NETWORK WORLD NEWSLETTER: JASON MESERVE'S VIRUS AND BUG PATCH 
ALERT
11/22/04
Today's focus:  Flaws found in Linux SMB file system

Dear [EMAIL PROTECTED],

In this issue:

* Patches from FreeBSD, Conectiva, Gentoo, others
* Beware new Sober variant
* Google search cache spawns SSL fear, and other interesting 
��reading
* Links related to Virus and Bug Patch Alert
* Featured reader resource
_______________________________________________________________
This newsletter is sponsored by Intel 
IT Productivity; Increasing ROI 

Learn how to effectively measure employee productivity, manage 
IT investments and reduce the Total Cost of Ownership in 
enterprise data management.  Visit Intel's IT Productivity 
center.  Click here to download white papers, books and IDC 
Research. 
http://www.fattail.com/redir/redirect.asp?CID=88611
_______________________________________________________________
NW'S RESEARCH CENTER ON SPAM 

Go to NW's Research Center on spam and find our in-depth review 
of 16 anti-spam products, our spam calculator to determine how 
much spam is costing your enterprise each year, the latest spam 
news, advice on how to fight spam and more. For the latest on 
spam click here: 
http://www.fattail.com/redir/redirect.asp?CID=88679
_______________________________________________________________

Today's focus:  Flaws found in Linux SMB file system

By Jason Meserve

Editor's note: With the Thanksgiving holiday here, this is our 
only newsletter this week. For a reminder of things we should be 
thankful for, read Ellen Messmer's latest Security Notes entry: 
<http://www.nwfusion.com/weblogs/security/006818.html?nl> 

Happy Thanksgiving to all of our readers!

Today's bug patches and security alerts:

Flaws found in Linux SMB file system

A denial-of-service vulnerability has been found in the SMB file 
system that is part of many Linux operating system kernels. An 
attacker would need control of the SMB server to carry out the 
attack or be able to intercept data bound for the affected 
server. For more, go to: 
<http://security.e-matters.de/advisories/142004.html>  
**********

iDefense warns of flaws in Fcron

Four security flaws have been found in Fcron, a scheduling tool 
that replaces Vixie Cron. The flaws could be exploited to bypass 
configuration settings, delete files, create files with root 
permission, and kill processes on the affected machine. For 
more, go to: 
<http://www.nwfusion.com/go2/1122bug1a.html> 

Related Gentoo advisory: 
<http://security.gentoo.org/glsa/glsa-200411-27.xml>  
**********

DoS in 3Com OfficeConnect ADSL Wireless 11g Firewall Router

A flaw in the way UDP traffic is handled by the 3Com 
OfficeConnect ADSL Wireless 11g Firewall Router could be 
exploited in a denial-of-service attack against the device. For 
more, go to: 
<http://www.osvdb.org/11839>  
**********

FreeBSD releases patch for Fetch

A buffer overflow in the Fetch file transfer utility could be 
exploited to overwrite memory and run the attacker's code of 
choice. For more, go to: 
<http://www.nwfusion.com/go2/1122bug1b.html>  
**********

NGSSoftware warns of WinRAR vulnerability

An undisclosed flaw in WinRAR, a repair and archive tool, has 
been found by security experts at NGSSoftware. The company is 
not releasing details for three months. Users can upgrade to 
version 3.41 to fix the problem: 
<http://www.rarlabs.com/> 

NGSSoftware advisory: 
<http://www.nextgenss.com/advisories/winrar.txt>  
**********

Conectiva patches subversion

All versions of subversion, a file change tracking system, 
including 1.0.7 are vulnerable to leaking meta data. This 
information could be used for other malicious purposes. For 
more, go to: 
<http://www.nwfusion.com/go2/1122bug1c.html> 

Conectiva updates libtiff3

Several integer overflow vulnerabilities found in previous 
versions of libtiff3, an image viewer application, have been 
patched. For more, go to: 
<http://www.nwfusion.com/go2/1122bug1d.html> 

Conectiva releases fix for xpdf

A flaw in various implementations of a PDF viewer application 
could be exploited to crash the affected application or 
potentially run arbitrary code on the affected machine. For 
more, go to: 
<http://www.nwfusion.com/go2/1122bug1e.html>  
**********

Gentoo patches Portage, Gentoolkit

Both Portage and Gentoolkit for Gentoo Linux have security 
issues around the creation of temporary files. These files could 
make the system vulnerable to a symlink attack. For more, go to: 
<http://security.gentoo.org/glsa/glsa-200411-13.xml> 

Gentoo releases updates for OpenSSL, Groff

Similar to the announcement above, OpenSSL and Groff are both 
vulnerable to symlink attacks because of the way temporary files 
are created. For more, go to: 
<http://security.gentoo.org/glsa/glsa-200411-15.xml> 

Gentoo issues fix for zgv

A buffer overflow has been discovered in zgv, an image viewer 
application for Gentoo. An attacker could exploit this to run 
their code of choice on the affected machine. For more, go to: 
<http://security.gentoo.org/glsa/glsa-200411-12.xml> 

Updates available from Gentoo for Kaffeine, gxine

Buffer overflow vulnerabilities have been found in Kaffeine and 
gxine. They could be exploited via content access through a 
malicious Web server. For more, go to: 
<http://security.gentoo.org/glsa/glsa-200411-14.xml>  
**********

eEye reports vulnerability in Kerio Personal Firewall

According to an alert from eEye, "eEye Digital Security has 
discovered a severe denial-of-service vulnerability in the Kerio 
Personal Firewall product for Windows. The vulnerability allows 
a remote attacker to reliably render a system inoperative with 
one single packet." For more, go to: 
<http://www.eeye.com/html/research/advisories/AD20041109.html> 

Kerio advisory: 
<http://www.kerio.com/security_advisory.html>  
**********


Today's roundup of virus alerts:

New Sober variant spreading

A new version of the Sober e-mail worm started spreading in 
Europe on Friday, according to anti-virus vendors, which have 
given the worm a midlevel threat rating. IDG News Service, 
11/19/04. 
<http://www.nwfusion.com/news/2004/1119newsober.html?nl> 

W32/Rbot-PX - This bot can be used for many malicious purposes 
after it infects a machine through network shares. It installs 
"crss.exe" in the Windows System directory and allows backdoor 
access via IRC. (Sophos)

W32/Rbot-PY - This variant installs "MCAFFEFLD.EXE" in the 
Windows System folder and can log keystrokes to the file 
"SYSZZY32.TXT". (Sophos)

W32/Rbot-QE - An Rbot variant that exploits the Windows LSASS 
vulnerability as it spreads via network shares. It installs 
"XPUpdate.exe" in the Windows System directory and can be used 
to log keystrokes, launch denial-of-service attacks, steal CD 
keys and download/run code from the Internet. (Sophos)

W32/Agobot-NZ - An Agobot variant that installs "gmsvc32.exe" in 
the Windows System directory. It modifies the Windows HOSTS file 
to prevent access to specific anti-virus and security Web sites. 
(Sophos)

W32/Agobot-OC - This Agobot variant tries to hide itself in the 
file "halflife2.exe", taking advantage of Microsoft's latest 
game's popularity. It too modifies the HOSTS file to limit 
access to security-related Web sites. (Sophos)

W32/Primat-C - A virus that uses peer-to-peer networks to 
spread, infecting .exe, .scr and .pif files. On the 18th of the 
month, it displays an image on the infected machine's screen. 
(Sophos)

W32/Forbot-CP - A Forbot variant that infects "iexplore.exe" in 
the Windows System directory and provides backdoor access via 
IRC. The worm may act as a proxy, steal CD key data and delete 
network shares. (Sophos)

Skulls - A new virus that infects mobile devices running the 
Symbian operating system. It is spread through an infected SIS 
file called  "Extended Theme Manager" and offered by a user 
called "Tee-222". It will display a bunch of skulls on the 
infected device's screen. (F-Secure)

Troj/Narod-D - A backdoor virus that opens port 3128 and listens 
for commands. It installs the file "systemp.exe" in the Windows 
System directory along with two DLLs. (Sophos)

W32/Bofra-H - Another Bofra variant that spreads via e-mail. The 
infected attached file always ends in 32.exe. It allows backdoor 
access to the infected system via IRC. (Sophos) 
**********

>From the interesting reading department:

Google search cache spawns SSL fear

It's proving tougher than anticipated to protect SSL VPNs from 
the voracious caching machine housed inside Google Desktop 
Search. Network World, 11/22/04. 
<http://www.nwfusion.com/news/2004/112204google.html?nl> 

IP VPNs save, but they can carry 'gotchas'

While IP VPNs are widely accepted as an effective remote access 
and WAN technology that can save money, there are hidden 
challenges users should be aware of to avoid costly problems. 
Network World, 11/22/04. 
<http://www.nwfusion.com/news/2004/112204vpnhidden.html?nl> 

E-comm gains offset by escalating fraud

Just in time for the start of the holiday shopping season, two 
vendors released research last week detailing a rise in 
e-commerce fraud. CyberSource published the results of its sixth 
annual e-commerce fraud survey, while VeriSign came out with its 
fourth Internet Security Intelligence Briefing, which details 
Internet usage trends as well as threat, vulnerability and fraud 
patterns. Network World, 11/22/04. 
<http://www.nwfusion.com/news/2004/112204ecomm.html?nl> 

Vendors aim to tamp down spyware

Spyware protection debuts in both desktop and gateway products. 
Network World, 11/22/04. 
<http://www.nwfusion.com/news/2004/112204spy.html?nl> 

Oracle announces quarterly patching schedule

Oracle plans to begin issuing cumulative software patches for 
Oracle Database, E-Business Suite, Application Server, Oracle 
Enterprise Manager and Collaboration Suite on a quarterly basis 
beginning Jan. 18. Network World Fusion, 11/18/04. 
<http://www.nwfusion.com/news/2004/1118orpatch.html?nl> 

Sybari offers security for IM, SharePoint

Sybari Software Thursday added Antigen 8.0 for Microsoft 
SharePoint and Antigen 8.0 for Instant Messaging, two 
anti-virus, anti-spam, and content-filtering security software 
products for enterprise environments. InfoWorld, 11/19/04. 
<http://www.nwfusion.com/news/2004/1119sybaroffer.html?nl>
_______________________________________________________________
To contact: Jason Meserve

Jason Meserve is the Multimedia Editor of Network World Fusion 
and writes about streaming media, search engines and IP 
Multicast. Jason can be reached at <mailto:[EMAIL PROTECTED]>. 
Check out his Multimedia Exchange weblog at: 
<http://www.nwfusion.com/weblogs/multimedia/> 
_______________________________________________________________
This newsletter is sponsored by Intel 
IT Productivity; Increasing ROI 

Learn how to effectively measure employee productivity, manage 
IT investments and reduce the Total Cost of Ownership in 
enterprise data management.  Visit Intel's IT Productivity 
center.  Click here to download white papers, books and IDC 
Research. 
http://www.fattail.com/redir/redirect.asp?CID=88610
_______________________________________________________________
ARCHIVE LINKS

Virus and Bug Patch Alert archive:
http://www.nwfusion.com/newsletters/bug/index.html

Breaking security news, updated daily
http://www.nwfusion.com/topics/security.html
_______________________________________________________________
FEATURED READER RESOURCE
NW FUSION PARTNERS' SITES NOW AVAILABLE

Network World Fusion Partners is a collaborative effort between 
Network World and sponsoring Partner companies. Each microsite 
contains best-of-breed information as well as custom content not 
found anywhere else, including a custom email newsletter and 
special offers. It is current, top-of-mind information that is 
readily accessible and bundled into one comprehensive package. 
Visit the NWFusion Partner sites to learn about storage 
solutions, network access solutions, optical networking and 
more. Visit NWFusion Partners at:
<http://www.nwfusion.com/go/nwprr>
_______________________________________________________________
May We Send You a Free Print Subscription? 
You've got the technology snapshot of your choice delivered 
at your fingertips each day. Now, extend your knowledge by 
receiving 51 FREE issues to our print publication. Apply 
today at http://www.subscribenw.com/nl2

International subscribers click here: 
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail 
newsletters, go to: 
<http://www.nwwsubscribe.com/Changes.aspx> 

To unsubscribe from promotional e-mail go to: 
<http://www.nwwsubscribe.com/Preferences.aspx> 

To change your e-mail address, go to: 
<http://www.nwwsubscribe.com/ChangeMail.aspx> 

Subscription questions? Contact Customer Service by replying to 
this message.

This message was sent to: [EMAIL PROTECTED] 
Please use this address when modifying your subscription. 
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor, 
at: <mailto:[EMAIL PROTECTED]> 

Inquiries to: NL Customer Service, Network World, Inc., 118 
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of 
Online Development, at: <mailto:[EMAIL PROTECTED]> 

Copyright Network World, Inc., 2004

------------------------
This message was sent to:  [EMAIL PROTECTED]

Reply via email to