Discovered: July 2, 2003
Updated: February 13, 2007 12:03:54 PM
Also Known As: Worm.Linux.Sorso.a, Backdoor.Linux.Sorso (AVP)
Type: Worm
Systems Affected: Linux
Linux.Sorso is a worm that replicates using a
Samba buffer overflow exploit. The worm targets vulnerable installations of the Samba server version 2.2.8a and earlier, version 2.0.10 and earlier, and Samba-TNG version 0.3.2 and earlier. The worm also contains code for a backdoor and a Distributed Denial of Service (DDoS) attack and only affects Linux running on Intel x86 platforms.
Protection
-
Initial Rapid Release version July 3, 2003
-
Latest Rapid Release version August 20, 2008 revision 017
-
Initial Daily Certified version July 3, 2003
-
Latest Daily Certified version August 20, 2008 revision 016
-
Initial Weekly Certified release date July 9, 2003
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yuhui Huang