* Patches from Mandrake Linux, Trustix, Conectiva, others * Beware new bot, Santabot * Attacks on Microsoft WINS hole raise alarms, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Today’s bug patches and security alerts:
NGSSoftware warns of multiple flaws in IBM DB2
Security consultants at NGSSoftware are warning of multiple flaws in the popular IBM DB2 database system. Many of the issues are remotely exploitable buffer overflows that could result in malicious code being run on the affected server. For more, go to:
https://www.nextgenss.com/advisories/db2-02.txt
**********
Mozilla 1.7.5 fixes NNTP flaw
A buffer overflow was found in the Network News Transport Protocol (NNTP) of older versions of Mozilla. Version 1.7.5 is said to fix the problem. Download the new version at:
https://www.mozilla.org/products/mozilla1.x/
**********
Mandrake Linux updates
Over the past few weeks while we were sipping Egg Nog, Mandrake Linux released the following updates:
IProute2 (temporary files):
https://www.nwfusion.com/go2/0103bug2a.html
Postgresql (temporary files):
https://www.nwfusion.com/go2/0103bug2b.html
Ethereal (multiple flaws):
https://www.nwfusion.com/go2/0103bug2c.html
Aspell (code execution):
https://www.nwfusion.com/go2/0103bug2d.html
Kdelibs (multiple):
https://www.nwfusion.com/go2/0103bug2e.html
https://www.nwfusion.com/go2/0103bug2k.html
Logcheck (overwrite files):
https://www.nwfusion.com/go2/0103bug2f.html
Krb5 (buffer overflow):
https://www.nwfusion.com/go2/0103bug2g.html
Mplayer (buffer overflows):
https://www.nwfusion.com/go2/0103bug2h.html
Samba (integer overflow):
https://www.nwfusion.com/go2/0103bug2i.html
Glibc (temporary files):
https://www.nwfusion.com/go2/0103bug2j.html
Kdegraphics (buffer overflow):
https://www.nwfusion.com/go2/0103bug2l.html
CUPS (buffer overflow):
https://www.nwfusion.com/go2/0103bug2m.html
Koffice (multiple):
https://www.nwfusion.com/go2/0103bug2n.html
Tetex (multiple):
https://www.nwfusion.com/go2/0103bug2o.html
**********
Trustix patches
A few Trustix updates from the past couple weeks:
Kernel (multiple flaws):
https://www.trustix.org/errata/2004/0068/
Kerberos5 (code execution):
https://www.trustix.org/errata/2004/0069/
Samba, PHP (multiple):
https://www.trustix.org/errata/2004/0066/
**********
SuSE updates
Updates from the folks at SuSE:
Kernel (multiple issues):
https://www.nwfusion.com/go2/0103bug2p.html
https://www.nwfusion.com/go2/0103bug2q.html
Samba (privilege escalation):
https://www.nwfusion.com/go2/0103bug2r.html
**********
OpenPKG fixes
A couple updates have been released for OpenPKG over the past weeks:
Gettext (temporary files):
https://www.openpkg.org/security/OpenPKG-SA-2004.055-gettext.html
Cvstrac (cross-scripting):
https://www.openpkg.org/security/OpenPKG-SA-2004.056-cvstrac.html
**********
Conectiva patches
A couple updates have been released for Conectiva over the past weeks:
Netpbm (temporary files):
https://www.nwfusion.com/go2/0103bug2s.html
Mplayer (buffer overflow):
https://www.nwfusion.com/go2/0103bug2t.html
**********
KDE issues patches
The latest patches from KDE:
FTP kioslave (command injection):
https://www.kde.org/info/security/advisory-20050101-1.txt
Konqueror Java Vulnerability:
https://www.kde.org/info/security/advisory-20041220-1.txt
**********
Sybase patches Adaptive Server Enterprise
NGSSoftware is reporting that Sybase has issued an update for its Adaptive Server Enterprise system. Version 12.5.3 fixes three high-profile flaws in the older versions of the software. For more, go to:
https://www.nwfusion.com/go2/0103bug2u.html
**********
Today’s roundup of virus alerts:
Troj/Agent-FO – A Trojan that installs random folders and files on the infected machine. It can be used to download code from the Internet. No real specifics were given. (Sophos)
Troj/BeastDo-W – This Trojan installs multiple files on the infected machine, including “svchost.exe” in the Windows folder and two randomly named PIF files in the Windows System folder. (Sophos)
W32/Sdbot-SW – Another Sdbot variant that allows backdoor access to the infected machine via IRC. It spreads via network shares and drops two files in the Windows System32 file: “HB90HGF3.EXE” and “SYSEDITS.EXE”, the latter being corrupt. It can be used for a number malicious purposes. (Sophos)
W32/Sdbot-SV – This variant spreads via a file called “buds.exe” and drops “forcepog.exe” in the Windows system folder. IRC can be used to control the Trojan, which can be used for DDoS attacks and system scanning. (Sophos)
W32/Puce-B – This virus runs on the 26th of certain months and moves the cursor around randomly when it activates. No word of permanent damage. (Sophos)
W32/Forbot-DJ – Yet another bot that spreads via network shares and allows backdoor access to IRC. It drops the file “ctst.exe” in the Windows System folder. It can be used as an HTTP proxy, launch DoS attacks and steal local information. (Sophos)
Troj/Santabot-A – A new bot that drops the file “DLLCACHEV2.EXE” in the Windows System folder. It can be used to download additional code or carry out malicious activities. (Sophos)
W32/Agobot-OT – A new Agobot variant that installs “updater.exe” in the Windows System folder after spreading via network shares. It can be used to limit access to anti-virus sites by modifying the HOSTS file and terminates similar applications. (Sophos)
W32/Rbot-SQ – This Rbot variant drops the file “mcafeee.exe” in the Windows System folder. It can be used a proxy, to launch DoS attacks, log keystrokes and can be used to start/stop systems. (Sophos)
**********
From the interesting reading department:
Attacks on Microsoft WINS hole raise alarms
Internet security monitoring groups are warning Microsoft Windows users about new Internet attacks aimed at Windows NT, Windows2000 and Windows Server 2003 machines running Windows Internet Naming Service. The attacks target a WINS vulnerability that was reported and patched by Microsoft in December. IDG News Service, 01/05/05.
https://www.nwfusion.com/news/2005/0105attaconmi.html?nl
AEP, Netilla merge amid SSL remote access shakeout
SSL remote access rivals AEP Systems and Netilla have merged to form AEP Networks with the hope of gaining enough business to survive the shakeout among SSL remote access vendors. Network World Fusion, 01/05/05.
https://www.nwfusion.com/news/2005/0105netilla.html?nl
Congresswoman reintroduces spyware bill
Spyware legislation that would allow fines of up to $3 million for makers of software that steals personal information from a user’s computer or highjacks its browser will get a second look after the U.S. Congress failed to pass the legislation in 2004. IDG News Service, 01/05/05.
https://www.nwfusion.com/news/2005/0105congrreint.html?nl
CES: Broadcom secures WLANs in one push of a button
Wi-Fi silicon vendor Broadcom plans to release new Wi-Fi security software that allows users to easily set up secure home wireless networks with access points from Linksys and devices from HP, the companies are expected to announce Wednesday at the International Consumer Electronics Show in Las Vegas. IDG News Service, 01/06/05.
https://www.nwfusion.com/news/2005/0106ces-bro.html?nl
Microsoft hurries anti-spyware, holds Exchange updates
Microsoft is getting ready to release a beta version of anti-spyware technology it purchased last month to the public, but will delay promised anti-spam and anti-virus improvements to the Exchange e-mail server, according to information provided by the company. IDG News Service, 01/05/05.




