Summary of Security Items from September 28 through October 4, 2005
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded in the past week. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores.
Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
- High: vulnerabilities with a CVSS base score of 7.0–10.0
- Medium: vulnerabilities with a CVSS base score of 4.0–6.9
- Low: vulnerabilities with a CVSS base score of 0.0–3.9
Entries may include additional information provided by organizations and efforts sponsored by CISA. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletin is compiled from external, open-source reports and is not a direct result of CISA analysis.
Information in the US-CERT Cyber Security Bulletin is a compilation and includes information published by outside sources, therefore the information should not be considered the result of US-CERT analysis. Software vulnerabilities are categorized in the appropriate section reflecting the operating system on which the vulnerability was reported; however, this does not mean that the vulnerability only affects the operating system reported since this information is obtained from open-source information.
This bulletin provides a summary of new or updated vulnerabilities, exploits, trends, viruses, and trojans. Updates to vulnerabilities that appeared in previous bulletins are listed in bold text. The text in the Risk column appears in red for vulnerabilities ranking High. The risks levels applied to vulnerabilities in the Cyber Security Bulletin are based on how the "system" may be impacted. The Recent Exploit/Technique table contains a "Workaround or Patch Available" column that indicates whether a workaround or patch has been published for the vulnerability which the script exploits.
Vulnerabilities
The table below summarizes vulnerabilities that have been identified, even if they are not being exploited. Complete details about patches or workarounds are available from the source of the information or from the URL provided in the section. CVE numbers are listed where applicable. Vulnerabilities that affect both Windows and Unix Operating Systems are included in the Multiple Operating Systems section.
Note: All the information included in the following tables has been discussed in newsgroups and on web sites.
The Risk levels defined below are based on how the system may be impacted:
Note: Even though a vulnerability may allow several malicious acts to be performed, only the highest level risk will be defined in the Risk column.
- High - A high-risk vulnerability is defined as one that will allow an intruder to immediately gain privileged access (e.g., sysadmin or root) to the system or allow an intruder to execute code or alter arbitrary system files. An example of a high-risk vulnerability is one that allows an unauthorized user to send a sequence of instructions to a machine and the machine responds with a command prompt with administrator privileges.
- Medium - A medium-risk vulnerability is defined as one that will allow an intruder immediate access to a system with less than privileged access. Such vulnerability will allow the intruder the opportunity to continue the attempt to gain privileged access. An example of medium-risk vulnerability is a server configuration error that allows an intruder to capture the password file.
- Low - A low-risk vulnerability is defined as one that will provide information to an intruder that could lead to further compromise attempts or a Denial of Service (DoS) attack. It should be noted that while the DoS attack is deemed low from a threat potential, the frequency of this type of attack is very high. DoS attacks against mission-critical nodes are not included in this rating and any attack of this nature should instead be considered to be a "High" threat.
Windows Operating Systems Only | ||||
Vendor & Software Name | Vulnerability - Impact Patches - Workarounds Attacks Scripts | Common Name / CVE Reference | Risk | Source |
ALZip 5.52, 6.0, Korean 6.1 | Multiple buffer overflow vulnerabilities have been reported in ALZip that could let remote malicious users execute arbitrary code. Upgrade to version 6.13: Currently we are not aware of any exploits for this vulnerability. | ALZip Arbitrary Code Execution | High | Security Focus, ID 15010, October 5, 2005 |
BitDefender AntiVirus 7.2, 8, 9 | A vulnerability has been reported in BitDefender AntiVirus that could let remote malicious users execute arbitrary code or obtain elevated privileges. Upgrade to newest version via online upgrade tool. Currently we are not aware of any exploits for this vulnerability. | BitDefender Anti-Virus Arbitrary Code Execution or Privilege Elevation | High | Secunia, Advisory: SA16991, October 4, 2005 |
MetaFrame Presentation Server 3.0, 4.0 | A vulnerability has been reported in Citrix MetaFrame Presentation Server that could let remote malicious users to bypass security restrictions. Vendor workaround: There is no exploit code required. | Citrix MetaFrame Security Restriction Bypassing | Medium | SecurityTracker Alert ID: 1014994, September 30, 2005 |
Icewarp Web Mail 5.5.1 | Multiple vulnerabilities have been reported in IceWarp Web Mail that could let remote malicious users conduct cross site scripting or traverse directories. No workaround or patch available at time of publishing. There is no exploit code required; however, a Proof of Concept exploit script has been published. | IceWarp Web Mail Cross Site Scripting or Directory Traversal | Medium | SecurityFocus, ID 14980, 14986, September 20, 2005 |
Breeze 5.0 | A vulnerability has been reported in the 'reset password' feature because passwords are stored in plaintext when the password is reset, which could let a malicious user obtain sensitive information. Updates available at: There is no exploit code required. | Macromedia Breeze Information Disclosure | Medium | Macromedia Security Bulletin MPSB 05-06, September 29, 2005 |
MailEnable Enterprise 1.1, Professional 1.6
| A buffer overflow vulnerability has been reported in MailEnable that could let remote malicious users execute arbitrary code. Vendor hotfix available: Currently we are not aware of any exploits for this vulnerability. | MailEnable Arbitrary Code Execution | High | Secunia Advisory: SA17010, October 4, 2005 |
Merak Mail Server 8.2.4r | An input validation vulnerability has been reported in Merak Mail Server that could let remote malicious users access (delete) arbitrary files. No workaround or patch available at time of publishing. There is no exploit code required; however, a Proof of Concept exploit script has been published. | Merak Mail Server Arbitrary File Access | Medium | SecurityFocus, ID 14988, September 30, 2005 |
msjet40.dll library version 4.00.8618.0 | A vulnerability was reported that could let a remote malicious user cause arbitrary code to be executed. This is because the 'msjet40.dll' component does not properly validate user-supplied input when parsing database files. No workaround or patch available at time of publishing. A Proof of Concept exploit has been published. | Microsoft Jet Database Remote Code Execution Vulnerability href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0944">CAN-2005-0944 | High | Hexview Advisory, |
Update Rollup 1 for Windows 2000 SP4 | Multiple vulnerabilities have been reported in various Microsoft products that could let malicious users perform a variety of functions. Apply Update Rollup: | Microsoft Update Rollup 1 for Windows 2000 SP4 CAN-2005-3168 | Medium | Microsoft Knowledge Base, ID 891861, September 28, 2005 |
Multiple vulnerabilities have been reported in NateOn Messenger that could let remote malicious users cause a denial of service or execute arbitrary code. No workaround or patch available at time of publishing. A Proof of Concept exploit script has been published. | NateOn Messenger Arbitrary Code Execution or Denial of Service | High | Secunia, Advisory: SA16983, October 4, 2005 | |
SecureW2 3.0, 3.1.1 | A vulnerability has been reported in SecureW2 that could let remote malicious users to disclose sensitive information. Upgrade to version 3.1.2: Currently we are not aware of any exploits for this vulnerability. | SecureW2 Information Disclosure | Medium | Secunia, Advisory: SA16909, September 26, 2005 SecurityFocus, ID 14947, October 3, 2005 |
Symantec AntiVirus Scan Engine 4.0, 4.3 | A buffer overflow vulnerability has been reported in Symantec AntiVirus that could let remote malicious users execute arbitrary code. Vendor upgrade available: Currently we are not aware of any exploits for this vulnerability. | Symantec Anti Virus Arbitrary Code Execution | High | Symantec Security Response, SYM05-017, October 4, 2005 |
Web Player prior to 3.0.0.100 | Multiple buffer overflow/ directory traversal vulnerabilities have been reported in Web Player that could let a remote malicious user execute arbitrary code or obtain arbitrary file control. Upgrade to version 3.0.0.101: A Proof of Concept exploit script has been published. | Virtools Web Player Arbitrary Code Execution or Arbitrary File Control | High | Secunia, Advisory: SA17034, October 3, 2005 |
UNIX / Linux Operating Systems Only | ||||
Vendor & Software Name | Vulnerability - Impact Patches - Workarounds Attacks Scripts | Common Name / CVE Reference | Risk | Source |
WebSTAR 5.3-5.3.4, 5.2-5.2.4, 5.1.3, 5.1.2 | A remote Denial of Service vulnerability has been report due to a failure to handle exceptional conditions. Upgrades available at: There is no exploit code required. | 4D WebStar Remote IMAP Denial of Service | Low | Security Focus, Bugtraq ID: 14981, September 30, 2005 |
Apache 2.0.x | A vulnerability has been reported in 'modules/ssl Patch available at: OpenPKG: RedHat: Ubuntu: SGI: Debian: Mandriva: Slackware: Trustix: Debian: Gentoo: Avaya: Conectiva: TurboLinux: There is no exploit code required. | Apache 'Mod_SSL SSLVerifyClient' Restriction Bypass | Medium | Security Tracker Alert ID: 1014833, September 1, 2005 OpenPKG Security Advisory, OpenPKG-SA-2005.017, September 3, 2005 RedHat Security Advisory, RHSA-2005:608-7, September 6, 2005 Ubuntu Security Notice, USN-177-1, September 07, 2005 SGI Security Advisory, 20050901-01-U, September 7, 2005 Debian Security Advisory, DSA 805-1, September 8, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:161, September 8, 2005 Slackware Security Advisory, SSA:2005-251-02, September 9, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0047, September 9, 2005 Debian Security Advisory DSA 807-1, September 12, 2005 Gentoo Linux Security Advisory, GLSA 200509-12, September 19, 2005 Avaya Security Advisory, ASA-2005-204, September 23, 2005 Conectiva Linux Announcement, CLSA-2005:1013, September 27, 2005 Turbolinux Security Advisory, TLSA-2005-94, October 3, 2005 |
ApacheTop 0.12.5 | A vulnerability has been reported due to the insecure creation of temporary files, which could let a malicious user overwrite sensitive data. Debian: There is no exploit code required. | ApacheTop Insecure Temporary File Creation | Medium | Security Focus, Bugtraq ID: 14982, September 30, 2005 Debian Security Advisory, DSA 839-1, October 4, 2005 |
ClamAV 0.80 -0.86.2, 0.70, 0.65-0.68, 0.60, 0.51-0.54 | Several vulnerabilities have been reported: a buffer overflow vulnerability was reported in 'libclamav/upx.c' due to a signedness error, which could let a malicious user execute arbitrary code; and a remote Denial of Service vulnerability was reported in 'libclamav/fsg.c' when handling a specially -crafted FSG-compressed executable file.
Upgrades available at: Gentoo: Mandriva: Trustix:
href="http://http.trustix.org/pub/trustix/updates/"> Debian: Conectiva: Currently we are not aware of any exploits for these vulnerabilities. | ClamAV UPX Buffer Overflow & FSG Handling Denial of Service | High | Secunia Advisory: SA16848, September 19, 2005 Gentoo Linux Security Advisory, GLSA 200509-13, September 19, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:166, September 20, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0051, September 23, 2005 Debian Security Advisory DSA 824-1, September 29, 2005 Conectiva Linux Announcement, CLSA-2005:1020, October 3, 2005 |
backupninja 0.5.2 | A vulnerability has been reported in the 'backupninja' script due to the insecure creation of temporary files, which could let a malicious user obtain elevated privileges. Upgrade available at: There is no exploit code required. | BackupNinja Insecure Temporary File Creation | Medium | Debian Security Advisory, DSA 827-1, September 29, 2005 |
cpio 1.0-1.3, 2.4.2, 2.5, 2.5.90, 2.6 | A vulnerability has been reported when an archive is extracted into a world or group writeable directory because non-atomic procedures are used, which could let a malicious user modify file permissions. Trustix: Mandriva: RedHat: SGI: SCO: Avaya: Conectiva: Ubuntu: There is no exploit code required. | Medium | Bugtraq, 395703, Trustix Secure Linux Security Advisory, TSLSA-2005-0030, June 24, 2005 Mandriva RedHat Security Advisory, RHSA-2005:378-17, July 21, 2005 SGI Security Advisory, 20050802-01-U, August 15, 2005 SCO Security Advisory, SCOSA-2005.32, August 18, 2005 Avaya Security Advisory, ASA-2005-191, September 6, 2005 Conectiva Linux Announcement, CLSA-2005:1002, September 13, 2005 Ubuntu Security Notice, USN-189-1, September 29, 2005 | |
cpio 2.6 | A Directory Traversal vulnerability has been reported when invoking cpio on a malicious archive, which could let a remote malicious user obtain sensitive information. Gentoo: Trustix: Mandriva: SCO: Avaya: Conectiva: Ubuntu: A Proof of Concept exploit has been published. | Medium | Bugtraq, Gentoo Linux Security Advisory, GLSA Trustix Secure Mandriva Linux Security Update Advisory, MDKSA2005: SCO Security Advisory, SCOSA-2005.32, August 18, 2005 Avaya Security Advisory, ASA-2005-191, September 6, 2005 Conectiva Linux Announcement, CLSA-2005:1002, September 13, 2005 Ubuntu Security Notice, USN-189-1, September 29, 2005 | |
Mailutils 0.6 | A format string vulnerability has been reported in 'search.c' when processing user-supplied IMAP SEARCH commands, which could let a remote malicious user execute arbitrary code. Patch available at: Gentoo: Debian: An exploit script has been published. | GNU Mailutils Format String | High | Security Tracker Alert ID: 1014879, September 9, 2005 Gentoo Linux Security Advisory, GLSA 200509-10, September 17, 2005 Security Focus, Bugtraq ID: 14794, September 26, 2005 Debian Security Advisory, DSA 841-1, October 4, 2005 |
GtkDiskFree 1.9.3 | A vulnerability has been reported in the 'src/mount.c' file due to the insecure creation of temporary files, which could let a malicious user cause a Denial of Service or overwrite files. Debian: Gentoo: There is no exploit code required. | GTKDiskFree Insecure Temporary File Creation | Medium | ZATAZ Audits Advisory, September 15, 2005 Debian Security Advisory, DSA 822-1, September 29, 2005 Gentoo Linux Security Advisory, GLSA 200510-01, October 3, 2005 |
Hylafax 4.2.1 | Several vulnerabilities have been reported: a vulnerability was reported in the 'xferfaxstats' script due to the insecure creation of temporary files, which could let a remote malicious user create/overwrite arbitrary files; and a vulnerability was reported because ownership of the UNIX domain socket is not created or verified, which could let a malicious user obtain sensitive information and cause a Denial of Service. Gentoo: There is no exploit code required. | HylaFAX Insecure Temporary File Creation | Medium | Security Focus, Bugtraq ID: 14907, September 22, 2005 Gentoo Linux Security Advisory, GLSA 200509-21, September 30, 2005 |
AIX 5.3 L, 5.3, 5.2.2, 5.2 L, 5.2 | A buffer overflow vulnerability has been reported due to a failure to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers, which could let a malicious user execute arbitrary code. Update information available at: http://www-1.ibm.com/ Currently we are not aware of any exploits for this vulnerability. | High | IBM Security Advisory, September 28, 2005 | |
UnZip 5.52 | A vulnerability has been reported due to a security weakness when extracting an archive to a world or group writeable directory, which could let a malicious user modify file permissions. Fedora: SCO: Ubuntu: Trustix: There is no exploit code required. | Info-ZIP UnZip File Permission Modification | Medium | Security Focus, 14450, August 2, 2005 Fedora Update Notification, SCO Security Advisory, SCOSA-2005.39, September 28, 2005 Ubuntu Security Notice, USN-191-1, September 29, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0053, September 30, 2005 |
Bugzilla 2.18-2.21 | Several vulnerabilities have been reported: a vulnerability was reported in the 'config.cgi' script because unauthorized access can be obtained even when the 'requirelogin' parameter is enabled, which could let a malicious user obtain sensitive information; and a vulnerability was reported in the user matching feature when the 'usevisibilitygroups' setting is enabled, which could let a remote malicious user obtain sensitive information. Upgrades available at: There is no exploit code required. | Bugzilla Information Disclosure | Medium | Bugzilla Security Advisory, September 30, 2005 |
MPlayer 1.0 pre7, .0 pre6-r4, 1.0 pre6-3.3.5-20050130 | A buffer overflow vulnerability has been reported due to insufficient validation of user-supplied strings, which could let a remote malicious user execute arbitrary code. Gentoo: Mandriva:
href="http://www.mandriva.com/security/advisories">http://www.mandriva.com/ Conectiva: Currently we are not aware of any exploits for this vulnerability. | MPlayer Audio Header Buffer Overflow | High | Security Tracker Alert ID: 1014779, August 24, 2005 Gentoo Linux Security Advisory, GLSA 200509-01, September 1, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:158, September 7, 2005 Conectiva Linux Announcement, CLSA-2005:1018, September 28, 2005 |
Linux kernel 2.6-2.6.10, 2.4-2.4.28 | A buffer overflow vulnerability has been reported in the 'coda_pioctl' function of the 'pioctl.c' file, which could let a malicious user cause a Denial of Service or execute arbitrary code with superuser privileges.
RedHat: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel Coda_Pioctl Local Buffer Overflow | High | Security Focus, Bugtraq ID: 14967, September 28, 2005 RedHat Security Advisory, RHSA-2005:663-19, September 28, 2005 |
DIA 0.91-0.94; | A vulnerability has been reported in 'plug-ins/python/diasvg_import.py' due to the insecure use of the 'eval()' function when handling a malicious Scalable Vector Graphics (SVG) file, which could let a remote malicious user execute arbitrary python code. Ubuntu: A Proof of Concept exploit has been published. | DIA Remote Arbitrary Code Execution | High | Security Focus, Bugtraq ID: 15000, October 3, 2005 Ubuntu Security Notice, USN-193-1, October 04, 2005 |
Cfengine 2.1.9, 2.1.8, 2.1.7 p1, 2.1 .0a9, 2.1.0a8, 2.1.0a6, 2.0.1-2.0.7 p1-p3, 2.0 .8p1, 2.0 .8, 2.0 .0, 1.6 a11, 1.6 a10, 1.5.3 -4, | Several vulnerabilities have been reported: a vulnerability was reported in '/bin/cfmailfilter' and '/contrib/cfcron.in' due to the insecure creation of temporary files, which could let a remote malicious user create/overwrite arbitrary files; and a vulnerability was reported in 'contrib/vicf.in/ due to the insecure creation of temporary files, which could let a remote malicious user create/overwrite arbitrary files. Debian: There is no exploit code required. | Cfengine Insecure Temporary Files | Medium | Debian Security Advisories, DSA 835-1 & 836-1, October 1, 2005 |
RedHat Enterprise Linux WS 3, ES 3, AS 3, Desktop 3.0; | A Denial of Service vulnerability has been reported in the 'find_target' function due to a failure to properly handle unexpected conditions when attempting to handle a NULL return value from another function. Upgrades available at: RedHat: There is no exploit code required. | Linux Kernel Find_Target Local Denial of Service | Low | Security Focus, Bugtraq ID: 14965, September 28, 2005 RedHat Security Advisory, RHSA-2005:663-19, September 28, 2005 |
RedHat Fedora Core3; | A remote Denial of Service vulnerability has been reported in the 'bgp_update_print()' function in 'print-bgp.c' when a malicious user submits specially crafted BGP protocol data. Update available at: Fedora: Trustix:
href="ftp://ftp.trustix.org/pub/trustix/updates/"> Mandriva: Fedora: Ubuntu: TurboLinux: Slackware: IPCop: IBM: A Proof of Concept exploit script has been published. | TCPDump BGP Decoding Routines Denial of Service | Low | Security Tracker Alert, 1014133, June 8, 2005 Fedora Update Notification, Trustix Secure Linux Security Advisory, TLSA-2005-0028, June 13, 2005 Mandriva Linux Security Update Advisory, Fedora Update Notification, Ubuntu Security Notice, Turbolinux Slackware Security Security Focus, Bugtraq ID: 13906, August 26, 2005 Security Focus, Bugtraq ID: 13906, October 3, 2005 |
RedHat Fedora Core4, Core3, Enterprise Linux WS 4, ES 4, AS 4, Desktop 4.0; | A format string vulnerability has been reported when displaying an invalid-handle error message, which could let a remote malicious user execute arbitrary code. RedHat: Fedora: Debian: An exploit script has been published. | RealNetworks RealPlayer & Helix Player Format String | High | RedHat Security Advisory, RHSA-2005:788-3, September 27, 2005 Fedora Update Notifications, Debian Security Advisory DSA 826-1, September 29, 2005 |
Squid Web Proxy Cache 2.5 .STABLE3-STABLE10, STABLE1 | A remote Denial of Service vulnerability has been reported when handling certain client NTLM authentication request sequences. Upgrades available at: Debian: Currently we are not aware of any exploits for this vulnerability. | Squid NTLM Authentication Remote Denial of Service | Low | Secunia Advisory: SA16992, September 30, 2005 Debian Security Advisory, DSA 828-1, September 30, 2005 |
SuSE Linux Professional | A buffer overflow vulnerability has been reported in the XFRM network architecture code due to insufficient validation of user-supplied input, which could let a malicious user execute arbitrary code. Patches available at: Ubuntu: SUSE: RedHat: Mandriva: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel XFRM Array Index Buffer Overflow | High | Security Focus, 14477, August 5, 2005 Ubuntu Security Notice, USN-169-1, August 19, 2005 SUSE Security Announcement, SUSE-SA:2005:050, September 1, 2005 RedHat Security Advisory, RHSA-2005:663-19, September 28, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
Trustix Secure Linux 3.0, 2.2, Secure Enterprise Linux 2.0, SuSE Novell Linux Desktop 9.0, Linux Professional 9.3 x86_64, 9.3, 9.2 x86_64, 9.2, 9.1 x86_64, 9.1, Linux Personal 9.3 x86_64, 9.3, 9.2 x86_64, 9.2, 9.1 x86_64, 9.1, Linux Enterprise Server for S/390 9.0, Linux Enterprise Server 9; 2.6-2.6.12 .4 | A Denial of Service vulnerability has been reported due to a failure to handle malformed compressed files. Upgrades available at: Ubuntu: SUSE: Trustix:
href="http://http.trustix.org/pub/trustix/updates/"> Mandriva: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel ZLib Null Pointer Dereference Denial of Service | Low | SUSE Security Announcement, SUSE-SA:2005:050, September 1, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0043, September 2, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
zlib 1.2.2, 1.2.1, 1.2 .0.7, 1.1-1.1.4, 1.0-1.0.9; Ubuntu Linux 5.0 4, powerpc, i386, amd64, 4.1 ppc, ia64, ia32; SuSE Open-Enterprise-Server 9.0, Novell Linux Desktop 9.0, Linux Professional 9.3, x86_64, 9.2, x86_64, 9.1, x86_64, Linux Personal 9.3, x86_64, 9.2, x86_64, 9.1, x86_64, Linux Enterprise Server 9; Gentoo Linux; | A buffer overflow vulnerability has been reported due to insufficient validation of input data prior to utilizing it in a memory copy operation, which could let a remote malicious user execute arbitrary code. Debian: FreeBSD: Gentoo: SUSE: Ubuntu: Mandriva: OpenBSD: OpenPKG: RedHat: Trustix: Slackware: TurboLinux: Fedora: zsync: Apple: SCO: IPCop: Debian: Trolltech: FedoraLegacy: Gentoo: Gentoo: Debian: Currently we are not aware of any exploits for this vulnerability. | Zlib Compression Library Buffer Overflow | High | Debian Security Advisory FreeBSD Security Advisory, Gentoo Linux Security Advisory, GLSA 200507- SUSE Security Announcement, SUSE-SA:2005:039, Ubuntu Security Notice, RedHat Security Advisory, RHSA-2005:569-03, Fedora Update Notifications, Mandriva Linux Security Update Advisory, OpenPKG Trustix Secure Slackware Security Turbolinux Security Fedora Update Notification, FEDORA-2005-565, July 13, 2005 SUSE Security Summary Security Focus, 14162, July 21, 2005 USCERT Vulnerability Note VU#680620, July 22, 2005 Apple Security Update 2005-007, SCO Security Advisory, SCOSA-2005.33, August 19, 2005 Security Focus, Bugtraq ID: 14162, August 26, 2005 Debian Security Advisory, DSA 797-1, September 1, 2005 Security Focus, Bugtraq ID: 14162, September 12, 2005 Fedora Legacy Update Advisory, FLSA:162680, September 14, 2005 Gentoo Linux Security Advisory, GLSA 200509-18, September 26, 2005 Gentoo Linux Security Advisory GLSA 200509-18, September 26, 2005 Debian Security Advisory, DSA 797-2, September 29, 2005 |
zlib 1.2.2, 1.2.1; Ubuntu Linux 5.04 powerpc, i386, amd64, | A remote Denial of Service vulnerability has been reported due to a failure of the library to properly handle unexpected compression routine input. Zlib: Debian: Ubuntu: OpenBSD: Mandriva: Fedora: Slackware: FreeBSD: SUSE: Gentoo: http://security.gentoo.org/ Trustix: Conectiva: Apple: TurboLinux: SCO: Debian: Trolltech: FedoraLegacy: Debian: Currently we are not aware of any exploits for this vulnerability. | Multiple Vendor Zlib Compression Library Decompression Remote Denial of Service | Low | Security Focus, Bugtraq ID 14340, July 21, 2005 Debian Security Advisory DSA 763-1, July 21, 2005 Ubuntu Security Notice, USN-151-1, July 21, 2005 OpenBSD, Release Errata 3.7, July 21, 2005 Mandriva Security Advisory, MDKSA-2005:124, July 22, 2005 Secunia, Advisory: SA16195, July 25, 2005 Slackware Security Advisory, SSA:2005- FreeBSD Security Advisory, SA-05:18, July 27, 2005 SUSE Security Announce- Gentoo Linux Security Advisory, GLSA 200507-28, July 30, 2005 Gentoo Linux Security Advisory, GLSA 200508-01, August 1, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0040, August 5, 2005 Conectiva Linux Announcement, CLSA-2005:997, August 11, 2005 Apple Security Update, APPLE-SA-2005-08-15, August 15, 2005 Turbolinux Security Advisory , TLSA-2005-83, August 18, 2005 SCO Security Advisory, SCOSA-2005.33, August 19, 2005 Debian Security Advisory, DSA 797-1, September 1, 2005 Security Focus, Bugtraq ID: 14340, September 12, 2005 Fedora Legacy Update Advisory, FLSA:162680, September 14, 2005 Debian Security Advisory, DSA 797-2, September 29, 2005 |
Gentoo Linux; | A vulnerability has been reported in MPEG tools due to the insecure creation of temporary files, which could let a malicious user overwrite sensitive data. Gentoo: There is no exploit code required. | Berkeley MPEG Tools Insecure Temporary File Creation | Medium | Gentoo Linux Security Advisory, GLSA 200510-02, October 3, 2005 |
GNOME vte, ibzvt2 1.4.2; | A vulnerability has been reported in 'grone-pty-helper' due to insufficient validation of the 'DISPLAY' environment variable before recorded as the user's logon hostname, which could let a malicious user spoof the hostname information in UTMP. No workaround or patch available at time of publishing. A Proof of Concept exploit script has been published. | Gnome-PTY-Helper UTMP Hostname Spoofing | Medium | Security Focus, Bugtraq ID: 15004, October 3, 2005 |
Linux kernel 2.6.8, 2.6.10 | A vulnerability has been reported in the EXT2/EXT3 file systems, which could let a remote malicious user bypass access controls.
Ubuntu: Mandriva: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel EXT2/EXT3 File Access Bypass | Medium | Security Focus, Bugtraq ID: 14792, September 9, 2005 Ubuntu Security Notice, USN-178-1, September 09, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
Linux kernel 2.6.8, 2.6.10 | A remote Denial of Service vulnerability has been reported in the 'ipt_recent' module when specially crafted packets are sent. Ubuntu: Mandriva: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel 'Ipt_recent' Remote Denial of Service | Low | Security Focus, Bugtraq ID: 14791, September 9, 2005 Ubuntu Security Notice, USN-178-1, September 09, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
Linux kernel 2.6.8-2.6.10, 2.4.21 | Several vulnerabilities have been reported: a buffer overflow vulnerability was reported in 'msg_control' when copying 32 bit contents, which could let a malicious user obtain root privileges and execute arbitrary code; and a vulnerability was reported in the 'raw_sendmsg()' function, which could let a malicious user obtain sensitive information or cause a Denial of Service. Ubuntu: Trustix: Fedora: RedHat: Mandriva: Currently we are not aware of any exploits for these vulnerabilities. | Linux Kernel Buffer Overflow, Information Disclosure, & Denial of Service | High | Secunia Advisory: SA16747, September 9, 2005 Ubuntu Security Notice, USN-178-1, September 09, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0049, September 16, 2005 Fedora Update Notifications, RedHat Security Advisory, RHSA-2005:663-19, September 28, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
RedHat Enterprise Linux WS 3, ES 3, AS 3, Desktop 3.0; OpenSSH 3.0-3.7.1, 2.9.9, 2.9 p1 & p2, 2.9, 2.5-2.5.2, 2.3 | A remote Denial of Service vulnerability has been reported in the 'LoginGraceTime' server configuration device due to a design error when servicing timeouts. Upgrades available at: There is no exploit code required. | OpenSSH LoginGraceTime Remote Denial of Service | Low | Security Focus, Bugtraq ID: 14963, September 28, 2005 RedHat Security Advisory, RHSA-2005:550-6, September 28, 2005 |
Ubuntu Linux 5.0 4 powerpc, i386, amd64, 4.1 ppc, ia64, ia32; | A Denial of Service vulnerability has been reported due to a failure to handle exceptional conditions. Upgrades available at: Ubuntu: SUSE: Trustix:
href="http://http.trustix.org/pub/trustix/updates/"> Mandriva: Currently we are not aware of any exploits for this vulnerability. | Linux Kernel ZLib Invalid Memory Access Denial of Service | Low | SUSE Security Announcement, SUSE-SA:2005:050, September 1, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0043, September 2, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:171, October 3, 2005 |
util-linux 2.8-2.13; | A vulnerability has been reported because mounted filesystem options are improperly cleared due to a design flaw, which could let a remote malicious user obtain elevated privileges. Updates available at: Slackware: Trustix: Ubuntu: Gentoo: Mandriva: Debian: SUSE: There is no exploit code required. | Util-Linux UMount Remounting Filesystem Elevated Privileges | Medium | Security Focus, Bugtraq ID: 14816, September 12, 2005 Slackware Security Advisory, SSA:2005-255-02, September 13, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0049, September 16, 2005 Ubuntu Security Notice, USN-184-1, September 19, 2005 Gentoo Linux Security Advisory, GLSA 200509-15, September 20, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:167, September 20, 2005 Debian Security Advisory, DSA 823-1, September 29, 2005 SUSE Security Summary Report, SUSE-SR:2005:021, September 30, 2005 |
XFree86 X11R6 4.3 .0, | A buffer overflow vulnerability has been reported in the pixmap processing code, which could let a malicious user execute arbitrary code and possibly obtain superuser privileges. Gentoo: RedHat: http://rhn.redhat.com/ Ubuntu: Mandriva: Fedora: Trustix: Debian: Sun: SUSE: Slackware: Sun: Currently we are not aware of any exploits for this vulnerability. | XFree86 Pixmap Allocation Buffer Overflow | High | Gentoo Linux Security Advisory, GLSA 200509-07, September 12, 2005 RedHat Security Advisory, RHSA-2005:329-12 & RHSA-2005:396-9, September 12 & 13, 2005 Ubuntu Security Notice, USN-182-1, September 12, 2005 Mandriva Security Advisory, MDKSA-2005:164, September 13, 2005 Fedora Update Notifications, Trustix Secure Linux Security Advisory, TSLSA-2005-0049, September 16, 2005 Debian Security Advisory DSA 816-1, September 19, 2005 Sun(sm) Alert Notification SUSE Security Announcement, SUSE-SA:2005:056, September 26, 2005 Slackware Security Advisory, SSA:2005-269-02, September 26, 2005 Sun(sm) Alert Notification |
Net-SNMP 5.2.1, 5.2, 5.1-5.1.2, 5.0.3 -5.0.9, 5.0.1 | A remote Denial of Service vulnerability has been reported when handling stream-based protocols. Upgrades available at: Trustix:
href="http://http.trustix.org/pub/trustix/updates/"> Fedora: RedHat: Mandriva: Ubuntu: Currently we are not aware of any exploits for this vulnerability. | Net-SNMP | Low | Secunia Trustix Secure Fedora Update Notifications, RedHat Security Advisory, RHSA-2005:720-04, August 9, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:137, August 11, 2005 Ubuntu Security Notice, USN-190-1, September 29, 2005 |
NTLM Authorization Proxy Server 0.9.9 | A vulnerability has been reported in Authorization Proxy Server (ntlmaps) due to insecure permissions on the configuration file, which could let a malicious user obtain sensitive information.
Debian: There is no exploit code required. | NTLM Authorization Proxy Server Insecure Configuration File Permissions | Medium | Debian Security Advisory, DSA 830-1, September 30, 2005 |
PCRE 6.1, 6.0, 5.0 | A vulnerability has been reported in 'pcre_compile.c' due to an integer overflow, which could let a remote/local malicious user potentially execute arbitrary code. Updates available at: Ubuntu: Ubuntu: Fedora: Gentoo: Mandriva: SUSE: Slackware: Ubuntu: Debian: SUSE: Gentoo: Conectiva: Gentoo: Debian: Gentoo: Debian: Conectiva: TurboLinux: Currently we are not aware of any exploits for this vulnerability. | PCRE Regular Expression Heap Overflow | High | Secunia Advisory: SA16502, August 22, 2005 Ubuntu Security Notice, USN-173-1, August 23, 2005 Ubuntu Security Notices, USN-173-1 & 173-2, August 24, 2005 Fedora Update Notifications, Gentoo Linux Security Advisory, GLSA 200508-17, August 25, 2005 Mandriva Linux Security Update Advisories, MDKSA-2005:151-155, August 25, 26, & 29, 2005 SUSE Security Announcements, SUSE-SA:2005:048 & 049, August 30, 2005 Slackware Security Advisories, SSA:2005-242-01 & 242-02 , August 31, 2005 Ubuntu Security Notices, USN-173-3, 173-4 August 30 & 31, 2005 Debian Security Advisory, DSA 800-1, September 2, 2005 SUSE Security Announcement, SUSE-SA:2005:051, September 5, 2005 Slackware Security Advisory, SSA:2005-251-04, September 9, 2005 Gentoo Linux Security Advisory, GLSA 200509-08, September 12, 2005 Conectiva Linux Announce-ment, CLSA-2005:1009, September 13, 2005 Gentoo Linux Security Advisory, GLSA 200509-12, September 19, 2005 Debian Security Advisory, DSA 817-1 & DSA 819-1, September 22 & 23, 2005 Gentoo Linux Security Advisory, GLSA 200509-19, September 27, 2005 Debian Security Advisory, DSA 821-1, September 28, 2005 Conectiva Linux Announcement, CLSA-2005:1013, September 27, 2005 Turbolinux Security Advisory, TLSA-2005-92, October 3, 2005 |
ProFTPd | Multiple format string vulnerabilities have been reported in ProFTPd that could let remote malicious users cause a Denial of Service or disclose information. Upgrade to version 1.3.0rc2: Gentoo: Trustix: TurboLinux: Mandriva: Debian: OpenPKG: Conectiva: Currently we are not aware of any exploits for these vulnerabilities. | ProFTPD Denial of Service or Information Disclosure | Medium | Secunia, Advisory: SA16181, July 26, 2005 Gentoo Linux Security Advisory, GLSA 200508-02, August 1, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0040, August 5, 2005 Turbolinux Security Advisory, TLSA-2005-82, August 9, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:140, August 16, 2005 Debian Security Advisories, DSA 795-1 & 795-2, September 1, 2005 OpenPKG Security Advisory, OpenPKG-SA-2005.020, September 6, 2005 Conectiva Linux Announcement, CLSA-2005:1015, September 28, 2005 |
ProZilla Download Accelerator 1.3.0-1.3.7 .4, 1.0 x, 1.3.7.3 | A buffer overflow vulnerability has been reported in 'ftpsearch.c' due to a boundary error when handling ftp search results in the 'get_string_ahref()' function, which could let a remote malicious user execute arbitrary code. Debian: An exploit script has been published. | High | Debian Security Advisory, DSA 834-1, October 1, 2005 | |
sblim-sfcb 0.9.1, 0.9 | A remote Denial of Service vulnerability has been reported due to a failure to handle malformed headers. Upgrades available at: There is no exploit code required. | SBLim-SFCB Malformed Header Denial of Service | Low | Secunia Advisory: SA16975, September 29, 2005 |
Squid Web Proxy Cache 2.5 & prior | A remote Denial of Service vulnerability has been reported in the 'storeBuffer()' function when handling aborted requests. Patches available at: Gentoo: OpenPKG: Mandriva: Debian: Ubuntu: RedHat: SUSE: SGI: Conectiva: Debian: SUSE: TurboLinux: Currently we are not aware of any exploits for this vulnerability. | Squid Aborted Requests Remote Denial of Service | Low | Security Tracker Alert ID: 1014864, September 7, 2005 Gentoo Linux Security Advisory GLSA 200509-06, September 7, 2005 OpenPKG Security Advisory, OpenPKG-SA-2005.021, September 10, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:162, September 12, 2004 Debian Security Advisory, DSA 809-1, September 13, 2005 Ubuntu Security Notice, USN-183-1, September 13, 2005 RedHat Security Advisory, RHSA-2005:766-7, September 15, 2005 SUSE Security Announcement, SUSE-SA:2005:053, September 16, 2005 SGI Security Advisory, 20050903-02-U, September 28, 2005 Conectiva Linux Announcement, CLSA-2005:1016, September 28, 2005 Debian Security Advisory, DSA 809-2, September 30, 2005 SUSE Security Summary Report, Turbolinux Security Advisory, TLSA-2005-96, October 3, 2005 |
Squid Web Proxy Cache 2.5 .STABLE1-STABLE 10, 2.4 .STABLE6 & 7, STABLE 2, 2.4, 2.3 STABLE 4&5, 2.1 Patch 2, 2.0 Patch 2 | A remote Denial of Service vulnerability has been reported in '/squid/src/ssl.c' when a malicious user triggers a segmentation fault in the 'sslConnectTimeout()' function. Patches available at: Trustix: OpenPKG: Mandriva: Ubuntu: Debian: RedHat: SUSE: SGI: Conectiva: SUSE: There is no exploit code required. | Squid 'sslConnect | Low | Security Tracker Alert ID: 1014846, September 2, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0047, September 9, 2005 OpenPKG Security Advisory, OpenPKG-SA-2005.021, September 10, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:162, September 12, 2005 Ubuntu Security Notice, USN-183-1, September 13, 2005 Debian Security Advisory, DSA 809-1, September 13, 2005 RedHat Security Advisory, RHSA-2005:766-7, September 15, 2005 SUSE Security Announcement, SUSE-SA:2005:053, September 16, 2005 SGI Security Advisory, 20050903-02-U, September 28, 2005 Conectiva Linux Announcement, CLSA-2005:1016, September 28, 2005 SUSE Security Summary Report, |
storeBackup 1.18-1.18.4 | A vulnerability has been reported due to the insecure creation of temporary files, which could let a malicious user obtain sensitive information. Upgrades available at: SUSE: There is no exploit code required. | StoreBackup Insecure Temporary File Creation | Medium | Security Focus, Bugtraq ID: 14985, September 30, 2005 SUSE Security Summary Report, |
Uim 0.5 .0, 0.4.9 | A vulnerability has been reported in 'uim/uim-custom.c' due to the incorrect use of several environment variables, which could let a malicious user obtain elevated privileges. Updates available at: There is no exploit code required. | Uim Elevated Privileges | Medium | Secunia Advisory: SA17043, October 4, 2005 |
gopherd 3.0.9 | A buffer overflow vulnerability has been reported in the 'VlfromLine()' function when copying an input line, which could let a remote malicious user obtain unauthorized access. Debian: An exploit script has been published. | UMN Gopher Client Remote Buffer Overflow | Medium | Secunia Advisory: SA16614, August 30, 2005 Debian Security Advisory, DSA 832-1, September 30, 2005 |
UW-imapd imap-2004c1 | A buffer overflow has been reported in UW-imapd that could let remote malicious users cause a denial of service or arbitrary code execution. Upgrade to version imap-2004g: Currently we are not aware of any exploits for this vulnerability. | UW-imapd Denial of Service and Arbitrary Code Execution | High | Secunia, Advisory: SA17062, October 5, 2005 |
Weex 2.6.1 .5, 2.6.1 | A format string vulnerability has been reported in the 'Log_Flush()' function when flushing an error log entry that contains format string specifiers, which could let a remote malicious user execute arbitrary code.
No workaround or patch available at time of publishing. Currently we are not aware of any exploits for this vulnerability. | Weex Format String | High | Secunia Advisory: SA17028, October 3, 2005 |
Ruby 1.6 - 1.6.8, 1.8 - 1.8.2 | A vulnerability has been reported in 'eval.c' due to a flaw in the logic that implements the SAFE level checks, which could let a remote malicious user bypass access restrictions to execute scripting code. Patches available at: Updates available at: There is no exploit code required. | Ruby Safe Level Restrictions Bypass | Medium | Security Tracker Alert ID: 1014948, September 21, 2005 |
Ruby 1.8.2 | A vulnerability has been reported in the XMLRPC server due to a failure to set a valid default value that prevents security protection using handlers, which could let a remote malicious user execute arbitrary code. Fedora: TurboLinux: Debian: Gentoo: Mandriva: RedHat: Debian: Currently we are not aware of any exploits for this vulnerability. | Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution | High | Fedora Update Notifications, Turbolinux Debian Security Advisory, DSA 748-1, July 11, 2005 Gentoo Linux Security Mandriva Linux Security Update Advisory, RedHat Security Advisory, RHSA-2005: Debian Security Advisory, DSA 773-1, August 11, 2005 |
Multiple Operating Systems - Windows / UNIX / Linux / Other | ||||
Vendor & Software Name | Vulnerability - Impact Patches - Workarounds Attacks Scripts | Common Name / CVE Reference | Risk | Source |
Blender 2.37 a | A buffer overflow vulnerability has been reported in 'blender' and 'blenderplay' due to a boundary error when handling command line inputs, which could let a remote malicious user execute arbitrary code. No workaround or patch available at time of publishing. Currently we are not aware of any exploits for this vulnerability. | Blender Remote Buffer Overflow | High | Security Focus, Bugtraq ID: 14983, September 30, 2005 |
CubeCart 3.0.3 | Cross-Site Scripting vulnerabilities have been reported in the 'cart.php' and 'index.php' scripts due to insufficient filtering of HTML code from certain user-supplied input before displaying the input, which could let a remote malicious user execute arbitrary HTML and script code. Upgrade available at: There is no exploit code required; however, a Proof of Concept exploit script has been published. | CubeCart Multiple Cross-Site Scripting | Medium | Security Tracker Alert ID: 1014984, September 28, 2005 |
EasyGuppy 4.5.5, 4.5.4 | A Directory Traversal vulnerability has been reported in 'printfaq' due to insufficient sanitization, which could let a remote malicious user obtain sensitive information. Upgrades available at: There is no exploit code required; however, a Proof of Concept exploit has been published. | EasyGuppy Directory Traversal | Medium | Security Focus, Bugtraq ID: 14984, September 30, 2005 |
OpenView Network Node Manager 7.50 Solaris, 7.50, 6.41 Solaris, 6.41 | A vulnerability has been reported in the 'node' URI parameter of the 'OvCgi/connected Revision 3: Revision 4: Revision 5: Added PHSS_33842, PSOV_03430, and NNM_01110. Workaround available at: There is no exploit code required; however, a Proof of Concept exploit script has been published. | HP OpenView Network Node Manager Remote Arbitrary Code Execution | High | Portcullis Security Advisory, 05-014, August 25, 2005 HP Security Advisory, HPSBMA01224, August 26, 2005 HP Security Advisory, HPSBMA01224 REVISION: 3, September 13, 2005 HP Security Advisory, HPSBMA01224 REVISION: 4, September 19, 2005 HP Security Advisory, HPSBMA01224 REVISION: 5, October 4, 2005 |
Hitachi Embedded Cosminexus Server Base 5.0, Embedded Cosminexus Server 5.0 , Cosminexus Primary Server Base 6.0, 5.0, Cosminexus Primary Server 6.0, Cosminexus Developer Standard 6.0, Cosminexus Developer Professional 6.0, Cosminexus Developer Light 6.0, Cosminexus Developer 5.0, Cosminexus Application Server Standard 6.0, Cosminexus Application Server Enterprise 6.0, Cosminexus Application Server 5.0 | A vulnerability has been reported when a malformed HTTP post request is sent without a body, which could let a remote malicious user obtain sensitive information. Patches available at: There is no exploit code required. | Hitachi Cosminexus Remote Information Disclosure | Medium | Hitachi Security Advisory, HS05-019, September 30, 2005 |
SMTP-Gateway for Linux/Unix 5.5, 5.0 , Antivirus for Linux Servers 5.5 -2, 5.0.1 .0, 3.5.135 .2, Antivirus 4.0.9.0, Antivirus Scanning Engine 5.0, 4.0, 3.0, | A heap overflow vulnerability has been reported during analysis of .CAB files, which could let a remote malicious user compromise the hosting computer.
No workaround or patch available at time of publishing. Currently we are not aware of any exploits for this vulnerability. | Kaspersky Anti-Virus Library Remote Heap Overflow | High | Security Focus, Bugtraq ID: 14998, October 3, 2005 |
lucidCMS 1.0 .11 | An SQL injection vulnerability has been reported in login due to insufficient sanitization of user-supplied input before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code. No workaround or patch available at time of publishing. There is no exploit code required; however, a Proof of Concept exploit has been published. | lucidCMS Login SQL Injection | Medium | Security Focus, Bugtraq ID: 14976, September 29, 2005 |
MediaWiki 1.4-1.4.8 | Cross-Site Scripting vulnerabilities have been reported when handling '<math>' tags, extensions and '<nowiki>' sections due to insufficient sanitization, which could let a remote malicious user execute arbitrary HTML and script code. Upgrades available at: SUSE: There is no exploit code required. | MediaWiki Cross-Site Scripting | Medium | Secunia Advisory: SA16932, September 30, 2005 SUSE Security Summary Report |
SquirrelMail Address Add Plugin 2.0, 1.9
| A Cross-Site Scripting vulnerability has been reported in 'add.php' due to insufficient sanitization of the 'first' parameter before returning to the user, which could let a remote malicious user execute arbitrary HTML and script code. Update available at: There is no exploit code required; however, a Proof of Concept exploit has been published. | SquirrelMail Cross-Site Scripting | Medium | Security Tracker Alert ID: 1014988, September 29, 2005 |
Firefox 1.0.6; | A vulnerability has been reported which could let a remote malicious user execute arbitrary commands via shell metacharacters in a URL.
Upgrades available at: RedHat: http://rhn.redhat.com/ Ubuntu: Mandriva: Fedora: Slackware: SGI: Conectiva: Fedora: TurboLinux: There is no exploit code required; however, a Proof of Concept exploit has been published. | Mozilla Browser/Firefox Arbitrary Command Execution | High | Security Focus Bugtraq ID: 14888, September 21, 2005 Security Focus Bugtraq ID: 14888, September 22, 2005 RedHat Security Advisories, RHSA-2005:785-9 & 789-11, September 22, 2005 Ubuntu Security Notices, USN-USN-186-1 & 186-2, September 23 & 25, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:169, September 26, 2005 Fedora Update Notifications, Slackware Security Advisory, SSA:2005-269-01, September 26, 2005 SGI Security Advisory, 20050903-02-U, September 28, 2005 Conectiva Linux Announcement, CLSA-2005:1017, September 28, 2005 Fedora Update Notifications, Turbolinux Security Advisory, TLSA-2005-93, October 3, 2005 |
Firefox 0.x, 1.x | Multiple vulnerabilities have been reported: a vulnerability was reported due to an error because untrusted events generated by web content are delivered to the browser user interface; a vulnerability was reported because scripts in XBL controls can be executed even when JavaScript has been disabled; a vulnerability was reported because remote malicious users can execute arbitrary code by tricking the user into using the 'Set As Wallpaper' context menu on an image URL that is really a javascript; a vulnerability was reported in the 'InstallTrigger.install()' function due to an error in the callback function, which could let a remote malicious user execute arbitrary code; a vulnerability was reported due to an error when handling 'data:' URL that originates from the sidebar, which could let a remote malicious user execute arbitrary code; an input validation vulnerability was reported in the 'InstallVersion.compareTo()' function when handling unexpected JavaScript objects, which could let a remote malicious user execute arbitrary code; a vulnerability was reported because it is possible for remote malicious user to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL; a vulnerability was reported due to an error when handling DOM node names with different namespaces, which could let a remote malicious user execute arbitrary code; and a vulnerability was reported due to insecure cloning of base objects, which could let a remote malicious user execute arbitrary code.
Updates available at: Gentoo: Mandriva: Fedora: RedHat: Ubuntu: http://security.ubuntu.com/ http://security.ubuntu.com/ SUSE: Debian: http://security.debian. SGI: Gentoo: Slackware: Debian: Debian: Fedora: HP: HP: Exploits have been published. | Firefox Multiple Vulnerabilities CAN-2005-2260 | High | Secunia Advisory: SA16043, July 13, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:120, July 13, 2005 Gentoo Linux Security Advisory, GLSA 200507-14, July 15, 2005 Gentoo Linux Security Advisory, GLSA 200507-17, July 18, 2005 Fedora Update Notifications, RedHat Security Advisory, RHSA-2005:586-11, July 21, 2005 Slackware Security Advisory, SSA:2005-203-01, July 22, 2005 Ubuntu Security Notices, USN-155-1 & 155-2 July 26 & 28, 2005 Ubuntu Security Notices, USN-157-1 & 157-2 August 1& 2, 2005 SUSE Security Announcement, SUSE-SA:2005:045, August 11, 2005 Debian Security Advisory, DSA 775-1, August 15, 2005 SGI Security Advisory, 20050802-01-U, August 15, 2005 Debian Security Advisory, DSA 777-1, August 17, 2005 Debian Security Advisory, DSA 779-1, August 20, 2005 Debian Security Advisory, DSA 781-1, August 23, 2005 Gentoo Linux Security Advisory, GLSA 200507-24, August 26, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:127-1, August 26, 2005 Slackware Security Advisory, SSA:2005-085-01, August 28, 2005 Debian Security Advisory, DSA 779-2, September 1, 2005 Debian Security Advisory, DSA 810-1, September 13, 2005 Fedora Legacy Update Advisory, FLSA:160202, September 14, 2005 HP Security Bulletin, HPSBOV01229, September 19, 2005 HP Security Bulletin, |
Netscape 8.0.3.3, 7.2;
| A buffer overflow vulnerability has been reported due to an error when handling IDN URLs that contain the 0xAD character in the domain name, which could let a remote malicious user execute arbitrary code. Patches available at: RedHat: http://rhn.redhat.com/ Fedora: Ubuntu: Gentoo: Slackware: Gentoo: Conectiva: Fedora: Debian: TurboLinux: A Proof of Concept exploit script has been published. | Mozilla/Netscape/ | High | Security Focus, Bugtraq ID: 14784, September 10, 2005 RedHat Security Advisories, 769-8 & RHSA-2005:768-6, September 9, 2005 Fedora Update Notifications, Ubuntu Security Notice, USN-181-1, September 12, 2005 Gentoo Linux Security Advisory GLSA 200509-11, September 18, 2005 Security Focus, Bugtraq ID: 14784, September 22, 2005 Slackware Security Advisory, SSA:2005-269-01, September 26, 2005 Gentoo Linux Security Advisory [UPDATE], GLSA 200509-11:02, September 29, 2005 Conectiva Linux Announcement, CLSA-2005:1017, September 28, 2005 Fedora Update Notifications, Debian Security Advisory, DSA 837-1, October 2, 2005 Turbolinux Security Advisory, TLSA-2005-93, October 3, 2005 |
Mozilla Firefox 1.0-1.0.6; Mozilla Browser 1.7-1.7.11 | Multiple vulnerabilities have been reported: a heap overflow vulnerability was reported when processing malformed XBM images, which could let a remote malicious user execute arbitrary code; a vulnerability has been reported when unicode sequences contain 'zero-width non-joiner' characters, which could let a remote malicious user cause a Denial of Service or execute arbitrary code; a vulnerability was reported due to a flaw when making XMLHttp requests, which could let a remote malicious user spoof XMLHttpRequest headers; a vulnerability was reported because a remote malicious user can create specially crafted HTML that spoofs XML objects to create an XBL binding to execute arbitrary JavaScript with elevated (chrome) permissions; an integer overflow vulnerability was reported in the JavaScript engine, which could let a remote malicious user obtain unauthorized access; a vulnerability was reported because a remote malicious user can load privileged 'chrome' pages from an unprivileged 'about:' page, which could lead to unauthorized access; and a window spoofing vulnerability has been reported when a blank 'chrom' canvas is obtained by opening a window from a reference to a closed window, which could let a remote malicious user conduct phishing type attacks. Firefox: Mozilla Browser: RedHat: Ubuntu: Mandriva: Fedora: Slackware: SGI: Conectiva: Gentoo: SUSE: Fedora: Debian: TurboLinux: Currently we are not aware of any exploits for this vulnerability. | Mozilla Browser / Firefox Multiple Vulnerabilities CAN-2005-2701 | High | Mozilla Foundation Security Advisory, 2005-58, September 22, 2005 RedHat Security Advisory, RHSA-2005:789-11, September 22, 2005 Ubuntu Security Notices, USN-186-1 & 186-2, September 23 & 25, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:169 & 170, September 26, 2005 Fedora Update Notifications, Slackware Security Advisory, SSA:2005-269-01, September 26, 2005 SGI Security Advisory, 20050903-02-U, September 28, 2005 Conectiva Linux Announcement, CLSA-2005:1017, September 28, 2005 Gentoo Linux Security Advisory [UPDATE] , September 29, 2005 SUSE Security Announcement, SUSE-SA:2005:058, September 30, 2005 Fedora Update Notifications, Debian Security Advisory, DSA 838-1, October 2, 2005 Turbolinux Security Advisory ,TLSA-2005-93, October 3, 2005 |
Ubuntu Linux 5.0 4 powerpc, i386, amd64, 4.1 ppc, ia64, ia32; | A buffer overflow vulnerability has been reported in the RTF importer due to a boundary error, which could let a remote malicious user execute arbitrary code. Upgrades available at: Ubuntu: Fedora: Gentoo: Currently we are not aware of any exploits for this vulnerability. | AbiWord RTF File Processing Remote Buffer Overflow | High | Security Tracker Alert ID: 1014982, September 28, 2005 Ubuntu Security Notice, USN-188-1, September 29, 2005 Fedora Update Notification, Gentoo Linux Security Advisory, GLSA 200509-20, September 30, 2005 |
Gentoo Linux; | A remote Denial of Service vulnerability has been reported in the HTTP 'Range' header due to an error in the byte-range filter. Patches available at: Gentoo: RedHat: Ubuntu: Fedora: SGI: Debian: Trustix: Mandriva: SUSE: Avaya: Conectiva: TurboLinux: There is no exploit code required. | Apache Remote Denial of Service | Low | Secunia Advisory: SA16559, August 25, 2005 Security Advisory, GLSA 200508-15, August 25, 2005 RedHat Security Advisory, RHSA-2005:608-7, September 6, 2005 Ubuntu Security Notice, USN-177-1, September 07, 2005 Fedora Update Notifications, Mandriva Linux Security Update Advisory, MDKSA-2005:161, September 8, 2005 SGI Security Advisory, 20050901-01-U, September 7, 2005 Debian Security Advisory, DSA 805-1, September 8, 2005 Trustix Secure Linux Security Advisory, TSLSA-2005-0047, September 9, 2005 SUSE Security Summary Report, SUSE-SR:2005:020, September 12, 2005 Avaya Security Advisory, ASA-2005-204, September 23, 2005 Conectiva Linux Announcement, CLSA-2005:1013, September 27, 2005 Turbolinux Security Advisory, TLSA-2005-94, October 3, 2005 |
PHPXMLRPC 1.1.1; | A vulnerability has been reported in XML-RPC due to insufficient sanitization of certain XML tags that are nested in parsed documents being used in an 'eval()' call, which could let a remote malicious user execute arbitrary PHP code.
PHPXMLRPC : Pear: Drupal: eGroupWare: MailWatch: Nucleus: RedHat: Ubuntu: Mandriva: Gentoo: http://security.gentoo.org/ http://security.gentoo.org/ Fedora: Debian: SUSE: Gentoo: http://security.gentoo.org/ Slackware: Debian: SGI: Slackware: Gentoo: Debian: There is no exploit code required. | PHPXMLRPC and PEAR XML_RPC Remote Arbitrary Code Execution | High | Security Focus, Bugtraq ID 14560, August 15, 2995 Security Focus, Bugtraq ID 14560, August 18, 2995 RedHat Security Advisory, RHSA-2005:748-05, August 19, 2005 Ubuntu Security Notice, USN-171-1, August 20, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:146, August 22, 2005 Gentoo Linux Security Advisory, GLSA 200508-13 & 14, & 200508-18, Fedora Update Notifications, Debian Security Advisory, DSA 789-1, August 29, 2005 SUSE Security Announcement, SUSE-SA:2005:049, August 30, 2005 Gentoo Linux Security Advisory, GLSA GLSA 200508-20& 200508-21, August 30 & 31, 2005 Slackware Security Advisory, SSA:2005-242-02, August 31, 2005 Debian Security Advisory, DSA 798-1, September 2, 2005 SUSE Security Announcement, SUSE-SA:2005:051, September 5, 2005 SGI Security Advisory, 20050901-01-U, September 7, 2005 Slackware Security Advisories, SSA:2005-251-03 & 251-04, September 9, 2005 Gentoo Linux Security Advisory, GLSA 200509-19, September 27, 2005 Debian Security Advisory, DSA 840-1, October 4, 2005 |
MySQL 5.0 .0-0-5.0.4, 4.1 .0-0-4.1.5, 4.0.24, 4.0.21, 4.0.20 , 4.0.18, 4.0 .0-4.0.15 | A buffer overflow vulnerability has been reported due to insufficient bounds checking of data that is supplied as an argument in a user-defined function, which could let a remote malicious user execute arbitrary code. This issue is reportedly addressed in MySQL versions 4.0.25, 4.1.13, and 5.0.7-beta available at: Mandriva: Ubuntu: Debian: SUSE: Debian: Currently we are not aware of any exploits for this vulnerability. | MySQL User-Defined Function Buffer Overflow | High | Security Focus 14509 , August 8, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:163, September 12, 2005 Ubuntu Security Notice, USN-180-1, September 12, 2005 Debian Security Advisories, DSA 829-1 & 831-1, September 30, 2005 SUSE Security Summary Report, Debian Security Advisory, DSA 833-1, October 1, 2005 |
MyBloggie 2.1.3 beta | An SQL injection vulnerability has been reported in the 'login.php' script due to insufficient validation of the 'username' parameter before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code. No workaround or patch available at time of publishing. A Proof of Concept exploit script has been published. | MyBloggie SQL Injection | Medium | Security Tracker Alert ID: 1014995, October 3, 2005 |
PHP-Fusion 6.0.109 | SQL injection vulnerabilities have been reported in 'photogallery.php' due to insufficient sanitization of the 'album' and 'photo' parameters before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code. No workaround or patch available at time of publishing. There is no exploit code required. | PHP-Fusion Multiple SQL Injection | Medium | Secunia Advisory: SA17048, October 4, 2005 |
PHP-Fusion 6.0.109 | An SQL injection vulnerability has been reported in 'messages.php' due to insufficient sanitization of the 'msg_send' parameter before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code. No workaround or patch available at time of publishing. There is no exploit code required; however, a Proof of Concept exploit script has been published. | PHP-Fusion SQL Injection | Medium | Secunia Advisory: SA16994, September 29, 2005 |
Polipo 0.9-0.9.8 | A vulnerability has been reported because files can be exposed outside of the local root, which could let a remote malicious user obtain sensitive information.
Upgrades available at: Currently we are not aware of any exploits for this vulnerability. | Polipo Web Root Restriction Bypass | Medium | Security Focus, Bugtraq ID: 14970, September 28, 2005 |
RealPlayer G2, 6.0 Win32, 6.0, 7.0 Win32, 7.0 Unix, 7.0 Mac, 8.0 Win32, 8.0 Unix, 8.0 Mac, 10.0 BETA, 10.0 v6.0.12.690, 10.0, 0.5 v6.0.12.1059 | A vulnerability has been reported when a specially crafted media file is opened, which could let a remote malicious user execute arbitrary code.
RealNetworks: RedHat: http://rhn.redhat.com/ Fedora: SUSE: Gentoo: Debian: Currently we are not aware of any exploits for this vulnerability. | RealNetworks RealPlayer Unspecified Code Execution | High | eEye Digital Security Advisory, RedHat Security Advisories, RHSA-2005: Fedora Update Notifications, SUSE Security Announce- Gentoo Linux Security Advisory, GLSA 200507-04, July 6, 2005 Debian Security Advisory, DSA 826-1, September 30, 2005 |
OpenOffice 1.1.4, 2.0 Beta | A vulnerability has been reported due to a heap overflow when a specially crafted malformed '.doc' file is opened, which could lead to a Denial of Service or execution of arbitrary code. Fedora: Gentoo: SUSE: RedHat:
href="http://rhn.redhat.com/errata/RHSA-2005-375.html"> SGI: Mandriva: Ubuntu: SUSE: Currently we are not aware of any exploits for this vulnerability. | High
| Security Focus, 13092, Fedora Update Notification, Gentoo Linux Security Advisory, GLSA 200504-13, April 15, 2005 SUSE Security Announcement, SUSE-SA:2005:025, April 19, 2005 RedHat Security Advisory, RHSA-2005:375-07, April 25, 2005 SGI Security Advisory, 20050501-01-U, May 5, 2005 Mandriva Linux Security Update Advisory, MDKSA-2005:082, May 6, 2005 Ubuntu Security Notice, USN-121-1, May 06, 2005 SUSE Security Summary Report, SUSE-SR:2005:021, September 30, 2005 |
[back to top] Wireless
The section below contains wireless vulnerabilities, articles, and viruses/trojans identified during this reporting period.
- 10 ways to wireless security: Wireless networking is easy to set up and convenient but more vulnerable to interception and attack than a wired connection. Ten tips for securing wireless can be found at: http://insight.zdnet.co.uk/communications/wireless/0,39020430,39223889,00.htm.
Wireless Vulnerabilities
- Nothing significant to report.
Recent Exploit Scripts/Techniques
The table below contains a sample of exploit scripts and "how to" guides identified during this period. The "Workaround or Patch Available" column indicates if vendors, security vulnerability listservs, or Computer Emergency Response Teams (CERTs) have published workarounds or patches.
Note: At times, scripts/techniques may contain names or content that may be considered offensive.
Date of Script | Script name | Workaround or Patch Available | Script Description |
October 4, 2005 | ciscocrack2.c | N/A | Updated version of ciscocrack.c that works with newer versions of IOS. |
October 4, 2005 | Fusionv-6.00.109.txt | No | Exploit for the PHP-Fusion information disclosure vulnerability. |
October 4, 2005 | fr-dyn0.txt | N/A | A cross site scripting exploit for friendsreunited.co.uk lost password functionality. |
October 4, 2005 | lucid_cms_1011_expl.txt | No | Exploit for the Lucid CMS SQL Injection, Login Bypass, and remote code execution vulnerabilities. |
October 4, 2005 | mybloggie213b.txt | No | Script that exploits the MyBloggie SQL Injection vulnerability. |
October 4, 2005 | virtbugs.c virtools.3.0.0.100.txt | Yes | Exploits for the Virtools Web Player Buffer Overflow and Directory Traversal vulnerabilities. |
October 3, 2005 | gnome_pty_helper.c | No | Proof of Concept exploit for the Gnome-PTY-Helper UTMP Hostname Spoofing vulnerability. |
September 30, 2005 | prozilla.c | Yes | Script that exploits the ProZilla Remote Buffer Overflow vulnerability. |
September 29, 2005 | cubecart-3.0.3.txt | Yes | Exploitation for the CubeCart Multiple Cross-Site Scripting vulnerabilities. |
September 29, 2005 | mantis-poc.tar.gz | N/A | Mantis Bugtracker exploit scanner that looks for versions less than 1.0.0RC2 and greater than 0.18.3 which are vulnerable to XSS and variable poisoning attacks if register_globals is enabled. |
September 28, 2005 | PhpF6_00_109xpl.php phpfusion600109.txt Fusionv-6.00.109.txt | No | Proof of Concept exploits for the PHP-Fusion SQL Injection vulnerability. |
September 28, 2005 | zabypass.zip | No | Proof of Concept exploit for the Zone Labs ZoneAlarm Pro DDE-IPC Advanced Program Control Bypass vulnerability. |
[back to
top]
name=trends>Trends
- Microsoft's five-month Office flaw exploited: Security experts are warning that a new Trojan horse exploits an unpatched flaw in Microsoft Office and could let an attacker take control of vulnerable computers. According to Symantec in an advisory they released, the Trojan horse arrives in the guise of a Microsoft Access file. The malicious code takes advantage of a flaw in Microsoft's Jet Database Engine. The security hole was reported to Microsoft in April but the company has yet to provide a fix for the problem. "Microsoft is aware that a Trojan recently released into the wild may be exploiting a publicly reported vulnerability in Microsoft Office." The software maker is investigating the issue and will take "appropriate action", the representative said. Source: http://software.silicon.com/
malware/0,3800003100,39152941,00.htm. - Data Scandal: According to security experts, a data scandal roll call would include big names in nearly every industry. Some experts say that there are hundreds if not thousands of other, less-publicized cases in which sensitive personal data has been compromised. For CIOs, this trend means two things: It may not be a case of whether your company will experience a data security breach but when it will experience such a breach. And, if you're one of the unlucky 10% or less who find their stories blasted throughout the national news media, you'd better know beforehand how you're going to respond when a breach occurs. Source: http://www.computerworld.com/securitytopics/security/
story/0,10801,105065,00.html . - Virus attacks fall: According to two reports, the threat of infection by mass-mailed viruses is decreasing and tailored attacks are on the increase. The number of viruses circulating around the Internet declined in September. Source: http://news.zdnet.co.uk/internet/security/
0,39020375,39225761,00.htm. - Center allows industry to explore cybersecurity: The National Science Foundation is sponsoring a new research center to explore short-term solutions to cybersecurity problems. Government, businesses and academic institutions are invited to take part in the Center for Information Protection (CIP), based at Iowa State University. "With over 85 percent of the cyber infrastructure controlled by private industries, it is critical that government, academia and the private sector work together to develop better methods to protect public and private information contained within the infrastructure," said Carl Landwehr, an NSF program director, in a prepared statement.
Source: http://www.fcw.com
/article90999-10-03-05-Print. - Online Crime Rises Dramatically, Report Says: According to a survey conducted by Symantec, online criminal activity of nearly every variety surged in the first half of 2005, fueled in large part by an increase in software security flaws and in the number of home computers being used against their owners' wishes to distribute spam, spyware and viruses. Symantec also tracked a massive increase in "denial of service" attacks. During this six month period, 1,862 new software vulnerabilities were discovered. Source: http://www.bizreport.com/news/9331/ .
- Defend your network against idle scanning: Just blocking the IP address when your organization's intrusion-detection system (IDS) identifies a scan of your network isn't addressing the real threat. Black hats employ several stealth scanning techniques, and one of those threats is the idle scan.
Source: http://insight.zdnet.co.uk/communications/networks/0,39020427,39224417,00.htm.
- Threat Alert: Spear Phishing: According to the secretary general of the Anti-Phishing Working Group, spear phishers act much like marketers, crafting a message and then directing it to just the right people.
Intercepted spear-phishing attempts exploded from 56 instances in January to more than 600,000 cases in June. Source: http://www.pcworld.com/resource/article/
0,aid,122497,pg,1,RSS,RSS,00.asp. - Malicious code could trick ZoneAlarm firewall: Security experts are warning that malicious code that masquerades as a trusted application could trick a ZoneAlarm firewall into letting it connect to the Internet. Source: http://beta.news.com.com/Malicious+code+could+trick+ZoneAlarm+
firewall/2100-1002_3-5886488.html?part=rss&tag=5886488&subj=news.
name=viruses id="viruses">Viruses/Trojans Top Ten Virus Threats
A list of high threat viruses, as reported to various anti-virus vendors and virus incident reporting organizations, has been ranked and categorized in the table below. For the purposes of collecting and collating data, infections involving multiple systems at a single location are considered a single infection. It is therefore possible that a virus has infected hundreds of machines but has only been counted once. With the number of viruses that appear each month, it is possible that a new virus will become widely distributed before the next edition of this publication. To limit the possibility of infection, readers are reminded to update their anti-virus packages as soon as updates become available. The table lists the viruses by ranking (number of sites affected), common virus name, type of virus code (i.e., boot, file, macro, multi-partite, script), trends (based on number of infections reported since last week), and approximate date first found.
face="Arial, Helvetica, sans-serif">Rank | Common Name | Type of Code |
face="Arial, Helvetica, sans-serif">Trend | Date |
face="Arial, Helvetica, sans-serif">Description |
1 | Netsky-P | Win32 Worm | Stable | March 2004 | A mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning the hard drives and mapped drives. The worm also tries to spread through various file-sharing programs by copying itself into various shared folder. |
2 | Lovgate.w | Win32 Worm | Slight Increase | April 2004 | A mass-mailing worm that propagates via by using MAPI as a reply to messages, by using an internal SMTP, by dropping copies of itself on network shares, and through peer-to-peer networks. Attempts to access all machines in the local area network. |
3 | Netsky-D | Win32 Worm | Increase | March 2004 | A simplified variant of the Netsky mass-mailing worm in that it does not contain many of the text strings that were present in NetSky.C and it does not copy itself to shared folders. Netsky.D spreads itself in e-mails as an executable attachment only. |
4 | Mytob-BE | Win32 Worm | Increase | June 2005 | A slight variant of the mass-mailing worm that utilizes an IRC backdoor, LSASS vulnerability, and email to propagate. Harvesting addresses from the Windows address book, disabling antivirus, and modifying data. |
5 | Mytob-AS | Win32 Worm | Increase | June 2005 | A slight variant of the mass-mailing worm that disables security related programs and processes, redirection various sites, and changing registry values. This version downloads code from the net and utilizes its own email engine. |
6 | Zafi-B | Win32 Worm | Decrease | June 2004 | A mass-mailing worm that spreads via e-mail using several different languages, including English, Hungarian and Russian. When executed, the worm makes two copies of itself in the %System% directory with randomly generated file names. |
7 | Mytob.C | Win32 Worm | Slight Decrease | March 2004 | A mass-mailing worm with IRC backdoor functionality which can also infect computers vulnerable to the Windows LSASS (MS04-011) exploit. The worm will attempt to harvest email addresses from the local hard disk by scanning files. |
8 | Zafi-D | Win32 Worm | Decrease | December 2004 | A mass-mailing worm that sends itself to email addresses gathered from the infected computer. The worm may also attempt to lower security settings, terminate processes, and open a back door on the compromised computer. |
9 | Netsky-Q | Win32 Worm | Decrease | March 2004 | A mass-mailing worm that attempts to launch Denial of Service attacks against several web pages, deletes the entries belonging to several worms, and emits a sound through the internal speaker. |
10 | Netsky-Z | Win32 Worm | Slight Decrease | April 2004 | A mass-mailing worm that is very close to previous variants. The worm spreads in e-mails, but does not spread to local network and P2P and does not uninstall Bagle worm. The worm has a backdoor that listens on port 665. |
Table updated October 3, 2005
Last updated
Please share your thoughts
We recently updated our anonymous product survey; we’d welcome your feedback.