* Attack code for critical Microsoft bug surfaces * Patches from FreeBSD, Debian, Ubuntu
endif; ?>Hope you’ve got that out-of-cycle Windows patch installed, because there’s already a worm running amok exploiting the flaw. Microsoft took the unusual step of rushing out a patch for Windows last Thursday and within hours attack code was published that could take advantage of the flaw. Not quite Zero Day, but pretty close. Of course, a lot of noise was made over Microsoft’s non-Patch Tuesday release, but some in the security community are wondering what the big deal is? After all, there are automatic systems in place to install said patches, and other vendors release patches all the time without a parade. So why the hoopla over this Microsoft release?
Attack code for critical Microsoft bug surfaces
Just hours after Microsoft posted details of a critical Windows bug, new attack code that exploits the flaw has surfaced. It took developers of the Immunity security testing tool two hours to write their exploit, after Microsoft released a patch for the issue Thursday morning. IDG News Service, 10/23/2008.
Also:
Data-Stealing Trojan Exploiting Just-Patched Windows Flaw
Microsoft says Windows flaw could bring worm attack
Microsoft advisory: Vulnerability in Server Service Could Allow Remote Code Execution
**********
A vulnerability in FreeBSD’s Neighbor Discovery protocol, part of its IPv6 implementation, could be exploited by an attacker to update router configurations without authorization. An update is available.
**********
Debian releases fix for libspf2 flaw
Dan Kaminski, the guy who figured out the major flaw in DNS this past summer, has found a buffer overflow vulnerability in libspf2, an implemenation of the Sender Policy Framework that is used by mail servers to filter for Spam and other bad messages. An attacker could exploit the flaw to run malicious code. An update is available.
**********
Two new updates from Ubuntu:




