* Patches from Apple, Microsoft, Cisco, others * FBI warns of Valentines Day Storm Worm virus * Blended security threats on the rise, and other interesting reading
What a busy week for security and system adminstrators: Apple has released an 11-patch update for Mac OS X 10.5 (Leopard), Micrososft also dropped 11 updates for everything from Windows to Microsoft Works, and Cisco has two fixes related to its Unified Communications platform. If that isn’t enough, today’s Valentine’s Day holiday is providing fodder for the Storm Worm authors.
Patches keep coming as Apple fixes OS X security bugs
The latest security updates fix a 11 of bugs in the Mac Operating system, including eight bugs in the recently released Mac OS X 10.5, known as “Leopard.” Apple released the security fixes in conjunction with an 10.5.2 update to Leopard, which includes dozens of other updates. IDG News Service, 02/12/08.
US-CERT advisory: Apple Updates for Multiple Vulnerabilities
New QuickTime bugs crawl into the open
A security researcher today revealed new and unpatched bugs in the Windows version of Apple Inc.’s QuickTime, just a week after the company plugged a hole known for nearly a month. Computerworld, 02/13/08.
**********
Microsoft releases massive set of security updates
Microsoft released 11 security updates Tuesday fixing critical flaws in its products, including a publicly known ActiveX bug that affects users of the Visual FoxPro database. In total, 17 individual software flaws were patched in the updates. Microsoft rates six updates as critical, meaning they should be installed as soon as possible, while the remaining five updates are considered “important.” Last month was an easier month on IT administrators, when Microsoft released just two updates. IDG News Service, 02/12/08.
Microsoft advisories:
Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution
Vulnerability in OLE Automation Could Allow Remote Code Execution
Vulnerability in Microsoft Word Could Allow Remote Code Execution
Cumulative Security Update for Internet Explorer
Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution
Vulnerability in Microsoft Office Could Allow Remote Code Execution
Vulnerability in Active Directory Could Allow Denial of Service
Vulnerability in Windows TCP/IP Could Allow Denial of Service
Vulnerability in Internet Information Services Could Allow Elevation of Privilege
Vulnerability in Internet Information Services Could Allow Remote Code Execution
Vulnerabilities in Microsoft Works File Converter Could Allow Remote Code Execution
Related:
Attack code posted for Microsoft Works bug
**********
Cisco warns of flaws in IP phones
According to an advisory from Cisco, “Cisco Unified IP Phone models contain multiple overflow and denial of service (DoS) vulnerabilities. There are workarounds for several of these vulnerabilities. Cisco has made free software available to address this issue for affected customers.”
Cisco patches SQL injection flaw in Unified Communication Manager
According to Cisco: “Cisco Unified Communications Manager is vulnerable to a SQL Injection attack in the parameter key of the admin and user interface pages. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database.” A free update is available.
**********
Attacks aimed at Adobe Reader, Acrobat flaws intensify
The flaws disclosed last week in Adobe System’s Reader and Acrobat programs have been used to exploit computers since at least January via malicious banner advertisements, security analysts are reporting. IDG News Service, 02/11/08.
US-CERT advisory: Adobe Reader and Acrobat Vulnerabilities
**********
Four new patches from Gentoo:
Gnumeric (integer overflow, code execution)
Horde IMP (authentication bypass)
**********
Ten new updates from Debian:
MPlayer (buffer overflows, code execution)
nagios-plugins (multiple flaws)
Linux-2.6 (missing access check)
Simple DirectMedia Layer 1.2 (multiple flaws)
tk8.4 (buffer overflow, code execution)
tk8.3 (buffer overflow, code execution)
**********
Two new fixes from Mandriva:
**********
Five new patches from rPath:
Simple DirectMedia Layer (multiple flaws)
tk (buffer overflow, code execution)
**********
Today’s malware news:
FBI warns of Valentines Day Storm Worm virus
The FBI and the Internet Crime Complaint Center today said that with the Valentine’s Day holiday approaching, users should be on the lookout for spam e-mails spreading Storm Worm malware. Network World Layer 8 blog, 02/11/08.
Symantec Security Response blog: Same Storm, Different Day
F-Secure: Storm Has Sent Their Cupids
SecureWorks: Ozdok/Mega-D Trojan Analysis
Enabled by some spam samples Marshal provided, Joe Stewart and the good folks @SecureWorks, with an assist from Team Cymru and my|NetWatchman, have identified the malware and botnet referred to as Mega-D. It turns out Mega-D is composed of bots from the little-known Ozdok malware family. Arbor Networks Security to the Core blog, 02/11/08.
Trojan.Pandex — Doing More Than Spamming
Trojan.Pandex was first found in early 2007 and is a Trojan that is primarily used to send spam. Obviously the author has more ambition than to stick with simply spamming because we’ve observed the Trojan enhancing its functions continuously over the past month or so. Symantec Security Response blog, 02/13/08.
**********
From the interesting reading department:
Blended security threats on the rise, IBM says
The number of malware code samples in the wild grew 30% to 410,000 in 2007, according to security researchers at IBM’s ISS division. The Storm Worm, in particular, accounted for 13% of the entire malware collection. Network World, 02/12/08.
Network threats develop ‘antibiotic’ resistance
Looking at how malware has evolved over time, you can see many of the same effects we see in nature. Network World, 02/12/08.
Encryption could make you more vulnerable, warn experts
The use of data encryption could make organizations vulnerable to new risks and threats, a panel of security experts warned today. TechWorld, 02/08/08.
Emperor Entertainment Group Web Site Hacked
Emperor Entertainment Group: From sex photo scandal to Web site being hacked, key word: protect the data on your hard drive. It’s probably not the best way to advertise privacy protection, but it’s indeed something that should ring a bell for those who leave their portable devices unattended or unsecured. Symantec Security Response blog, 02/12/08.
Microsoft pushes out Vista SP1 prerequisites on Patch Tuesday
Along with the monster patch batch it issued yesterday, Microsoft also prepared Windows Vista users with what it said are the last two prerequisite updates they’ll need before they can download Service Pack 1 (SP1) next month. Computerworld, 02/13/08.
CA: Mobile devices safer than previously thought
Mobile devices are not that dangerous in terms of malware, claims IT management solutions provider CA. CIO, 02/11/08.
Russia becomes spam superpower
Russia might be a country trying to regain superpower status, but it has already reached it in one less welcome area — the amount of spam it sends to the world.
Our malware detections continue to grow at a quick pace. But by how much? F-Secure blog, 02/12/08.




