* Patches from rPath, FreeBSD, Ubuntu, others * Hillary Clinton spam sighted in the wild * With racy name, bug-finder gets no credit from Microsoft, and other interesting reading
Firefox and Opera are both under fire as security researchers at Vexillium have found a flaw that could allow attackers to capture a users’ Web history. No word on updates yet, but be on the lookout. We’ve also got pairs of patches from rPath, FreeBSD, Ubuntu, Debian, Mandriva and Gentoo.
Opera, Firefox bug could export users’ Web history
A flaw in the way the Firefox and Opera browsers handle an image file could allow an attacker to see what Web sites a person has visited. The problem concerns how the two browsers handle a “.BMP,” or bitmap, image file, according to an advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem. IDG News Service, 02/18/08.
Vexillium: FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak
**********
Two new updates from rPath:
mailman (cross-scripting attack)
**********
Two new patches from FreeBSD:
sendfile (information disclosure)
**********
Two new fixes from Ubuntu:
**********
Two new updates from Debian:
nagios-plugins (buffer overflows)
**********
Two new patches from Mandriva:
xine-lib (buffer overflow, code execution)
**********
Two new fixes from Gentoo:
Pulseaudio (code execution, privilege escalation)
**********
Today’s malware news:
Hillary Clinton spam sighted in the wild
The Hillary Clinton election campaign is being exploited in a spam message that tries to trick users into downloading a Trojan to their desktops by pretending to offer a link to a video of a Hillary Clinton campaign speech. “It’s the first time we’ve seen spam like this targeting Hillary Clinton,” says Doug Bowers, Symantec’s senior director of anti-abuse engineering, who says the spam message, still not seen in large volumes, was first spotted today. Network World, 02/14/08.
Symatec Security Response blog: You Know it’s Election Year When…
**********
From the interesting reading department:
With racy name, bug-finder gets no credit from Microsoft
When a hacker going by the name Chujwamwdupe published attack code that exploited a recently patched bug in Microsoft Office 2003 earlier this week, it looked almost as if he were publishing the software out of spite. IDG News Service, 02/15/08.
Harvard Web site hacked, database on file-sharing site
One of Harvard University’s Web sites appeared on Monday to have been hacked, with its contents appearing on the BitTorrent file-sharing network. IDG News Service, 02/18/08.
Replicating virtual servers vulnerable to attack
Black Hat presentation details man-in-the-middle exploits can endanger data, availability of resources. Network World, 02/15/08.
Google finds evil all over the Web
The Web is scarier than most people realize, according to research published recently by Google. The search engine giant trained its Web crawling software on billions of Web addresses over the past year looking for malicious pages that tried to attack their visitors. They found more than 3 million of them, meaning that about one in 1,000 Web pages is malicious, according to Neils Provos, a senior staff software engineer with Google.
Firefox 3.0’s malware blocker whacks access to popular add-on sites
The new Firefox 3.0 anti-malware tool that debuted last week in Beta 3 is blocking users from reaching the Web site for a popular add-on to the open-source browser. Another add-on site, blocked last week, has since been cleared. Computerworld, 02/18/08.




