* Patches from rPath, Gentoo, Debian * Malicious PDF files being spammed out in volume * Immediate flaw alerts vs. Disclosing with patches, and other interesting reading
Today’s malware news:
Malicious PDF files being spammed out in volume
Malicious PDF file (report.pdf or debt.2007.pdf or overdraft.2007.10.26.pdf or so) has been massively spammed through e-mail. The PDF is spiced with CVE-2007-5020 exploit that downloads ms32.exe that downloads more components. F-Secure Antivirus Research blog, 10/26/07.
Guess we may have to update our IT Graveyard slideshow….
Storm worm can befuddle NAC
A newly discovered capability of the Storm worm could invalidate results churned out by NAC products, attendees at Interop New York learned last week. Network World, 10/25/07.
Most of the day-to-day malware that we currently analyze has a financial motive. Such malware typically doesn’t do anything noticeably malicious as it doesn’t want to tip-off the victim. But every now and then, we see something that’s just plain nasty. F-Secure Antivirus Research blog, 10/25/07.
**********
Today’s bug patches and security alerts:
Three new updates from rPath:
cpio / tar (denial of service, code execution)
**********
Four new fixes from Gentoo:
Sylpheed / Claws Mail (format string, code execution)
HPLIP (privilege escalation, code execution)
**********
Two new patches from Debian:
xen-utils (non-secure temp files)
**********
From the interesting reading department:
Immediate flaw alerts vs. Disclosing with patches
What’s safer, knowing there’s a gaping hole that can be exploited in a software product even when there is no patch for it, or being told about the gaping hole once there is a patch? Network World, 10/26/07.
Mystery of RealPlayer exploit, hijacked ad server unfolds
A week after Symantec security researchers traced the elaborate course of a malware exploit — apparently devised in the Netherlands — to what may be a compromised ad server belonging to Internet advertising company 24/7 Real Media, the attack method isn’t fully understood. Network World, 10/25/07.
Firefox Update Plugs 8 Security Holes
Mozilla has shipped an update to its Firefox Web browser that corrects at least eight separate security flaws, including two that Mozilla flagged as especially serious. Firefox users should have already received an update that brings the browser to version 2.0.0.8. Security Fix blog, 10/25/07.
These days, many people take it for granted that their e-mail is secure. People (and companies) send all kinds of critical information through e-mail, expecting it to make it to the correct person and only that person. That’s a bad assumption. Symantec Security Response blog, 10/25/07.
Security deadline missed by one-third of Visa merchants
Just over a third of large-volume Visa merchants failed to meet a Sept. 30 deadline to comply with the Payment Card Industry’s 12-part Data Security Standard, Visa said yesterday, and those companies are facing fines of $25,000 per month. Network World, 10/25/07.
Austrian police to use crime-busting Trojans
The Austrian Police has become the latest European agency to express its intention to use specially-crafted Trojans to remotely monitor criminal suspects. Network World, 10/25/07.
A couple of weeks ago in this blog entry, we learned how misleading applications advertise themselves on the Web. Now we’ll take a closer look at the other side of things to see how misleading applications infiltrate users’ machines in order to convince people to download and purchase them. Symantec Security Response blog, 10/26/07.
Microsoft now admits to WSUS update error
On the same day it tried to refute reports that enterprise customers’ PCs were being force-fed the Windows XP desktop search tool, Microsoft Corp. did a turnabout and admitted it had messed up. Computerworld, 10/26/07.
Advance fee scams target cash-strapped consumers
Authorities are warning of yet another scam targeting online loan applicants. This time it’s an advance fee loan scheme involving MortgageTree Lending, a company that is finding plenty of victims online. PC World, 10/25/07.
Editor’s note: Starting the week of Nov. 12, subscribers to the HTML version of this newsletter will notice some enhancements to the layout that will provide you with easier and clearer access to a wider range of resources at Network World. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.




