Linux.Sorso

Printer Friendly Page

Discovered: July 2, 2003
Updated: February 13, 2007 12:03:54 PM
Also Known As: Worm.Linux.Sorso.a, Backdoor.Linux.Sorso (AVP)
Type: Worm
Systems Affected: Linux


Linux.Sorso is a worm that replicates using a Samba buffer overflow exploit. The worm targets vulnerable installations of the Samba server version 2.2.8a and earlier, version 2.0.10 and earlier, and Samba-TNG version 0.3.2 and earlier. The worm also contains code for a backdoor and a Distributed Denial of Service (DDoS) attack and only affects Linux running on Intel x86 platforms.


Protection

  • Initial Rapid Release version July 3, 2003
  • Latest Rapid Release version August 20, 2008 revision 017
  • Initial Daily Certified version July 3, 2003
  • Latest Daily Certified version August 20, 2008 revision 016
  • Initial Weekly Certified release date July 9, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Writeup By: Yuhui Huang
Search by name
Example: W32.Beagle.AG@mm
2 year protection
Windows Vista Security