Sun patches JRE

Opinion
Oct 27, 20034 mins

* Patches from Sun, Immunix, Conectiva, others * Beware e-mail worm spreading via messages filled with Cyrillic characters and attachment called "WIN2DRV.EXE" * 'Net security gets root-level boost, and other interesting reading

Today’s bug patches and security alerts:

Sun patches Java Runtime Environment flaw

A vulnerability in Sun’s Java Runtime Environment (JRE) could allow a malicious applet to bypass the “sandbox” restrictions and carry out any commands on the affected machine. A fix is available. For more, go to:

https://sunsolve.sun.com/pub-gi/retrieve.pl?doc=fsalert/57221

**********

Mandrake 9.2 damages some CD-ROMs

MandrakeSoft, the makers of the Mandrake Linux distribution, has warned users that the latest release, 9.2, could damage some LG-based CD-ROMs. Sydney Morning Herald, 10/27/03.

https://www.smh.com.au/articles/2003/10/27/1067213193986.html

Mandrake Linux advisory:

https://www.mandrakelinux.com/en/92errata.php3#badlg

**********

OpenPKG patches ircd

A buffer overflow in the IRC daemon for OpenPKG could be exploited to crash the server, resulting in a denial-of-service. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2003.045-ircd.html

**********

Immunix patches fetchmail

A number of minor vulnerabilities that could be exploited in denial-of-service attacks have been patched in Immunix’s implementation of fetchmail. Source code for the new packages can be found here:

https://www.nwfusion.com/go2/1027bug1a.html

**********

Conectiva patches sane

A number of bugs and potential security vulnerabilities were found in sane, a package used with document scanners. Most of these are pretty minor. For more, go to:

https://www.nwfusion.com/go2/1027bug1b.html

Conectiva issues patch for anonftp

A bug in the “ls” directory command used by the Conectiva anonftp server could be exploited in a denial-of-service attack against the affected machine. For more, go to:

https://www.nwfusion.com/go2/1027bug1c.html

**********

Today’s roundup of virus alerts:

W32/Sober-A – An e-mail virus that spreads using a variety of message subject lines and attachment names. The virus seems more like an annoyance than anything that causes permanent damage. (Sophos)

Lohack.C – A virus that activates when the infected message is displayed in Outlook’s preview pane. One attribute of the virus is that it moves the cursor around the screen of the infected machine. (Panda Software)

Flop.A – This virus spreads via floppy disks and displays a message in Spanish on the infected machine. (Panda Software)

Sexer.A – Another e-mail worm that spreads via a message filled with Cyrillic characters and with an attachment called “WIN2DRV.EXE”. The virus sends itself out to everyone in the Outlook address book and changes the Windows background to one filled with Cyrillic characters. (Panda Software)

Vix.A – This worm spreads via peer-to-peer files and infected PE files, rendering them useless. (Panda Software)

W32/Agobot-AC – Another variant of the Agobot family of worms. This one drops a backdoor program that accepts commands via IRC on the infected machine. (Sophos)

W32/Randex-Q – Like Agobot, this worm also drops a backdoor application that uses IRC to receive commands. Randex-Q spreads via poorly secured network shares. (Sophos)

VBS/Flea-A – Great name for a virus. This one spreads via an HTML-based e-mail signature that contains JavaScript. It adds the infected signature to every e-mail sent by the infected machine. (Sophos)

**********

From the interesting reading department:

‘Net security gets root-level boost

A year after surviving a massive distributed denial-of-service attack, the Internet’s root servers are better fortified against hacker activity, thanks to behind-the-scenes deployment of a routing technique known as Anycast, experts say. Network World, 10/27/03.

https://www.nwfusion.com/news/2003/1027ddos.html

U.S. Gov’t Plans Internet Security Ads

The Homeland Security Department and the technology industry plan to spend $1.8 million on the cybersecurity advertising campaign in cooperation with the Ad Council. Washington Post, 10/23/03.

https://www.nwfusion.com/go2/1027bug1d.html

Victoria’s Secret to pay up for poor panty privacy

New York Attorney General Eliot Sptizer has sorted through Victoria Secret’s dirty undies and is set to doll out a $50,000 fine to the company for online privacy violations. The Register, 10/21/03.

https://www.theregister.co.uk/content/6/33504.html

AOL turning off users’ Windows Messenger

ISP AOL is taking aggressive steps to combat spam and close a security loophole by turning off a Microsoft Windows feature that spammers are exploiting to display pop-up messages on users’ desktops, AOL said. IDG News Service, 10/24/03.

https://www.nwfusion.com/news/2003/1024aolturni.html