Microsoft’s plethora of patches

Opinion
Mar 13, 20085 mins

* Patches from Microsoft, Cisco, Gentoo, others * Password-stealing hackers infect thousands of Web pages * Mozilla adds 900 fixes and upgrades Firefox 3 beta, and other interesting reading

Over the past few newsletters, I mentioned calm before the storm. Well, the storm arrived this week. Microsoft’s Patch Tuesday delivered a series of updates for the Office Suite on Windows, plus the company released an update for Mac Office 2008 that includes some security enhancements. And, if that weren’t enough, a prominent security researcher is warning of a new Internet Explorer FTP flaw and there’s a bug in Microsoft Home Server that won’t be patched until June. Also this week, Cisco released a patch for its Secure Access Control Server.

Microsoft’s Patch Tuesday is an all-Office affair

Microsoft’s monthly Patch Tuesday focused entirely on Office, and most notably Excel, with four critical patches, including one that could allow a hacker to hijack a user’s e-mail. Of the 11 vulnerabilities contained in the four patches, nine of them addressed Excel, including a zero-day exploit that has been around since January. Network World, 03/11/08.

Microsoft advisories:

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution

Vulnerability in Microsoft Outlook Could Allow Remote Code Execution

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution

Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution

Related:

US-CERT advisory: Microsoft Updates for Multiple Vulnerabilities

Microsoft delivers first update for Mac Office 2008

Microsoft Corp. patched the latest version of Office for Mac yesterday to fix more than two-dozen problems, including a security snafu revealed just days after the suite was launched in mid-January. Computerworld, 03/12/08.

Microsoft advisory: Description of the Office 2008 for Mac 12.0.1 Update

Two years after patch, another IE FTP flaw

A flaw in the way Microsoft’s Internet Explorer browser processes FTP commands could let attackers steal or erase data from a victim’s FTP site. IDG News Service, 03/12/08.

Rapid7 advisory: Microsoft Internet Explorer FTP Command Injection Vulnerability

Microsoft to patch Home Server corruption bug – in June

Microsoft Monday said its engineers were still “heads down working” on the data corruption bug that has plagued Windows Home Server since late last year, but acknowledged that a fix wouldn’t be released until June at the earliest. Computerworld, 03/10/08.

Microsoft blog: An update on KB #946676

**********

Cisco patches Access Control Server

Cisco is reporting two flaws in its Cisco Secure Access Control Server (ACS) for Windows User-Changeable Password. The first is a buffer overflow that could be exploited to run malicious code and the second is a cross-scripting attack that could be remotely exploited. A patch for both flaws is available.

**********

Researcher posts attack code for RealPlayer bug

noted ActiveX researcher yesterday revealed a bug in RealNetworks’ RealPlayer that could be exploited by attackers to hijack Windows machines running Internet Explorer. Computerworld, 03/11/08.

Full Disclosure post: Real Networks RealPlayer ActiveX Control Heap Corruption

**********

Seven new patches from Gentoo:

Sarg (code execution)

International Components for Unicode (multiple flaws)

Apache (multiple flaws)

Cacti (multiple flaws)

PDFlib (buffer overflows, code execution)

MPlayer (buffer overflows, code execution)

phpMyAdmin (SQL injection)

**********

Three new updates from rPath:

dovecot (authentication bypass)

lighttpd (information disclosure)

dbus (privilege escalation)

**********

Two new fixes from Debian:

libnet-dns-perl (multiple flaws)

moin (multiple flaws)

**********

Today’s malware news:

Trojan.Trafbrush: Providing Click Fraud Services to Affiliates

My colleague, Takashi Katsuki, posted a blog that describes how Trojan.Farfli provides a service to affiliates, which allows them to increase the number of hits for an affiliate’s tracker. Recently I came across another Trojan, which provides such a service: Trojan.Trafbrush. Symantec Security Response blog, 03/12/08.

Password-stealing hackers infect thousands of Web pages

Hackers looking to steal passwords used in popular online games have infected more than 10,000 Web pages in recent days. IDG News Service, 03/12/08.

**********

From the interesting reading department:

Mozilla adds 900 fixes and upgrades Firefox 3 beta

Mozilla Tuesday released the latest beta of Firefox 3, including some 900 bug fixes and highlighting for users that it is for testing purposes only. On the security front, Mozilla has added malware protection to warn users about Trojans, viruses or spyware that a Web site may try to install. Network World, 03/11/08.

Cisco to patch routers on regular schedule

Following the lead of Microsoft and Oracle, Cisco will start releasing security patches for some of its products on a schedule. IDG News Service, 03/11/08.

Wi-Fi security still too complicated, expert claims

Although the 802.1x access protocol is a must for wireless network security, companies rarely use it and thus leave the door open for hackers, according to Robert Lamprecht, IT advisory supervisor at KPMG. IDG News Service, 03/12/08.

Insider threat highlighted at audit conference

The recent scandal at French bank Société Générale has again highlighted how vulnerable companies are against insider threats, speakers said Tuesday at the European Computer Audit Control and Security Conference in Stockholm. IDG News Service, 03/11/08.

BlackBerry servers ripe for the hacking

Many companies running BlackBerry Enterprise Server (BES) could be inadvertently opening a door to attackers, a penetration testing company has found. TechWorld, 03/10/08.

Rise in Gmail spam indicates more solved CAPTCHAs

Spam originating from Google’s Gmail domain doubled last month, indicating that spammers are still defeating the CAPTCHA, the distorted text used as a security test to thwart mass registration of e-mail accounts and other Web site abuse. IDG News Service, 03/10/08.

Security must evolve, CERT official says

Security has to evolve into something that supports business, rather than the other way around, according to Lisa R. Young, senior member of the technical staff at Carnegie Mellon University’s Computer Emergency Response Team. DG News Service, 03/10/08.