled via IRC and used for a number of malicious purposes. (Sophos)

W32/Ssik-A – Hey, a new name! This worm uses a random filename to infect a Windows machine and displays the message “LoRz reborn!!”. It also tries to move the Task Manager application to make the worm harder to stop. (Sophos)

W32/Agobot-NX – A new Agobot variant that uses the file “bmsvc32.exe” as its infection point in the Windows System folder. The virus modifies the HOSTS file in an attempt to block access to popular anti-virus and security sites. (Sophos)

Troj/Mirchack-D – This is a hacked version of the mIRC chat application. It can be used in a denial of service attack or to install a backdoor on the infected machine. (Sophos)

W32/Protoride-W – A backdoor Trojan that listens for commands via IRC. It spreads via network shares using the file “msupdate.exe”. (Sophos)

W32/Mofei-E – A backdoor application that spreads via network shares. It installs itself as “ALERTER.EXE” and runs as the service “Net Login Helper”. It also copies itself in a number of popular applications. (Sophos)

**********

From the interesting reading department:

AOL upgrade packs security tools

AOL subscribers Thursday will receive a raft of new and enhanced security services as part of their standard package with the launch of AOL 9.0 Security Edition, the latest upgrade of the company’s fee-based, consumer-focused online service.  IDG News Service, 11/18/04.

https://www.nwfusion.com/news/2004/1118aolupgra.html?nl

Newsletter: Linux is ‘most breached’ OS on the ‘Net, security research firm says.

According to London security analysis and consulting firm mi2g, Linux is the most commonly breached operating system on computers connected to the Internet 24/7. Network World Linux Newsletter, 11/10/04.

https://www.nwfusion.com/newsletters/linux/2004/1108linux2.html?nl

Internet Security Intelligence Briefing

The VeriSign Internet Security Intelligence Briefing reports current trends for Internet growth, usage, security, and online fraud. This briefing includes data and intelligence drawn from VeriSign’s Internet infrastructure services, including DNS services, digital certificates (SSL and PKI), Managed Security Services (MSS), Payments, and Fraud Protection Service. VeriSign, November 2004.

https://www.verisign.com/static/017574.pdf

Microsoft releases management tools, expands on DSI model

Microsoft Tuesday released a handful of software products that are key elements in its drive to develop a comprehensive management platform for Windows. The company also released the first beta of its newest corporate patch server. Network World Fusion, 11/16/04.

https://www.nwfusion.com/news/2004/1116msdsi.html?nl

AMD readies security, virtualization features for 2006

Advanced Micro Devices plans to build security and virtualization features into its server processors by 2006, the company said Friday during its annual analyst event. IDG News Service, 11/15/04.

https://www.nwfusion.com/news/2004/1115amdreadi.html?nl

Panel: Gov’t can’t mandate security

Now is not the time for the U.S. government to mandate cybersecurity standards to private industry, despite significant threats and a lack of understanding by many company executives. So concluded a panel of government officials that met to discuss the issue in September. IDG News Service, 11/15/04.

https://www.nwfusion.com/news/2004/1115panelgovt.html?nl