Access flaw found, not part of Patch Tuesday updates

Opinion
Jul 7, 20084 mins

* Patches from Opera, Mandriva, Debian, others * Cue the fireworks, Storm makes 4th return * Clothes don't make this man: Sweatshirt helps nail Citibank card scammer, and other interesting reading

Microsoft is warning of a new Access-based attack that is exploited when users visit a malicious Web site using Internet Explorer. Details are limited about exactly what is wrong with Access and the fix will not be included in today’s Patch Tuesday release, meaning attackers potentially have another month to exploit the flaw. Microsoft will be patching four non-critical bugs today in its monthly update, including flaws in Exchange and SQL.

Microsoft warns of new Access attack

Cybercriminals are exploiting a bug in software used by Microsoft’s Access database program in a new online attack, Microsoft warned Monday. The flaw lies in the Snapshot Viewer ActiveX control, which ships with “all supported versions of Microsoft Office Access except Microsoft Access 2007,” Microsoft said in a security advisory, published Monday. IDG News Service, 07/07/2008.

Microsoft advisory

US-CERT advisory

Four Microsoft patches due Tuesday; not rated critical

Microsoft will release four security patches for its Windows, Exchange and SQL products next Tuesday, all rated “important.” The Exchange and SQL flaws are “Elevation of Privilege” bugs, meaning that an attacker could theoretically exploit them to get administrative access to a PC. One of the Windows flaws is labeled a “spoofing” bug, meaning that it could help hackers trick the user into doing things like visiting malicious Web sites. IDG News Service, 07/03/2008.

Microsoft advanced advisory

**********

Opera patches multiple bugs in flagship browser

Opera Software ASA patched the newest version of its flagship browser for the first time yesterday when it released Opera 9.5.1 to fix several flaws. The update patches bugs in the Windows, Mac OS X and Linux editions, said Opera in notes posted to its Web site. Computerworld, 07/03/2008.

Opera 9.5.1 change log

**********

Critical vulnerability found in popular VLC media player

Danish security company Secunia has found a flaw in the VLC media player that could allow an attacker to gain control of someone’s PC. The problem, which Secunia ranks as “highly critical,” affects version 0.8.6h on Windows. Secunia said in an advisory that version 0.8.6i should be released soon. IDG News Service, 07/03/2008.

Secunia: VLC Media Player WAV Processing Integer Overflow

**********

10 new patches from Mandriva:

gnome-screensaver (clipboard disclosure)

squid (denial of service)

sympa (denial of service)

phpMyAdmin (multiple flaws)

xine-lib (input validation, code execution)

PHP updates by Mandriva version:

Corporate 4.0

Corporate 3.0, Multi Network Firewall 2.0

2008.1

2008.0

2007.1

**********

Three new fixes from Debian:

pcre3 (buffer overflow, code execution)

wordpress (multiple flaws)

sympa (denial of service)

**********

Today’s malware news

Cue the fireworks, Storm makes 4th return

As predicted, hackers tried to trick users into downloading the Storm bot on Friday by unleashing a flood of Independence Day spam bearing links to malicious sites, several security companies reported. Computerworld, 07/05/2008.

F-Secure details the attack

SQL attacks lob onto tennis association Web site

Visitors to the Association of Tennis Professionals Web site have potentially been infected with spyware after apparent lax security allowed a malicious script to be injected across its pages. The SQL injection attack acts as a conduit for spyware and Trojans to be downloaded to victims’ machines. Computerworld, 07/04/2008.

**********

From the interesting reading department:Clothes don’t make this man: Sweatshirt helps nail Citibank card scammer

A bank-card scammer using stolen Citibank account numbers and PINs netted hundreds of thousands of dollars, but was caught because he didn’t spend enough on clothes, according to court documents. Network World, 07/03/2008.

Expect iPhone, Fourth of July scams, security firm says

Apple Inc.’s launch of its new iPhone 3G will produce a flurry of spam and scams, a security company warned today. Computerworld, 07/03/2008.

ICANN blames June site hijack on registrar

The international organization that oversees the Web’s top-level domain naming system said that the hijacking last month of several of its domains was the result of a security breach at the registrar that manages those URLs. Computerworld, 07/07/2008.

Google gives away free Web-application security scanner

Google has released for free one of its internal tools used for testing the security of Web-based applications. IDG News Service, 07/03/2008.

Lithuania: Attacks focused on hosting company

A vulnerability in a Web server contributed to attacks on some 300 Web sites in Lithuania earlier this week, a computer security expert said on Friday. IDG News Service, 07/04/2008.

AVG fixes antivirus software skewing Web site statistics

Security company AVG is upgrading a component of its antivirus software so as not to place an undue traffic load on the Web sites it scans. IDG News Service, 07/07/2008.