* Patches from Adobe, IBM, Ubuntu, others * Storm worm strikes back at security pros * TJX data breach affected 94 million cards, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Adobe patches critical PDF vulnerability
Adobe patched its Reader and Acrobat programs today to fix a flaw that exposed most Windows XP users to exploits arriving in malicious PDF files. The patches are included in updates to Reader, the for-free PDF rendering utility, and Acrobat, Adobe’s full-featured application; both have been tagged as Version 8.1.1.
Also:
Attack PDF prowls for unpatched Adobe Reader, Acrobat
Russians behind attack PDFs, security researcher says
**********
IBM fixes four flaws in Notes e-mail, Domino server
IBM patched four vulnerabilities in its Notes and Domino e-mail software to plug holes that could be used to access information or infect systems with malicious code. Collectively ranked as “moderately critical” by Copenhagen-based bug tracker Secunia ApS, the four vulnerabilities involve Notes’ Internet Message Access Protocol (IMAP) service; its scripting language, LotusScript; the Domino server’s command console; and how both Notes and Domino map memory in Windows when they’re used in a shared environment such as Citrix.
Users can download the appropriate update from Lotus’ Upgrade Central.
Also:
Symantec advisory: Lotus Notes Memory Mapped Files Vulnerability
iDefense advisory: IBM Lotus Domino IMAP Buffer Overflow Vulnerability
**********
Cisco investigating DoS flaw in EAP protocol
Cisco is looking into a reported flaw in its Extensible Authentication Protocol (EAP) that could be exploited in a denial-of-service attack against devices running the protocol. Only a handful of access points are affected.
**********
Asterisk team warns of SQL injection bug in add-on
The cdr_addon_mysql add-on for the Asterisk open source PBX is vulnerable to SQL injection. Attackers could exploit this to view and corrupt data. A fix is available.
**********
Seven new patches from Ubuntu:
gnome-screensaver (authentication bypass)
OpenSSL (denial of service, code execution)
nagios-plugins (multiple flaws)
**********
Two new fixes from Debian:
xfce4-terminal (code execution)
reprepro (authentication bypass)
**********
Three new updates from Mandriva:
Tk (buffer overflow, code execution)
**********
Five new patches from Gentoo:
MLDonkey (authenication bypass)
OpenOffice.org (heap overflow, code execution)
**********
Today’s malware news:
Storm worm strikes back at security pros
The Storm worm is fighting back against security researchers that seek to destroy it and has them running scared, Interop New York show attendees heard Tuesday. Network World, 10/24/07.
**********
From the interesting reading department:
TJX data breach affected 94 million cards, banks allege
The TJX data breach affected more than 94 million credit and debit card accounts, more than twice the number acknowledged by the big retailer, a group of banks allege in a new court filing. TJX has previously acknowledged that 45.7 million card numbers were stolen in data breaches beginning in 2005. Network World, 10/24/07.
Phishers (almost) scam grocery giant out of $10 million
Apparently it’s not just unwary individuals that fall victim to online scammers. Even large corporations, it seems, can get suckered into parting with their money by devious phishers. Case in point: Eden Prairie, MN.-based grocery chain Supervalu Inc., which earlier this year got conned into depositing more than $10 million into two fraudulent bank accounts before recognizing the ruse. Details of the case are contained in court documents filed in connection with two forfeiture cases stemming from the incident. Computerworld, 10/22/07.
Malware on the rise as criminals target vulnerable firms
Malicious code that installs files such as Trojans, password stealers, keyboard loggers and other malware on users’ systems registered a fivefold increase in the first half of 2007, according to research released by Microsoft at the RSA Security conference in London. Computerworld, 10/23/07.
ActiveX File Overwrite/Delete Vulnerabilities
These days a new type of vulnerability is becoming more popular. It is an arbitrary file overwrite/delete vulnerability that can be exploited by attackers to overwrite or delete arbitrary files on an affected computer. These vulnerabilities exist particularly because of a registered ActiveX control failing to restrict which domains may load the control for execution. An attack exploiting this vuln can lead to arbitrary code execution by a remote attacker. Symantec Security Response blog, 10/23/07.
Hackers gain access to private hotel network using Cisco VoIP
Two security experts at hacker conference ToorCon9 in San Diego this week hacked into their hotel’s corporate network using a Cisco VoIP phone. Cisconet blog, 10/22/07.




