* Patches from Mandriva, Debian, Microsoft, others * Storm and the NFL * Financially motivated malware thrives, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Apple updates iTunes security update
According to the Apple advisory, “A buffer overflow exists in iTunes when processing album cover art. By enticing a user to open a maliciously crafted music file, an attacker may trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing proper bounds checking.” Users should upgrade to iTunes 7.4 to fix the flaw.
**********
Four new updates from Mandriva:
MySQL (privilege escalation, denial of service)
eggdrop (buffer overflow, code execution)
krb5 (stack overflow, denial of service)
**********
Three new fixes from Debian:
librpcsecgss (buffer overflow, code execution)
krb5 (stack overflow, denial of service)
**********
Three more Kerberos 5 (krb5) updates
As reported last week: MIT advises, “The krb5 Kerberos administration daemon (kadmind) is vulnerable to a stack buffer overflow in the RPCSEC_GSS authentication flavor of the RPC library. Third-party applications using the RPC library provided with MIT krb5 may also be affected.”
New updates:
**********
Microsoft Patch Tuesday this week: Microsoft cooks up five patches
Microsoft on Tuesday plans to release five security updates targeting flaws in Windows, SharePoint, Visual Studio and Microsoft’s instant messaging clients. Of the five bulletins expected Sept. 11, only one will be labeled “critical,” Microsoft’s highest rating, although of the remaining four — all ranked “important” — two could result in remote code execution if successfully exploited. Details were spelled out in the prepatch notification that Microsoft posted Thursday morning. Computerworld, 09/06/07.
**********
Today’s malware news:
Today we started seeing new Storm mails and the web pages changed layouts completely. Now the theme is National Football League (NFL) which is timely considering the 2007 NFL season started on the 6th of September. F-Secure Antivirus Research Weblog, 09/09/07.
**********
From the interesting reading department:
Financially motivated malware thrives
Financially motivated malware attacks are on the rise, with automated software packages making it easy for unskilled hackers to earn a living by sending out spam, researchers at messaging security vendor Secure Computing say. Network World, 09/06/07.
E-Greeting Card Giant Unaffected By Storm Worm
It’s been nearly three weeks since I first wrote about the Storm worm authors using fake online greeting cards to trick people into clicking on links to Web sites that try to download and install malicious software. Since then, it looks like the Storm worm authors have adopted a number of other ruses, but they don’t appear to have abandoned the greeting card scam. So I phoned American Greetings, which owns without a doubt the biggest e-greetings company around. According to AG spokesperson Frank Cirillo, the incessant attacks have had little measurable impact on the company’s click-through rates. Security Fix blog, 09/06/07.




