Not a good week for Apple

Opinion
Mar 20, 20086 mins

* Patches from Debian, Mandriva, Gentoo, others * Hannaford supermarket chain discloses data breach involving credit, debit cards, and other interesting reading

Apple may want to rethink that ad campaign that pokes at Microsoft’s numerous patches after this week’s deluge of patches. In all, over 100 fixes were released across three updates: 90 for the Leopard OS, 13 for Safari and one for Apple’s 802.11n base station. VMWare, Asterisks and MIT Kerberos also have multiple updates today.

Apple issues mega-monster security update

Apple Tuesday issued a record-breaking security update that patched nearly 90 vulnerabilities in both its own code and the third-party applications it bundles with its Tiger and Leopard operating systems. Computerworld, 03/19/08.

Apple’s Security Update 2008-002

Apple updates Safari browser, busts 13 bugs

Apple Inc. today patched 13 vulnerabilities in Safari with an update that takes the browser to Version 3.1. Only one of the patched bugs carried Apple’s most dire warning — that the flaw could result in “arbitrary code execution.” Computerworld, 03/18/08.

Apple Safari 3.1 advisory

Apple updates AirPort Extreme Base Station

A new firmware update is out for Apple’s 802.11n AirPort Extreme Base Station. Firmware version 7.3.1 fixes an input validation flaw that could be exploited in a denial-of-service attack agaist the unit.

**********

VMware fixes security bugs

VMware has identified and fixed seven security bugs in the free version of its hypervisor, which could let hackers launch denial-of-service, change user privileges and forge RSA key signatures. Network World, 03/17/08.

VMWare advisory

Secunia: VMware Server Multiple Vulnerabilities

**********

Malicious subtitle file could trip up VLC media player

A flaw in the widely-used open-source VLC media player could allow an attacker to execute harmful code on a PC. The problem stems from a buffer overflow that can occur when the player processes subtitle files used for movies, according to a security advisory. IDG News Service, 03/18/08.

SecurityVulns advisory

**********

Two flaws found in Kerberos 5

MIT is advising users of two flaws found in its Kerberos 5 network authentication protocol. Both flaws could be used in a denial-of-service attack against an affected system and there’s a slight chance malicious code could be run as well. Patches are available.

MIT advisories:

MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc

MITKRB5-SA-2008-002: array overrun in RPC library used by kadmin

Two Linux vendors are already out with related patches:

Ubuntu: Kerberos vulnerabilities

Debian: krb5

**********

Multiple flaws in Asterisk patched

According to a Secunia advisory, “Some vulnerabilities have been reported in Asterisk, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.” Patches are available.

Asterisk advisories:

AST-2008-005: HTTP Manager ID is predictable 

AST-2008-004: Format String Vulnerability in Logger and Manager

AST-2008-003: Unauthenticated calls allowed from SIP channel driver

AST-2008-002: Two buffer overflows in RTP Codec Payload Handling

**********

Nine new updates from Debian:

ikiwiki (cross-scripting flaw)

unzip (code execution)

lighttpd (file disclosure)

Smarty (function execution)

Horde3 (file execution)

backup-manager (password disclosure)

ldapscripts (password disclosure)

Dovecot (privilege escalation)

icedove (multiple flaws)

**********

Two new fixes from Mandriva:

unzip (invalid pointer, code execution)

Nagios (multiple flaws)

**********

Six new patches from Gentoo:

MoinMoin (multiple flaws)

Adobe Acrobat Reader (non-secure temp files)

Dovecot (multiple flaws)

PCRE (buffer overflow, code execution)

Website META Language (non-secure temp files)

LIVE555 Media Server (denial of service)

**********

From the interesting reading department:

Hannaford supermarket chain discloses data breach involving credit, debit cards

Portland, Maine-based supermarket chain Hannaford Brothers Monday disclosed it has suffered a data intrusion into its computer network that has resulted in the theft of customer credit and debit card numbers. (EEK! I’ve shopped at Hannaford stores from time to time!) Network World, 03/17/08.

Pennsylvania pulls plug on voter site after data leak

With voting in Pennsylvania’s presidential primary just a month away, the state was forced to pull the plug on a voter registration Web site Tuesday after it was found to be exposing sensitive data about voters in the state. IDG News Service, 03/19/08.

Hackers hijacking routers and blackmailing firms to regain access

A Cisco engineer is warning of scams by hackers who hijack routers and blackmail companies to regain access. Cisco Subnet, 03/18/08.

Spammers Exploit the Tax Season

We have observed spammers disguising themselves as the IRS and dangling an offer of a tax refund to unwitting recipients. That is, a refund made available once you input your credit card information into their site. Symantec Security Response blog, 03/17/08.

DSL Reports under DDoS

DSL reports had been disabled by a DDoS attack. The site was back online within a few hours, with site owner Justin providing some information. No motivations are immediately visible, however DSL reports operates a large, informative pool of forums and helps their community stay secure and online. It’s entirely possible that someone is just upset at their efforts. Arbor Networks Security to the Core blog, 03/19/08.

Hackers vs. Windows, Mac, Linux next week in big-money contest

The security conference that last year made headlines with a hacking challenge whose winner walked away with a $10,000 prize will reprise the contest next week — this time with more money at stake, the contest’s organizer said today. Computerworld, 03/19/08.

State agency moves to plug USB flash drive security gap

Security officials are issuing USB flash drives to workers in the state of Washington’s Division of Child Support as part of a new security procedure established to eliminate the use of non-approved thumb drives by workers collecting and transporting confidential data. Computerworld, 03/17/08.

Security vendor Lockdown goes belly up

Network access control start-up Lockdown Networks has shut down operations, becoming another in what has become a string of vendors floundering in the network access arena. Network World, 03/19/08.

Big-money bug broker gives up, frustrated by red tape

A bug broker who claimed he got as much as $200,000 for an exploit closed shop this weekend because buyers took so long to evaluate the vulnerabilities that in some cases the bugs were patched and deals made moot. Computerworld, 03/17/08.

Millennial Workforce: IT Risk or Benefit?

We went out and commissioned a study with Applied Research-West to measure IT risk issues surrounding the emerging millennial workforce within companies. Our goal was to measure millennial workers’ perceptions and expectations regarding their use of new devices and Web 2.0 applications in the workplace, and to compare those results with their older coworkers’ responses as well in order to gauge the IT crowd’s perception of this issue. Symantec Security Response, 03/19/08.