Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Apple patches multiple flaws

Patches from Apple, Microsoft, Ubuntu, others Tricky eBay car scam hits the Web Phishing attacks target CareerBuilder.com users, and other interesting reading
Security: Threat Alert By Jason Meserve , Network World , 03/15/2007
Sign up for this newsletter now!

Jason Meserve provides up-to-the-minute news on vendor security alerts and fixes.

  • Share/Email
  • Comment
  • Print

Today's bug patches and security alerts:

Apple patches multiple Mac OS X flaws

A new update from Apple fixes vulnerabilities in ColorSync, CoreGraphics, Crash Reporter, CUPS, Disk Images, DS Plug-Ins, Flash Player, GNU Tar, HFS, HID Family, ImageIO, Kernel, MySQL Server, Networking, OpenSSH, Printing, QuickDraw Manager, servermgrd, SMB File Server, Software Update, sudo, and Weblog.

Related US-CERT advisory

Apple releases patch for iPhoto vulnerability

A flaw in Apple's popular iPhoto application could exploited by an attacker to run malicious code on an affected system. The vulnerability lies in iPhoto's handling of "photocasts".

**********

Microsoft releases two Vista fixes

As promised, Microsoft did not unveil any security fixes Tuesday. But it did push out several other patches it deemed "high priority," including two for Windows Vista. Among the four updates Microsoft pegged as "non-security, high-priority" today were the usual monthly revamp of the Microsoft Malicious Software Removal Tool and new signatures for the Outlook 2003 and Outlook 2007 antispam filters. Computerworld, 03/13/07.

New IE 7 bug could help phishers

A vulnerability in Microsoft's Internet Explorer browser could help fraudsters make phishing Web sites appear legitimate, a security researcher reported Wednesday. Microsoft is investigating the claim. IDG News Service, 03/14/07

**********

Two new patches from Ubuntu:

Xine (buffer overflow, code execution)

KTorrent (multiple flaws)

**********

Two new updates from Mandriva:

xine-lib (buffer overflow, code execution)

mplayer (buffer overflow, code execution)

**********

Two new fixes from Gentoo:

SILC Server (denial of service)

Amarok (code execution)

**********

Today's malware news:

Tricky eBay car scam hits the Web

Symantec has uncovered an unusually sophisticated e-mail scam, targeting eBay users with a combination of legitimate eBay auctions and a Windows Trojan that intercepts a user's Web traffic. TechWorld, 03/12/07.

**********

From the interesting reading department:

Phishing attacks target CareerBuilder.com users

Attackers are launching targeted phishing scams from the job-related site CareerBuilder.com, according to one network manager who says his engineering firm recently had to combat phishing techniques that use the lure of phony online resumes. Network World, 03/12/07.

Jason Meserve is multimedia editor at Network World.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed