Apple ‘fixes’ causing problems

Opinion
Nov 26, 20073 mins

* Once-fixed bug pops up again in Leopard's Mail * New QuickTime bug opens XP, Vista to attack

Apple might be suffering from a little post-Thanksgiving indigestion as a new bug in QuickTime is cauing problems for Windows XP and Vista users. And an older bug has reappeared in Leopard’s Mail application, which could be used to run malware on an unsuspecting user’s machine. Apple’s not alone: rPath, Debian, Mandriva and Gentoo all have multiple patches out.

Today’s bug patches and security alerts:

Once-fixed bug pops up again in Leopard’s Mail

Apple Inc. reintroduced a critical vulnerability in Leopard, the newest version of Mac OS X, that it patched more than 20 months ago in Tiger, security experts said this week. A bug in Apple Mail — the e-mail client included in Mac OS X — that Apple fixed on March 1, 2006 in Tiger has cropped up in Leopard, security researchers from Symantec Corp. and Intego Inc. said. Attackers can use the new-old vulnerability to hide malicious code in seemingly harmless file attachments and get Apple Mail to run the malware without warning the user, as it designed to do, said Symantec in a warning to customers of its DeepSight threat network. Computerworld, 11/23/07.

**********

New QuickTime bug opens XP, Vista to attack

Security researchers warn that attack code targeting an unpatched bug in Apple Inc.’s QuickTime has gone public, and added that in-the-wild attacks against systems running Windows XP and Vista are probably not far behind. There was no word as of Sunday whether the Mac OS X versions of the media player are also vulnerable. Computerworld, 11/25/07.

**********

Four new updates from rPath:

Kernel (multiple flaws)

flac (integer overflow, code execution)

PHP5 (multiple flaws)

Samba (code execution)

**********

Three new fixes from Debian:

Samba (code execution)

kdegraphics (buffer overflow, code execution)

cupsys (buffer overflow, code execution)

**********

Eight new patches from Mandriva:

cacti (SQL injection)

tetex (multiple flaws)

phpMyAdmin (multiple flaws)

CUPS (buffer overflow, code execution)

poppler (multiple flaws)

Kernel (multiple flaws)

net-snmp 5.4.1 (denial of service)

Samba (code execution)

**********

12 new updates from Gentoo:

Feynmf (non-secure temp files, file overwrite)

Net-SNMP (denial of service)

PCRE (multiple flaws)

Samba (code execution)

Perl (buffer overflow, code execution)

Link Grammar (buffer overflow, code execution)

teTeX (multiple flaws)

MySQL (denial of service)

Mozilla Thunderbird (multiple flaws)

VMware (multiple flaws)

Poppler, KDE (code execution)

Bochs (multiple flaws)

**********

Today’s malware news:

Trojan horse spreads quickly through Microsoft’s IM

A new Trojan horse that started to spread early Sunday via Microsoft Corp.’s instant messaging client has already infected about 11,000 PCs, a security company said today. Computerworld, 11/19/07.

Hackers jack Monster.com, infect job hunters

Monster.com confirmed Tuesday that it took down a portion of its online job search service after attackers hacked the site and used it to feed exploits to visitors. Computerworld, 11/20/07.