Microsoft readies a Patch Tuesday Dozen

Opinion
Feb 11, 20084 mins

* Patches from Mozilla, Mandriva, Debian, others * Mayday, Mayday, a Botnet is Here * 'Anonymous' group declares online war on Scientology , and other interesting reading

Big week for Windows administrators as Microsoft is readying a dozen patches for its various operating systems and software packages. Seven of the 12 updates are critical in nature. Security staff should also be on the lookout to make sure all machines running Firefox have downloaded the latest update, which fixes three critical flaws.

Microsoft readying slew of critical updates for Patch Tuesday

After kicking off 2008 with just two security updates in January, Microsoft plans to release one of its largest bundles of patches ever this Tuesday. The critical updates are for Microsoft’s Windows operating system, Internet Explorer and the company’s Office software, all of which are frequent targets of hackers. Here’s how they break down: Two of the critical updates are for Windows, and there is one update each for Internet Explorer, Office, Office Publisher and Microsoft Word. A critical update is also being readied for the VBScript and JScript scripting languages used by Internet Explorer. IDG News Service, 02/07/08.

**********

Mozilla patches three critical Firefox flaws

Mozilla issued 10 patches on Friday for its Firefox browser, including three for critical vulnerabilities. The latest version of Firefox is now 2.0.0.12. IDG News Service, 02/08/08.

Mozilla advisories

Web browsing history and forward navigation stealing

Privilege escalation, XSS, Remote Code Execution

Crashes with evidence of memory corruption

**********

New iPhone and iPod touch Safari exploit discovered

It looks like there’s another iPhone / touch exploit out there lurking on the unseen horizons of those device’s browsers. According to reports, a memory exploit — similar to the previously-patched TIFF exploit — has been discovered which affects units with firmware 1.0.2 all the way up to 1.1.3. Engadget, 02/07/08.

Bugtraq: Apple iPhone Mobile Safari Memory Exhaustion Remote Denial of Service Vulnerability

**********

MySpace Uploader ActiveX Exploited in the Wild

Yesterday our honeypots picked up a browser attack toolkit that I had not encountered before. This toolkit uses dynamic function and variable names and wraps its exploits in two levels of dynamic encoding. Finding a new toolkit on our honeypots always piques my interest as a new toolkit often yields new exploit payload. Symantec Security Response blog, 02/07/08.

**********

Six new patches from Mandriva:

Qt4 (certificate bypass)

Tk (buffer overflow)

SDL_image (buffer overflow, code execution)

netpbm (buffer overflow)

gd (buffer overflow)

libcdio (buffer overflow, denial of service)

**********

Two new fixes from Debian:

phpBB (multiple flaws)

libexif (multiple flaws)

**********

Two new updates from rPath:

Firefox (multiple flaws)

kernel (multiple flaws)

**********

Today’s malware news:

Mayday, Mayday, a Botnet is Here

A recent report indicates there is a newer, more sinister botnet that is setting itself up to surpass the Storm worm. Symantec Security Response blog, 02/06/08.

Antivirus company’s Web site downloads…a virus

The Web site for Indian antivirus vendor AvSoft Technologies has been hacked and is being used to install malicious software on visitors’ computers, security researchers said Thursday. IDG News Service, 02/08/08.

Pidief, the word for exploits?

There has been a recent report from SANS about PDF files (1.pdf and b.pdf) containing a newly patched Adobe Reader/Acrobat exploit being widely distributed. Symantec Security Response blog, 02/09/08.

**********

From the interesting reading department:

‘Anonymous’ group declares online war on Scientology

A mysterious anti-Church of Scientology group is using YouTube and other social networking sites to gather people for a day of action against the church. Computerworld, 02/08/08.

Microsoft’s Vista SP1 hits manufacturing

The release of Vista SP1 to manufacturing may mean more adoption by corporate users, say some IT executives. IDC analyst Al Gillen says it’s a small factor in implementation consideration. Users, many of whom expressed frustration that they have been waiting for this service pack for a while, can expect to see the service pack in mid-March or April. CIO, 02/07/08.

Web site of U.K. landmark hacked to serve malware

The Web site of one of the U.K.’s most famous landmarks, the Forth Road Bridge, has been torn open in embarrassing fashion to serve malware, researchers are reporting. TechWorld, 02/08/08.

Soccer league’s online shoppers get kicked by security breach

A series of SQL injection attacks on servers hosted by a third-party service provider has compromised the personal data of an unspecified number of individuals who had shopped on Major League Soccer’s MLSgear.com Web site. 02/08/08.