Enterprise customers still waiting for Patch Tuesday updates

Opinion
Jun 16, 20082 mins

* Patches from Debian, Mandriva, Gentoo, Ubuntu and more * Get a text message saying you won the lottery?

It’s been nearly a week since Microsoft’s June Patch Tuesday security updates were released, but some corporate users are still waiting for updates because of a bug in Microsoft’s patch distribution tools for enterprises. A fix is in the works and Microsoft is offering a workaround for those that want to push patches out ASAP. There’s also a number of new phishing attack vectors hackers are using in attempt to lure personal information out of would-be victims.

Microsoft snafu blocks enterprise patching

Microsoft confirmed late Friday that enterprise administrators using one of its patch distribution tools have not been able to install last week’s security updates. The company offered a workaround and said it is working on a fix. Computerworld, 06/15/2008.

Microsoft advisory

**********

Six new updates from Debian:

mt-daapd (multiple vulnerabilities)

typo3 (multiple flaws)

xorg-server (multiple flaws)

imlib2 (buffer overflows, code execution)

tomcat5.5 (input santisation, cross-scripting)

linux-2.6 (heap overflow, code execution)

**********

Four new patches from Mandriva:

util-linux-ng (injection flaw)

kernel for version 2008.1 (multiple flaws)

kernel for version 2007.1 (multiple flaws)

Firefox (multiple flaws)

**********

Two fixes from Gentoo:

rdesktop (multiple flaws)**********

Imlib 2 (user-assisted code execution)

Two new updates from Ubuntu:

X.org (multiple flaws)**********

Evolution (multiple flaws)

Two new patches from rPath:

kernel (buffer overflow, code execution)

vsftpd (denial of service)

**********

Today’s malware news:

Get a text message saying you won the lottery?

If you haven’t guessed already, it’s a scam. 419 Scammers have turned to text messaging as their next fraud-inducing medium. Network World Security Blog, 06/12/2008.

Marketing or spam?

PandaLabs has detected the sending of phishing emails that try to trick users into revealing their bank details. Unlike other fraudulent mails, users are asked to type the URL on the email into a cell phone or smartphone with Internet access, instead of clicking a link which redirected them to a spoof web page aimed at stealing confidential details. Panda Security, 06/14/2008.

FBI warns of child-support card scam

The U.S. Federal Bureau of Investigation warned Friday that online scammers are now targeting single parents who use the EPPICard system to receive child-support payments. The criminals are running a typical phishing scam, but one that is targeted at a new group of victims. IDG News Service, 06/13/2008.