A bushel of Linux updates

Opinion
Jan 10, 20058 mins

* Patches from Conectiva, NetBSD, Gentoo, others * Beware Trojan disguised as Flash player * NIST mulls new WLAN security guidelines, and other interesting reading

We finish cleaning out the extensive number of updates we got over the past few weeks. Thankfully, we just have to write about 99% of these patches and not actually install them in our production environment.

Today’s bug patches and security alerts:

Conectiva patches Samba

An integer overflow in the Samba SMB/CIFS services could be exploited to run code on the affected machine with root privileges. The attacker would need valid credentials to access the server before they could exploit the flaw. For more, go to:

https://www.nwfusion.com/go2/0110bug1b.html

**********

NetBSD patches compat

A flaw in the way certain system calls are made to the NetBSD kernel could be exploited by a local user to gain elevated privileges. For more, go to:

https://www.nwfusion.com/go2/0110bug1a.html

**********

iDefense warns of Computer Associates eTrust EZ Antivirus flaws

According to iDefense, the default file Access Control List settings in Computer Associates eTrust EZ Antivirus could be exploited to disable the service or gain elevated privileges on the affected machine. For more, go to:

https://www.nwfusion.com/go2/0110bug1i.html

**********

Recent updates from Gentoo:

LinPopUp (Buffer overflow):

https://security.gentoo.org/glsa/glsa-200501-01.xml

A2ps (temporary files):

https://security.gentoo.org/glsa/glsa-200501-02.xml

Mozilla, Firefox, Thunderbird (multiple):

https://security.gentoo.org/glsa/glsa-200501-03.xml

Shoutcast Server (code execution):

https://security.gentoo.org/glsa/glsa-200501-04.xml

MIT-krb5 (heap overflow):

https://security.gentoo.org/glsa/glsa-200501-05.xml

Tiff (integer overflow):

https://security.gentoo.org/glsa/glsa-200501-06.xml

Xine-lib (multiple overflows):

https://security.gentoo.org/glsa/glsa-200501-07.xml

PHPGroupWare (multiple):

https://security.gentoo.org/glsa/glsa-200501-08.xml

Xzgv (multiple overflows):

https://security.gentoo.org/glsa/glsa-200501-09.xml

Vilistextum (buffer overflow):

https://security.gentoo.org/glsa/glsa-200501-10.xml

**********

Recent updates from Debian:

Htmlheadline (temporary files):

https://www.debian.org/security/2005/dsa-622

Nasm (buffer overflow):

https://www.debian.org/security/2005/dsa-623

Zip (buffer overflow):

https://www.debian.org/security/2005/dsa-624

Pcal (buffer overflows):

https://www.debian.org/security/2005/dsa-625

Tiff (buffer overflow):

https://www.debian.org/security/2005/dsa-626

Namazu2 (cross-scripting):

https://www.debian.org/security/2005/dsa-627

Imlib2 (integer overflow):

https://www.debian.org/security/2005/dsa-628

Krb5 (buffer overflow):

https://www.debian.org/security/2005/dsa-629

**********

Recent updates from Mandrake Linux:

Libtiff (multiple):

https://www.nwfusion.com/go2/0110bug1c.html

https://www.nwfusion.com/go2/0110bug1d.html

https://www.nwfusion.com/go2/0110bug1e.html

wxGTK2 (multiple):

https://www.nwfusion.com/go2/0110bug1f.html

Vim (multiple):

https://www.nwfusion.com/go2/0110bug1g.html

Nasm (buffer overflow):

https://www.nwfusion.com/go2/0110bug1h.html

**********

Today’s roundup of virus alerts:

Trojan disguised as Flash player targets cell phones

An updated variant of the Skulls Trojan horse comes disguised as a new version of the Macromedia Flash player to fool users of mobile phones running the Symbian operating system. IDG News Service, 01/07/05.

https://www.nwfusion.com/news/2005/0107trojadisgu.html?nl

Winxor.A – Exploits the Windows WINS vulnerability that was recently disclosed. It allows backdoor access via IRC and installs an FTP server that is accessible on port 36010. (Panda Software)

W32/Sdbot-SW – This Trojan drops two files in the Windows folder after infecting a machine via a network share. The first file is called “HB90HGF3.EXE” and the second is “SYSEDITS.EXE”, though it seems to be corrupt. It can allow backdoor access via IRC. (Sophos)

W32/Sdbot-TA – An Sdbot variant that installs “tbbzxzxcxxcx.exe” in the Windows System folder after spreading through a network share. It can be used to provide backdoor access via IRC and other malicious purposes. (Sophos)

W32/Sdbot-TB – This variant installs “wupdated.exe” in the Windows System directory and registers itself as a “Windows Update Service”. It can be used as an HTTP proxy, participate in denial-of-service attacks, and log keystrokes. (Sophos)

Troj/Corpse-A – A proxy Trojan that installs “EPLRR3.DLL” in the Windows System folder and allows access to the infected machine. (Sophos)

W32/Pikis-B – This e-mail worms spreads through a message that looks like it is sent from a .ru domain and has an .exe attachment. It can disable a number of security-related processes running on the infected machine. (Sophos)

W32/Rbot-SX – An Rbot variant that exploits a number of known Windows vulnerabilities as it spreads through network shares. It drops the read-only file “win32src.exe” in the Windows System directory and can be used for a number of malicious purposes. (Sophos)

W32/Agobot-OU – Another worm that spreads through network shares and allows backdoor access via IRC. This variant drops the file “WINSRV.EXE” in the Windows System directory and can be used steal information from the local machine or participate in denial-of-service attacks. (Sophos)

W32/Agobot-ADH – A similar Agobot variant that spreads via network shares. No infected file name given, but this variant can block access to security related Web sites by modifying the Windows HOSTS file. (Sophos)

Troj/Feutel-A – A worm that attempts to download code from a number of pre-configured sites. It can be used to log keystrokes and provide backdoor access to the infected machine via IRC. It drops the file “G-Server.exe”. (Sophos)

VBS/Mcon-G – A Visual Basic worm that spreads via IRC and may delete files from the infected machine. It’ll also copy itself to a number of locations on the infected hard drive and any attached network drive. (Sophos)

**********

From the interesting reading department:

Forget about sleeping: It’s Patch Tuesday

Microsoft’s monthly patch release triggers a race between hackers, vendors and customers. Network World, 01/10/05.

https://www.nwfusion.com/news/2005/011005widernetpatchtuesday.html?nl

NIST mulls new WLAN security guidelines

The National Institute of Standards and Technology, the federal agency responsible for defining security standards and practices for the government, plans to issue new guidelines pertaining to wireless LANs in the near future. Network World, 01/10/05.

https://www.nwfusion.com/news/2005/011005nist.html?nl

McAfee tool identifies exposed data

Recognizing that Google’s search engine can become a repository for far too much information, McAfee this week released an updated version of its Foundstone SiteDigger security tool that helps enterprises identify damaging information that may be exposed on the Web. InfoWorld, 01/10/05.?

https://www.nwfusion.com/news/2005/0110mcafetool.html

Technology Update: Identified Internet Mail combats fraud

IIM provides new protection that can help stem the tide of unwanted and harmful e-mail. Network World, 01/10/05.

https://www.nwfusion.com/news/tech/2005/011005techupdate.html?nl

A look into the future

Well, industry experts say to expect network industry merger activity – nearly $60 billion worth of which took place in one week last month – to continue unabated, and don’t be surprised if this turns out to be the year enterprise-scale VoIP makes it to the mainstream. Look for licensing issues to be top of mind as vendors iron out the impact of server enhancements on application pricing. You might even catch a glimpse of Microsoft’s long-awaited Longhorn software, albeit in beta only. Network World, 01/10/05.

https://www.nwfusion.com/news/2005/011005crystalball.html?nl

Opinion: Divine divination

Welcome to 2005! As this is the crystal ball issue, I was looking for predictions about the coming year. I was tempted by molybdomancy (divining from the shapes created by dripping molten lead into cold water) but in the end decided to go with the traditional goat’s entrails. So, here’s what 2005 has in store for us … Network World, 01/10/05.

https://www.nwfusion.com/columnists/2005/011005backspin.html?nl

Texas A&M probes traffic for assaults, faults

Texas A&M University has improved the network management and security for its sprawling wireless and wired campus network with an application that sifts through traffic for abnormalities or irregularities. Network World, 01/10/05.

https://www.nwfusion.com/news/2005/011005texasam.html?nl

Carriers increase companies’ control over handhelds

Some mobile operators already have some offerings in place to deal with the conflict over enterprise-class mobile phones. Network World, 01/10/05.

https://www.nwfusion.com/news/2005/011005ecsmartphoneside.html?nl

Weblog: Money mules

Kids today. We know that people who fall for phishing attacks have their bank/credit-card accounts sucked out. But people smart enough to set up the scams aren’t going to just have the money wired to themselves. Instead, they recruit “money mules.” Network World Fusion, 01/07/05.

https://www.nwfusion.com/compendium/2005/007180.html?nl

Newsletter: Security Web seminars: a good training resource

Readers of this column and others in the Network World Fusion series have no doubt received announcements of a wide variety of recorded lectures available on demand for different topics. However, many of us ignore such invitations, so I thought it would be helpful to review this resource here. Network World Security Newsletter, 01/06/05.

https://www.nwfusion.com/newsletters/sec/2005/0103sec2.html?nl