* VMware releases slew of updates * Flaw found in MSN messaging protocol * Patches from Mandriva
VMware is out with a batch of fixes for its systems that includes a new ActiveX control update designed to quell security issues related to Internet Explorer and updates for a range of other issues. Pidgin users should take heed and download the latest version of the open source IM client after the latest warning from The Zero Day Initiative about a flaw in the MSN chat protocol. And iPhone users will have to wait at least a few more days for a fix from Apple for the little flaw that allows locked iPhones to be opened with a few easy button pushes.
VMware releases slew of updates
Updates are available for a range of VMWare products including VMware Workstation, VMware Player, VMware ACE, VMware Server and VMware ESX. With these releases, VMWare is addressing an issue with the way its ActiveX controls run inside Internet Explorer as well as fixing flaws that could be used for privilege escalation, denial-of-service attacks and to run malicious code.
**********
Flaw found in MSN messaging protocol
The Zero Day Initiative is reporting a new flaw in the way the MSN instant messaging protocol is handled by certain multi-protocol clients could be exploited to run malicious code on an affected system. Pidgin is one system that is impacted, but has already released an update.
Pidgin update**********Apple promises September fix for iPhone security flaw
A recently discovered security flaw that would allow access to a locked iPhone will be fixed next month, Apple said on Thursday. The security flaw allows access to a locked iPhone by pressing the emergency call button at the unlock screen, followed by two taps on the home button. Macworld, 08/28/2008.
**********
Two new updates from Mandriva:
ipsec-tools (denial of service)
libxml2 (denial of service)**********
Today’s malware news:
Do You Know Where Your Baby Is?
Notice! The virus-spreading spammer doesn’t have your baby but is claiming to. In recent emails observed by Symantec, malicious code is being spread by hoax emails claiming to have pictures of your hijacked [sic] baby. The Subject line makes the claim that someone has “hijacked” your baby and the attachment on the message is not a photo, but rather a zip file containing a downloader. Symantec Security Response, 08/29/2008.
Leave Your Webcam On 24/7? Might Want To Reconsider…
It’s nothing new that many hackers use programs that allow them to “spy” on their victims once they’ve compromised the PC (as long as they have a webcam switched on, of course). Similarly, hacking culture has always had a fascination for memes, incorporating them into part of the design of their latest DDoS tools. The SpywareGuide Greynets Blog, 09/01/2008.
Sometimes it’s easy to believe that every last thing online is going to eat into your PC, burn your house down, kill your cat and so on. The last few days I’d been hearing rumblings about some “Youtube rap video” and a file that would start hijacking your PC – well, thanks to a tipoff from a forum-goer at Spywarewarrior, I can hopefully put this one to rest. The SpywareGuide Greynets Blog, 08/29/2008.




