* IE flaw is bigger than expected * Asterisk patches major remotely exploitable flaw * Patches from rPath and Gentoo
endif; ?>Still using Internet Explorer 5? You might be vulnerable to a information-stealing flaw. Microsoft last week said IE7 was the only browser version affected by a newly discovered vulnerability. But late last week the company expanded that advisory to include ALL versions of IE from 5 to 8 beta. No patches are available, but Microsoft does offer some risk-mitigating steps to take. Might be time to give Firefox, Safari or Chrome a try if you haven’t already.
Oops! Looks like that IE flaw is bigger than expectedA day after its massive Patch Tuesday release, Microsoft last week warned of a new Internet Explorer vulnerability that could be used to steal user information. At the time, it was thought that only IE7 that was affected. Turns out all versions of IE are vulnerable and hackers are taking action, according to the SANS Internet Storm Center. Microsoft has not yet released a patch for the flaw, which affects everything from IE5 to IE8 beta. The company is recommending a number of risk-mitigating steps, but it might be best to use a different browser until patches are available.SANS ISC diary entry**********Asterisk patches major remotely exploitable flaw
According to the Asterisk advisory, “There is a possibility to remotely crash an Asterisk server if the server is configured to use realtime IAX2 users. The issue occurs if either an unknown user attempts to authenticate or if a user that uses hostname matching attempts to authenticate. The problem was due to a broken function call to Asterisk’s realtime configuration API.” Updates are available to fix the flaw.
**********
Two new patches from rPath:
tshark/wireshark (denial of service)
**********
Two new updates from Gentoo:




