* Patches from Gentoo, Debian, others * Beware new Bagle variant * Threat center aims to thwart viruses, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
New version of GetRight available
The GetRight download manager that is widely used on Windows machines is vulnerable to a buffer overflow when handling skin files. An attacker could exploit this to run their code of choice on the affected machine. Version 5.2b fixes the issue. For more, go to:
https://www.getright.com/new52.html
**********
Gentoo patches rssh, scponly
Gentoo’s implementation of rssh and scponly do not properly filter command line options. An attacker could exploit this to bypass shell restrictions. For more, go to:
https://security.gentoo.org/glsa/glsa-200412-01.xml
Gentoo releases fix for PDFlib
Multiple buffer overflow vulnerabilities have been found in PDFlib. These could be exploited to run arbitrary code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200412-02.xml
Gentoo issues update for mirrorselect
Mirrorselect, “a tool for to help select distfiles mirrors for Gentoo,” does not securely create temporary files. This could be exploited in a symlink attack against the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200412-05.xml
Gento patches Perl
A local user could overwrite any file by using a symlink attack on temporary files created by Perl. A fix is available. For more, go to:
https://security.gentoo.org/glsa/glsa-200412-04.xml
**********
Debian patches viewcvs
Several flaws have been found in viewcvs, a tool for viewing CVS and Subversion repositories via a browser. In some cases, certain restrictions are ignored. For more, go to:
https://www.debian.org/security/2004/dsa-605
**********
Mandrake Linux releases updated gzip packages
A flaw in the way temporary files are created by Mandrake Linux’s implementation of gzip could be exploited in a symlink attack. For more, go to:
https://www.nwfusion.com/go2/1213bug1a.html
Mandrake Linux updates ImageMagick
According to a Mandrake Linux alert, “A vulnerability was discovered in ImageMagick where, due to a boundary error within the EXIF parsing routine, a specially crafted graphic image could potentially lead to the execution of arbitrary code.” For more, go to:
https://www.nwfusion.com/go2/1213bug1b.html
Mandrake Linux patches openssl
Poorly secured temporary files are created by one of the functions in Mandrake Linux’s openssl implementation. An attacker could exploit these via a symlink attack. For more, go to:
https://www.nwfusion.com/go2/1213bug1c.html
**********
Today’s roundup of virus alerts:
W32/Anig-C – A virus that spreads via network shares and can be used to steal passwords and log keystrokes. It drops the file “GinaDLL.DLL” and listens for remote commands on port 5190. (Sophos)
W32/Setclo-A – This virus too spreads via networks shares using the file “SETUP.EXE”. No word on any damage caused by this miscreant. (Sophos)
W32/Bagle-AA – A new Bagle variant that spreads via e-mail with varying subject lines. The infected attachment could have a number of different extensions, none of which belong to a legitimate attachment. The virus attempts to kill a number of security-related processes running on the infected machine. (Sophos)
W32/Agobot-NX – This IRC backdoor worm spreads via network shares, dropping “bmsvc32.exe” in the Windows System directory. It modifies the Windows HOSTS file to limit access to security related Web sites. (Sophos)
Troj/Brabot-A – Another worm that spreads via network shares. This one creates the registry entry “HKLMSoftwareMicrosoftWindowsCurrentVersionRun lmloader” It drops “lEXPLORE.exe” and “Pws.exe” on the infected machine as well. (Sophos)
W32/Atak-F – An e-mail worm that spreads in a message that looks like it is sent from the Microsoft Security Team. The infected attachment will have a .zip extension. (Sophos)
**********
From the interesting reading department:
Clear Choice Test: Enterprise-level anti-spyware software
We tested Webroot Software’s Spy Sweeper Enterprise Version 1.5, InterMute’s SpySubtract Pro Version 2.5, Tech Assist’s Omniquad AntiSpy Enterprise Edition Version 4.0 and PepiMK Software’s SpyBot – Search & Destroy Version 1.3. Network World, 12/13/04.
https://www.nwfusion.com/reviews/2004/121304rev.html?nl
Tech Update: Trusted chip assures endpoint integrity
Embedding trusted hardware into computing systems provides a reliable, secure way to determine endpoint integrity of clients, and protect networks against internal and external attack. Network World, 12/13/04.
https://www.nwfusion.com/news/tech/2004/121304techupdate.html?nl
Management Strategies: Identity introduction
Rolling out identity services projects requires careful steps and planning. Network World, 12/13/04.
https://www.nwfusion.com/careers/2004/121304man.html?nl
Threat center aims to thwart viruses
Hoping to help users take a proactive stance in hardening instant-messaging and peer-to-peer communications networks against viruses and worms, IMlogic last week opened a dedicated threat center to supply detection, analysis and thwarting of the work of hackers. Network World, 12/13/04.
https://www.nwfusion.com/news/2004/121304imlogic.html?nl
Nortel system stops network threats
Nortel now can protect businesses from never-before-seen threats using new intrusion-detection and -prevention technology that monitors network traffic and blocks the traffic that seems malicious. Network World, 12/13/04.
https://www.nwfusion.com/news/2004/121304nortel.html?nl
Phishing Web sites grew by 33% in November
The number of phishing Web sites associated with online identity theft scams grew by 33% in November, after dropping off in September and early October, according to data compiled by the Anti-Phishing Working Group (APWG) and shared with IDG News Service. IDG News Service, 12/10/04.
https://www.nwfusion.com/news/2004/1210phishwebs.html?nl
Symantec to buy IDS company Platform Logic
Anti-virus software company Symantec signed an agreement to buy Platform Logic, a maker of intrusion detection software, for an undisclosed sum, according to information obtained by IDG News Service. IDG News Service, 12/09/04.
https://www.nwfusion.com/news/2004/1209symantobu.html?nl
Digital PhishNet launched to combat phishing scams
A collaborative initiative involving several major industry players and law enforcement agencies Wednesday was formally launched in an effort to deal with the growing problem of online phishing scams. IDG News Service, 12/09/04.
https://www.nwfusion.com/news/2004/1209digitphish.html?nl
Fraud, feds top concerns as CSOs meet in New York
The explosive growth in online fraud and the impact of tough new federal regulations were on the minds of information security executives who gathered in New York Tuesday for the second annual CSO Interchange, a gathering of chief security officers. IDG News Service, 12/09/04.




