* Patches from Cisco, FreeBSD, Debian, others * Beware latest Agobot and Rbot variants * InfoExpress simplifies security devices, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Cisco patches CNS Network Registrar DNS/DHCP server
According to a Cisco alert, “Cisco CNS Network Registrar Domain Name Service /Dynamic Host Configuration Protocol (DNS/DHCP) server for the Windows Server platforms is vulnerable to a Denial of Service attack when a certain crafted packet sequence is directed to the server. Cisco has made free software available to address this vulnerability for all affected customers.” For more, go to:
https://www.cisco.com/warp/public/707/cisco-sa-20041202-cnr.shtml
**********
Apple releases Mac OS X update to fix multiple application flaws
Apple Security Update 2004-12-02 fixes problems in multiple applications: Apache, Apache 2, Appkit, Cyrus IMAP, HIToolbox, Kerberos, Postfix, PSNormalizer, QuickTime Streaming Server, Safari, and Terminal. For more, go to:
https://www.nwfusion.com/go2/1206bug1a.html
**********
FreeBSD patches procfs and linprocfs
Flaws in FreeBSD’s implementation of procfs and linprocfs could be exploited by a local user in a denial-of-service attack against the affected machine. There’s also a chance that kernel information could be leaked via the exploit. For more, go to:
https://www.nwfusion.com/go2/1206bug1b.html
**********
Debian patches BNC
A buffer overflow in BNC, an IRC proxy, could be exploited by a malicious IRC server operator to run code on the affected client machine. For more, go to:
https://www.debian.org/security/2004/dsa-595
Debian fixes yardradius
A stack overflow in yardradius, a radius authentication and accounting server, could be exploited to run any code on the affected machine. For more, go to:
https://www.debian.org/security/2004/dsa-598
Debian issues patch for tetex-bin
A number of integer overflows have been found in tetex-bin, which could be exploited by a specially crafted PDF file and used to run an attacker’s code on the affected machine. For more, go to:
https://www.debian.org/security/2004/dsa-599
Debian releases patch for libgd1, libgd2
Debian has found more potential buffer overflows in the GD library. Using code embedded in an image, an attacker could run arbitrary code on the affected machine when one of these overflows is exploited. For more, go to:
libgd1:
https://www.debian.org/security/2004/dsa-601
libgd2:
https://www.debian.org/security/2004/dsa-602
**********
Gentoo releases patch for TWiki
A flaw in TWiki could allow an attacker to run commands on the affected machine with the privileges of the TWiki user. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-33.xml
Gentoo patches phpBB
An attacker could run any code on the phpBB server with the privilege of the phpBB process if an undisclosed vulnerability is exploited. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-32.xml
Gentoo issues phpWebSite patch
According to Gentoo, “phpWebSite is vulnerable to possible HTTP response splitting attacks.” For more, go to:
https://security.gentoo.org/glsa/glsa-200411-35.xml
Gentoo releases fix for phpMyAdmin
The phpMyAdmin application, which provides Web-based management for MySQL databases, is vulnerable to a cross-scripting attack. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-36.xml
**********
Conectiva issues fix for samba
A buffer overflow vulnerability in Samba, an open source file/print server application, could be exploited by an attacker to run any code they wished on the affected machine. Version 3.08 of Samba is said to fix the problem. For more, go to:
https://www.nwfusion.com/go2/1206bug1c.html
**********
Mandrake Linux releases patch for a2ps
According to an alert from Mandrake Linux, “The GNU a2ps utility fails to properly sanitize filenames, which can be abused by a malicious user to execute arbitrary commands with the privileges of the user running the vulnerable application.”
https://www.nwfusion.com/go2/1206bug1d.html
Mandrake Linux patches zip
A flaw in the zip compression utility could be exploited to trick the user into creating directory with code that could be run on the affected machine with the privileges of the zip process. For more, go to:
https://www.nwfusion.com/go2/1206bug1e.html
**********
Today’s roundup of virus alerts:
W32/Agobot-NZ – This Agobot variant targets machines that infected with the MyDoom virus. It installs the file “gmsvc32.exe” in the Windows System directory. It allows backdoor access via IRC and tries to limit access to security sites by modifying the HOSTS file. (Sophos)
W32/Agobot-OH – Another Agobot variant that targets network shares with weak or no password protection. It installs “trendav.exe” in the Windows System folder. It too allows IRC backdoor access and limits access to certain security sites. (Sophos)
W32/Agobot-OL – Yet another Agobot relative. It uses the file “smsvc32.exe” and adds the wrinkle of being able to steal CD key and other sensitive information. (Sophos)
W32/Rbot-QX – An Rbot variant that uses a random, nine-letter file name to infect systems, but it adds the registry key “upd4te2d4te”. It spreads to machines via network shares, exploiting the DCOM-RPC, LSASS, WebDAV and UPNP. (Sophos)
W32/Rbot-RC – This Rbot variant installs “lmhosts.exe” in the Windows System folder. It listens for requests from the outside on port 113 and can be used to steal information and participate in DDoS attacks. (Sophos)
W32/Sdbot-RU – This bot version installs the file “outlook.exe” in the Windows System directory. It can be used to redirect Internet traffic, join in DDoS attacks, and steal registration keys for popular games. (Sophos)
**********
From the interesting reading department:
InfoExpress simplifies security devices
InfoExpress is merging its LAN and WAN access-control appliances into one product that will let customers simplify local or remote network access policies. Network World, 12/06/04.
https://www.nwfusion.com/news/2004/120604infoexpress.html?nl
HP adds identity wares to platform
HP last week added a new piece to its identity management lineup that is designed to allow companies to share identity information across corporate boundaries. Network World, 12/06/04.
https://www.nwfusion.com/news/2004/120604hpidentity.html?nl
Axalto unveils smart card powered by .Net
Axalto last week offered up a smart card based on Microsoft’s .Net technology, which could make it easier for corporations adopting .Net for Web services to develop card-based security. Network World, 12/06/04.
https://www.nwfusion.com/news/2004/120604axalto.html?nl
Bluesocket to secure branch WLANs
Bluesocket this week is scheduled to uncrate a wireless gateway and a Web-based management application that lets network administrators remotely authenticate, secure and manage wireless LAN users in hundreds of branch offices. Network World, 12/06/04.
https://www.nwfusion.com/news/2004/120604blusocket.html?nl
Former cybersecurity czar: Code-checking tools needed
Software vendors need automated tools that look for bugs in their code, but it may be a decade before many of those tools are mature and widely used, said the former director of cybersecurity for the U.S. Department of Homeland Security. IDG News Service, 12/02/04.
https://www.nwfusion.com/news/2004/1202formecyber.html?nl
Deepnet browser guards against phishing
Internet users are getting more Web browser choices. On the heels of a new Netscape preview release and the launch of Firefox 1.0, a U.K. company on Thursday released a Web browser it claims is more secure than Internet Explorer or Firefox. IDG News Service, 12/02/04.
https://www.nwfusion.com/news/2004/1202deepnbrows.html?nl
Mobile phones: An ear full of worms
They’re coming to mobile phones – those nasty viruses, worms and Trojan horses that have, on more than one occasion, crippled PCs. No doubt about that. The question is: Will they be as bad? IDG News Service, 12/03/04.




