* Patches from FreeBSD, Debian, Red Hat, others * Beware new version of the Minmail worm * Check Point gear guards LANs, and other interesting reading
endif; ?>A little off the subject of security, but we’re looking for people that work at home and use videoconferencing to regularly keep in touch with colleagues in the home office. If you’re willing to be interviewed, drop me a line at jmeserve@nww.com.
Today’s bug patches and security alerts:
RealNetworks warns of media player security flaws
RealNetworks’ media player software contains vulnerabilities that could let an attacker take control of a PC on which the software is used to download multimedia files, the company confirmed this week. IDG News Service, 02/06/04.
https://www.nwfusion.com/news/2004/0206realnwarns.html?nl
RealNetworks patch:
https://www.service.real.com/help/faq/security/040123_player/EN/
NGSSoftware advisory:
https://www.nextgenss.com/advisories/realone.txt
**********
FreeBSD patches shmat
A flaw in shmat, part of the System V Shared Memory interface, could be exploited by an attacker to read/write to certain parts of the kernel memory. This could disclose sensitive information that could be used in future attacks. For more, go to:
https://www.nwfusion.com/go2/0209bug1a.html
**********
Debian patches gaim
Twelve vulnerabilities have been found in Gaim, a cross platform, multi-protocol instant messaging application. While some of the flaws are minor a few could be exploited to gain root privileges on the affected machine. For more, go to:
https://www.debian.org/security/2004/dsa-434
Debian issues fix for mpg123
A heap overflow in mpg123, a command-line media player, could be exploited to run arbitrary code on the affected machine with the privileges of the user running mpg123. For more, go to:
https://www.debian.org/security/2004/dsa-435
**********
Red Hat updates mailman packages
A new patch for mailman fixes a cross-site scripting vulnerability in the mailing list application. For more, go to:
https://rhn.redhat.com/errata/RHSA-2004-020.html
Red Hat patches NetPBM
A temporary files vulnerability exists in NetPBM that could allow an attacker create or overwrite files with the privileges of another user. For more, go to:
https://rhn.redhat.com/errata/RHSA-2004-030.html
**********
Mandrake Linux patches glibc
According to an alert from Mandrake Linux, “A read buffer overflow vulnerability exists in the resolver code in versions of glibc up to and including 2.2.5. The vulnerability is triggered by DNS packets larger than 1024 bytes, which can cause an application to crash.” For more, go to:
https://www.nwfusion.com/go2/0209bug1b.html
**********
Gentoo releases PHP patch
A flaw in PHP could allow an attacker to gain access to MySQL database passwords and other off-limit system areas. For more, go to:
https://forums.gentoo.org/viewtopic.php?t=133441
**********
Today’s roundup of virus alerts:
Troj/Sdbot-FM – A Trojan horse that runs as a Windows service and connects to an IRC server to allow unauthorized access to the infected machine by attackers. (Sophos)
W32/Agobot-CP – A back door Trojan horse that spreads between Windows machines by exploiting the DCOM RPC and RPC locator vulnerabilities. The virus connects to an IRC server to allow attackers unauthorized access to the infected machine. (Sophos)
W32/Mimail-T – Another version of the Mimail worm that spreads via e-mail. This version comes in a message that starts with “*** GLOBAL WARMING:”. (Sophos, Panda Software)
W32/Holar-J – This virus, which spreads via e-mail or MSN Messenger, attempts to delete a number of popular file types on the infected machine. (Sophos)
X-Scan.A – A set of hacking tools that are used to find vulnerabilities in a Windows machine and log keystrokes. (Panda Software)
Y2K – A joke virus that pretends to be searching for Y2K vulnerabilities and while doing so, flickers the screen and opens the CD tray. At the end of the “test” it reveals itself as a joke. (Panda Software)
**********
From the interesting reading department:
Can Apple Keep the Worms Out?
Mac owners have long boasted of their immunity to viruses. But with Unix-based OS X, it’s a whole new ball game. BusinessWeek Online, 02/05/04.
https://www.nwfusion.com/go2/0209bug1c.html
Check Point gear guards LANs
Check Point is introducing a LAN appliance that can protect networks against application-layer exploits such as Blaster and Slammer that sneak past perimeter firewalls. Network World Fusion, 02/05/04.




