* Patches from Mozilla, Apple, Trustix, others * Virus comes back from dead on German laptops * New Crimeware Stat, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Mozilla slaps temp patch on Firefox
Mozilla on Tuesday took another swat at a pesky vulnerability that eluded their July 17 patch. The problem, which is related to a known QuickTime vulnerability that also remains unpatched, was first reported more than a year ago. Users should upgrade to Firefox 2.0.0.7 if they haven’t been automatically updated already. Computerworld, 09/18/07.
**********
Yahoo Messenger hit with ninth zero-day exploit of the year
Attack code that targets Yahoo Messenger has been published on the Internet, a security researcher warned today, marking the ninth exploit aimed at the popular instant messaging software so far this year. In a posting to the milw0rm.com Web site, someone identified as “shinnai” disclosed malicious Visual Basic code that allegedly lets attackers feed any file to users of the latest version of Messenger. The exploit code successfully executes on a fully-patched PC running Windows XP SP2, shinnai said, although the effect depends on the security settings of Internet Explorer (IE).
**********
Hacker publishes notorious Apple Wi-Fi attack (finally)
More than a year after claiming to have found a way to take over a Macintosh computer using a flaw in the system’s wireless card, David Maynor has published details of his exploit. Computerworld, 09/18/07.
**********
Trustix releases new ‘multi’ update
A new master patch from Trustix fixes flaws in apache, clamav, kerberos5, php, rsync, tar and vim. The most serious of the flaws could be exploited to run malicious code on an affected system.
**********
Four new patches from rPath:
OpenOffice.org (buffer overflow, code execution)
**********
Four new updates from Ubuntu:
t1lib (buffer overflow, code execution)
X.org (buffer overflow, code execution)
Qt (buffer overflow, denial of service)
**********
Two new fixes from Mandriva:
**********
Four patches from Gentoo:
Poppler (multiple buffer overflows)
PhpWiki (authentication bypass)
**********
Today’s malware news:
Virus comes back from dead on German laptops
A virus thought to have died out years ago is believed to have infected up to 100,000 laptops during manufacture by German vendor Medion International. The exact number of systems affected by the Stoned.Angelina virus is not known, but the consignment of between 10,000 and 100,000 Medion laptops was destined for sale in Danish and German outlets of European retailing giant Aldi. Computerworld, 09/17/07.
**********
From the interesting reading department:
New Crimeware Stats
Bots, Trojan Horses and Denial of Service (DOS) are the top three malicious attack types being picked up in the wild by security vendors, according their recent reports. Network World, 09/19/07.
Hackers leak antipiracy vendor’s e-mails to Net
More than 6,000 e-mail messages detailing plans by MediaDefender to flood peer-to-peer networks with fake music and movie files — and to create a fake site that could be used to snare pirates — have leaked onto the Internet. Computerworld, 09/17/07.
Trend Micro security gurus look for better ways to classify malware
Two senior security veterans from Trend Micro are trying to get the industry to change how it classifies malicious software. They argue that today’s classification system, which tends to focus on the technical way the software works, neglects a far more important metric that matters more to users: how it tries to steal your money. IDG News Service, 09/19/07.
Fear of insider threats hits home
The more money that companies spend on securing their IT operations from external attack, the more it seems they become aware that the potential threat posed by their own employees remains their most significant risk. InfoWorld, 09/19/07.
Symantec: Bank account details fetch $400 online
Stolen bank account numbers are commanding the highest price in an underground trade of personal details stolen by hackers, according to a survey released Monday by security vendor Symantec. IDG News Service, 09/17/07.
Hackers milk massive increase in browser plug-in bugs
Hackers loosed a record number of malicious code threats in the first six months of 2007, Symantec Corp. said today, with the most dangerous targeting vulnerabilities in browser plug-ins — the weak link in Web 2.0.
Malware becoming more sophisticated, warns IBM
IBM has reported an increase in malware volume and sophistication as part of its security statistics report for the first half of the year. Computerworld, 09/17/07.




