Patches by the wagon load

Opinion
Feb 14, 20086 mins

* Patches from Apple, Microsoft, Cisco, others * FBI warns of Valentines Day Storm Worm virus * Blended security threats on the rise, and other interesting reading

What a busy week for security and system adminstrators: Apple has released an 11-patch update for Mac OS X 10.5 (Leopard), Micrososft also dropped 11 updates for everything from Windows to Microsoft Works, and Cisco has two fixes related to its Unified Communications platform. If that isn’t enough, today’s Valentine’s Day holiday is providing fodder for the Storm Worm authors.

Patches keep coming as Apple fixes OS X security bugs

The latest security updates fix a 11 of bugs in the Mac Operating system, including eight bugs in the recently released Mac OS X 10.5, known as “Leopard.” Apple released the security fixes in conjunction with an 10.5.2 update to Leopard, which includes dozens of other updates. IDG News Service, 02/12/08.

Apple advisory

US-CERT advisory: Apple Updates for Multiple Vulnerabilities

New QuickTime bugs crawl into the open

A security researcher today revealed new and unpatched bugs in the Windows version of Apple Inc.’s QuickTime, just a week after the company plugged a hole known for nearly a month. Computerworld, 02/13/08.

Advisory from Laurent Gaffie

**********

Microsoft releases massive set of security updates

Microsoft released 11 security updates Tuesday fixing critical flaws in its products, including a publicly known ActiveX bug that affects users of the Visual FoxPro database. In total, 17 individual software flaws were patched in the updates. Microsoft rates six updates as critical, meaning they should be installed as soon as possible, while the remaining five updates are considered “important.” Last month was an easier month on IT administrators, when Microsoft released just two updates. IDG News Service, 02/12/08.

Microsoft advisories:

Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution

Vulnerability in OLE Automation Could Allow Remote Code Execution

Vulnerability in Microsoft Word Could Allow Remote Code Execution

Cumulative Security Update for Internet Explorer

Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution

Vulnerability in Microsoft Office Could Allow Remote Code Execution

Vulnerability in Active Directory Could Allow Denial of Service

Vulnerability in Windows TCP/IP Could Allow Denial of Service

Vulnerability in Internet Information Services Could Allow Elevation of Privilege

Vulnerability in Internet Information Services Could Allow Remote Code Execution

Vulnerabilities in Microsoft Works File Converter Could Allow Remote Code Execution

Related:

Attack code posted for Microsoft Works bug

**********

Cisco warns of flaws in IP phones

According to an advisory from Cisco, “Cisco Unified IP Phone models contain multiple overflow and denial of service (DoS) vulnerabilities. There are workarounds for several of these vulnerabilities. Cisco has made free software available to address this issue for affected customers.”

Cisco patches SQL injection flaw in Unified Communication Manager

According to Cisco: “Cisco Unified Communications Manager is vulnerable to a SQL Injection attack in the parameter key of the admin and user interface pages. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database.” A free update is available.

**********

Attacks aimed at Adobe Reader, Acrobat flaws intensify

The flaws disclosed last week in Adobe System’s Reader and Acrobat programs have been used to exploit computers since at least January via malicious banner advertisements, security analysts are reporting. IDG News Service, 02/11/08.

US-CERT advisory: Adobe Reader and Acrobat Vulnerabilities

**********

Four new patches from Gentoo:

scponly (multiple flaws)

Gnumeric (integer overflow, code execution)

Gallery (multiple flaws)

Horde IMP (authentication bypass)

**********

Ten new updates from Debian:

MPlayer (buffer overflows, code execution)

nagios-plugins (multiple flaws)

Linux-2.6 (missing access check)

Simple DirectMedia Layer 1.2 (multiple flaws)

WML (denial of service)

tk8.4 (buffer overflow, code execution)

tk8.3 (buffer overflow, code execution)

Iceweasel (multiple flaws)

Icedove (multiple flaws)

Xulrunner (multiple flaws)

**********

Two new fixes from Mandriva:

Kernel (multiple flaws)

Kernel (multiple flaws)

**********

Five new patches from rPath:

boost (denial of service)

Simple DirectMedia Layer (multiple flaws)

tk (buffer overflow, code execution)

openldap (denial of service)

Kernel (multiple flaws)

**********

Today’s malware news:

FBI warns of Valentines Day Storm Worm virus

The FBI and the Internet Crime Complaint Center today said that with the Valentine’s Day holiday approaching, users should be on the lookout for spam e-mails spreading Storm Worm malware. Network World Layer 8 blog, 02/11/08.

Symantec Security Response blog: Same Storm, Different Day

F-Secure: Storm Has Sent Their Cupids

SecureWorks: Ozdok/Mega-D Trojan Analysis

Enabled by some spam samples Marshal provided, Joe Stewart and the good folks @SecureWorks, with an assist from Team Cymru and my|NetWatchman, have identified the malware and botnet referred to as Mega-D. It turns out Mega-D is composed of bots from the little-known Ozdok malware family. Arbor Networks Security to the Core blog, 02/11/08.

Trojan.Pandex — Doing More Than Spamming

Trojan.Pandex was first found in early 2007 and is a Trojan that is primarily used to send spam. Obviously the author has more ambition than to stick with simply spamming because we’ve observed the Trojan enhancing its functions continuously over the past month or so. Symantec Security Response blog, 02/13/08.

**********

From the interesting reading department:

Blended security threats on the rise, IBM says

The number of malware code samples in the wild grew 30% to 410,000 in 2007, according to security researchers at IBM’s ISS division. The Storm Worm, in particular, accounted for 13% of the entire malware collection. Network World, 02/12/08.

Network threats develop ‘antibiotic’ resistance

Looking at how malware has evolved over time, you can see many of the same effects we see in nature. Network World, 02/12/08.

Encryption could make you more vulnerable, warn experts

The use of data encryption could make organizations vulnerable to new risks and threats, a panel of security experts warned today. TechWorld, 02/08/08.

Emperor Entertainment Group Web Site Hacked

Emperor Entertainment Group: From sex photo scandal to Web site being hacked, key word: protect the data on your hard drive. It’s probably not the best way to advertise privacy protection, but it’s indeed something that should ring a bell for those who leave their portable devices unattended or unsecured. Symantec Security Response blog, 02/12/08.

Microsoft pushes out Vista SP1 prerequisites on Patch Tuesday

Along with the monster patch batch it issued yesterday, Microsoft also prepared Windows Vista users with what it said are the last two prerequisite updates they’ll need before they can download Service Pack 1 (SP1) next month. Computerworld, 02/13/08.

CA: Mobile devices safer than previously thought

Mobile devices are not that dangerous in terms of malware, claims IT management solutions provider CA. CIO, 02/11/08.

Russia becomes spam superpower

Russia might be a country trying to regain superpower status, but it has already reached it in one less welcome area — the amount of spam it sends to the world.

Up, Up and Away

Our malware detections continue to grow at a quick pace. But by how much? F-Secure blog, 02/12/08.