* Patches from Microsoft, Gentoo, Ubuntu, others * Storm Gets Cute * Mobile VoIP - a privacy accident waiting to happen?
endif; ?>In last Thursday’s newsletter, we had a link to a story about Commerce Bank customer records accessed by hackers. Neither the newsletter or the story said which Commerce Bank, but a reader forwarded us this link, which points out that it was a bank in Kansas. Just FYI for those who may use a Commerce Bank and were worried.
The reader also said: “I think I will go back to cash.”
Today’s bug patches and security alerts:
Critical Oracle patches coming next week
Oracle will release security updates for its products next week fixing 51 vulnerabilities in its products. Included in the Critical Patch Update, set to be released Tuesday, will be critical updates for the company’s flagship Oracle Database. Twenty-seven database bugs will be fixed, but five of the bugs can be “exploited over a network without the need for a username and password,” Oracle said in a note on next week’s patches. IDG News Service, 10/12/07.
**********
Microsoft to fix URI security flaw after criticism
Microsoft plans to fix a bug in the Windows operating system that has been blamed for a handful of critical vulnerabilities in Windows software. IDG News Service, 10/11/07.
Word exploit loose, according to Microsoft, Symantec
Security researchers spotted an attack yesterday that exploits a vulnerability in Microsoft Word patched just the day before. On Wednesday, Symantec Corp. reported it had obtained a suspicious Word document that crashed every version of the application except the newest, Word 2007, when opened. After it examined the document, Symantec found that the document included shell code and three pieces of malware. Computerworld, 10/11/07.
**********
Five new patches from Gentoo:
T1Lib (buffer overflow, code execution)
X Font Server (multiple flaws)
SKK Tools (non-secure temporary files)
**********
Four new updates from Ubuntu:
hplip (buffer overflow, code execution)
Tk (buffer overflow, code execution)
xen-3.0 (user validation, code execution)
**********
Four new fixes from rPath:
initscripts (password disclosure)
util-linux (privilege escalation)
xen (privilege escalation, code execution)
elinks (information disclosure)
**********
Three new patches from Foresight Linux:
OpenSSL (buffer overflow, code execution)
**********
Today’s malware news:
After a few weeks of low activity from the Storm gang they restarted their activities earlier this week. The mails and website were the same as from September but yesterday they changed the e-mail messages and also the website. F-Secure blog, 10/12/07.
An unknown group has caused quite a hassle by publicly posting information about tens of thousands of user accounts. F-Secure blog, 10/13/07.
**********
From the interesting reading department:
Mobile VoIP – a privacy accident waiting to happen?
I was surprised to find a couple of things. Firstly, despite the security features supported by my handset, the SIP call setup dialog was completely unencrypted. Secondly, so was the audio! And thirdly, so was the text messaging functionality. On top of this, I was quite surprised by the fact that the “user agent” header included my (globally unique) wireless hardware address! Symantec Security Response blog, 10/11/07.




