Cisco patches CNS Network Registrar

Opinion
Dec 6, 20047 mins

* Patches from Cisco, FreeBSD, Debian, others * Beware latest Agobot and Rbot variants * InfoExpress simplifies security devices, and other interesting reading

Today’s bug patches and security alerts:

Cisco patches CNS Network Registrar DNS/DHCP server

According to a Cisco alert, “Cisco CNS Network Registrar Domain Name Service /Dynamic Host Configuration Protocol (DNS/DHCP) server for the Windows Server platforms is vulnerable to a Denial of Service attack when a certain crafted packet sequence is directed to the server. Cisco has made free software available to address this vulnerability for all affected customers.” For more, go to:

https://www.cisco.com/warp/public/707/cisco-sa-20041202-cnr.shtml

**********

Apple releases Mac OS X update to fix multiple application flaws

Apple Security Update 2004-12-02 fixes problems in multiple applications: Apache, Apache 2, Appkit, Cyrus IMAP, HIToolbox, Kerberos, Postfix, PSNormalizer, QuickTime Streaming Server, Safari, and Terminal. For more, go to:

https://www.nwfusion.com/go2/1206bug1a.html

**********

FreeBSD patches procfs and linprocfs

Flaws in FreeBSD’s implementation of procfs and linprocfs could be exploited by a local user in a denial-of-service attack against the affected machine. There’s also a chance that kernel information could be leaked via the exploit. For more, go to:

https://www.nwfusion.com/go2/1206bug1b.html

**********

Debian patches BNC

A buffer overflow in BNC, an IRC proxy, could be exploited by a malicious IRC server operator to run code on the affected client machine. For more, go to:

https://www.debian.org/security/2004/dsa-595

Debian fixes yardradius

A stack overflow in yardradius, a radius authentication and accounting server, could be exploited to run any code on the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-598

Debian issues patch for tetex-bin

A number of integer overflows have been found in tetex-bin, which could be exploited by a specially crafted PDF file and used to run an attacker’s code on the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-599

Debian releases patch for libgd1, libgd2

Debian has found more potential buffer overflows in the GD library. Using code embedded in an image, an attacker could run arbitrary code on the affected machine when one of these overflows is exploited. For more, go to:

libgd1:

https://www.debian.org/security/2004/dsa-601

libgd2:

https://www.debian.org/security/2004/dsa-602

**********

Gentoo releases patch for TWiki

A flaw in TWiki could allow an attacker to run commands on the affected machine with the privileges of the TWiki user. For more, go to:

https://security.gentoo.org/glsa/glsa-200411-33.xml

Gentoo patches phpBB

An attacker could run any code on the phpBB server with the privilege of the phpBB process if an undisclosed vulnerability is exploited. For more, go to:

https://security.gentoo.org/glsa/glsa-200411-32.xml

Gentoo issues phpWebSite patch

According to Gentoo, “phpWebSite is vulnerable to possible HTTP response splitting attacks.” For more, go to:

https://security.gentoo.org/glsa/glsa-200411-35.xml

Gentoo releases fix for phpMyAdmin

The phpMyAdmin application, which provides Web-based management for MySQL databases, is vulnerable to a cross-scripting attack. For more, go to:

https://security.gentoo.org/glsa/glsa-200411-36.xml

**********

Conectiva issues fix for samba

A buffer overflow vulnerability in Samba, an open source file/print server application, could be exploited by an attacker to run any code they wished on the affected machine. Version 3.08 of Samba is said to fix the problem. For more, go to:

https://www.nwfusion.com/go2/1206bug1c.html

**********

Mandrake Linux releases patch for a2ps

According to an alert from Mandrake Linux, “The GNU a2ps utility fails to properly sanitize filenames, which can be abused by a malicious user to execute arbitrary commands with the privileges of the user running the vulnerable application.”

https://www.nwfusion.com/go2/1206bug1d.html

Mandrake Linux patches zip

A flaw in the zip compression utility could be exploited to trick the user into creating directory with code that could be run on the affected machine with the privileges of the zip process. For more, go to:

https://www.nwfusion.com/go2/1206bug1e.html

**********

Today’s roundup of virus alerts:

W32/Agobot-NZ – This Agobot variant targets machines that infected with the MyDoom virus. It installs the file “gmsvc32.exe” in the Windows System directory. It allows backdoor access via IRC and tries to limit access to security sites by modifying the HOSTS file. (Sophos)

W32/Agobot-OH – Another Agobot variant that targets network shares with weak or no password protection. It installs “trendav.exe” in the Windows System folder. It too allows IRC backdoor access and limits access to certain security sites. (Sophos)

W32/Agobot-OL – Yet another Agobot relative. It uses the file “smsvc32.exe” and adds the wrinkle of being able to steal CD key and other sensitive information. (Sophos)

W32/Rbot-QX – An Rbot variant that uses a random, nine-letter file name to infect systems, but it adds the registry key “upd4te2d4te”. It spreads to machines via network shares, exploiting the DCOM-RPC, LSASS, WebDAV and UPNP. (Sophos)

W32/Rbot-RC – This Rbot variant installs “lmhosts.exe” in the Windows System folder. It listens for requests from the outside on port 113 and can be used to steal information and participate in DDoS attacks. (Sophos)

W32/Sdbot-RU – This bot version installs the file “outlook.exe” in the Windows System directory. It can be used to redirect Internet traffic, join in DDoS attacks, and steal registration keys for popular games. (Sophos)

**********

From the interesting reading department:

InfoExpress simplifies security devices

InfoExpress is merging its LAN and WAN access-control appliances into one product that will let customers simplify local or remote network access policies. Network World, 12/06/04.

https://www.nwfusion.com/news/2004/120604infoexpress.html?nl

HP adds identity wares to platform

HP last week added a new piece to its identity management lineup that is designed to allow companies to share identity information across corporate boundaries. Network World, 12/06/04.

https://www.nwfusion.com/news/2004/120604hpidentity.html?nl

Axalto unveils smart card powered by .Net

Axalto last week offered up a smart card based on Microsoft’s .Net technology, which could make it easier for corporations adopting .Net for Web services to develop card-based security. Network World, 12/06/04.

https://www.nwfusion.com/news/2004/120604axalto.html?nl

Bluesocket to secure branch WLANs

Bluesocket this week is scheduled to uncrate a wireless gateway and a Web-based management application that lets network administrators remotely authenticate, secure and manage wireless LAN users in hundreds of branch offices. Network World, 12/06/04.

https://www.nwfusion.com/news/2004/120604blusocket.html?nl

Former cybersecurity czar: Code-checking tools needed

Software vendors need automated tools that look for bugs in their code, but it may be a decade before many of those tools are mature and widely used, said the former director of cybersecurity for the U.S. Department of Homeland Security. IDG News Service, 12/02/04.

https://www.nwfusion.com/news/2004/1202formecyber.html?nl

Deepnet browser guards against phishing

Internet users are getting more Web browser choices. On the heels of a new Netscape preview release and the launch of Firefox 1.0, a U.K. company on Thursday released a Web browser it claims is more secure than Internet Explorer or Firefox. IDG News Service, 12/02/04.

https://www.nwfusion.com/news/2004/1202deepnbrows.html?nl

Mobile phones: An ear full of worms

They’re coming to mobile phones – those nasty viruses, worms and Trojan horses that have, on more than one occasion, crippled PCs. No doubt about that. The question is: Will they be as bad? IDG News Service, 12/03/04.

https://www.nwfusion.com/news/2004/1203mobilphone.html?nl