Malware News

W32/Winemmem infects packages, installers and self-extracting archives (files with extra data, so called "overlay"). It rewrites the code section of the original application and relocates a random size block of code from the beginning of code section and OEP to the end of the file, increasing the size of extra data. This Virus does not create new sections, it does not modify the PE header.

Mozilla Firefox 3.5 'TraceMonkey' Vulnerability

Print PDF

Mozilla Firefox is prone to a remote code-execution vulnerability. Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable. NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2.

Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability

Risk

High

Date Discovered

July 13, 2009

Description

Mozilla Firefox is prone to a remote code-execution vulnerability. Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable. NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP3. UPDATE (July 15, 2009): Remote code execution is also possible in Firefox 3.5 running on Apple Mac OS X.

Technologies Affected

  • Mozilla Firefox 3.5.0
  • Mozilla XULRunner 1.9
  • Mozilla XULRunner 1.9.1
  • Mozilla XULRunner 1.9.1.1
  • RedHat Fedora 11

Recommendations

Block external access at the network boundary, unless external parties require service.

If global access isn't needed, filter access to the affected computer at the network boundary. Restricting access to only trusted computers and networks might greatly reduce the likelihood of successful exploits.

Run all software as a nonprivileged user with minimal access rights.

To reduce the impact of latent vulnerabilities, run all applications with the minimal amount of privileges required for functionality.

Deploy network intrusion detection systems to monitor network traffic for malicious activity.

Deploy NIDS to monitor network traffic for signs of anomalous or suspicious activity. This includes but is not limited to requests that include NOP sleds and unexplained incoming and outgoing traffic. This may indicate exploit attempts or activity that results from successful exploits.

Do not follow links provided by unknown or untrusted sources.

To reduce the likelihood of successful exploits, never visit sites of questionable integrity or follow links provided by unfamiliar or untrusted sources.

Set web browser security to disable the execution of script code or active content.

Disabling JavaScript in the browser will prevent successful exploits but may reduce the functionality of sites that employ JavaScript.
The vendor has released an advisory and fixes. Please see the references for details.

Credits

SBerry aka Simon Berry-Byrne

Disclaimer

The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.

Common Threats

iTunes Hacking

Microsoft launches online security patch

Microsoft has released an emergency online security patch following the discovery of a potential glitch in its technology. The software giant announced that the online security update will automatically be installed for Internet Explorer customers. Microsoft released the patch after a vulnerability in the company's Active Template Library was discovered. The software is used to build ActiveX controls and other web application components.

Web users should be cautious of fake anti-virus programs

A new report has highlighted that malware posing as anti-virus software is spreading across tens of millions of computers each month. According to research by PandaLabs, over 1,000 examples of fake anti-virus software were found in the first quarter of 2008 alone. The program works by issuing false warnings of infections, persuading web users to buy software they do not need, and can also download Trojans or malware.

Spammers translating messages cause global security issues

Spam email is becoming a growing threat in non-English speaking nations, according to a new study. Research by MessageLabs highlights that spammers are now using free online translation sites to write messages in a variety of languages and target a greater number of people across the globe. As a result, some nations which previously enjoyed a high level of internet security are now falling victim to rising levels of spam.

Malware 'the greatest threat'

The greatest threat to computer networks is malware, meaning people should be wary of introducing unnecessary software to their machines, an expert has stated. Writing for his risk management blog hosted by online publication ComputerWeekly.com, Stuart King warned that some people are reporting that their new digital picture frames and gadgets such as MP3 players are infected with viruses.

Sun Java Runtime Environment Vulnerabilities

Sun Java Runtime Environment and Java Development Kit are prone to multiple security vulnerabilities. Successful exploits may allow attackers to violate the same-origin policy, obtain sensitive information, bypass security restrictions, run untrusted applets with elevated privileges, and cause denial-of-service conditions. This may result in a compromise of affected computers.

* Geeks Houston ®, Geeks Mobile, and geeksquadonline.com have no affiliation to Geek Squad or Best Buy

Internet Explorer Execution Vulnerability

Microsoft Internet Explorer is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the browser and possibly the computer. Failed attacks may cause denial-of-service conditions.

Read more...
PCWorld
PCWorld.com
  • Windows 8 Security: What's New
    Windows 8 is a major OS overhaul, but some of the most important additions might be the ones you can't see. Here's a look at Windows 8's new security tools and features.

    Add to digg Add to Reddit Add to Slashdot Email this Article Add to StumbleUpon