Mozilla was busy this week quashing a handful of bugs in its popular Firefox browser, while Microsoft won’t confirm it is working on patching an eight-year-old flaw in Windows. Plus, Lotus fixes a key vulnerability in Notes 7, and Linux vendors Ubuntu, Debian, Mandriva and Gentoo release multiple updates.
Today’s bug patches and security alerts:
Handful of bugs squashed in Firefox security fix
Mozilla has released an update to its Firefox browser, fixing a widely publicized flaw in the open-source software. The 2.0.0.10 update fixes a handful of memory corruption flaws that crash Firefox, and a cross-site request forgery flaw that could give attackers a way to get unauthorized access to certain Web sites. IDG News Service, 11/27/07.
Most Firefox browsers should have downloaded this update already.
**********
Microsoft won’t confirm proxy configuration flaw, impending patch
Microsoft Tuesday was still examining the details of a vulnerability discovered by a hacker that appears to exploit an eight-year-old flaw in Windows. So far, the company has not announced plans for a patch. In addition, the company would not confirm that the issue is based on a vulnerability first discovered in 1999 in the Web Proxy Autodiscovery Protocol (WPAD) in Windows. Nor would the company commit to the fact that any fix is under development. Network World, 11/27/07.
**********
Update: Mac version of QuickTime buggy too
The QuickTime vulnerability disclosed in the Windows version of QuickTime last week also affects Mac OS X, Symantec Corp. said today. According to additional research by Symantec’s security response team, the Real-Time Streaming Protocol (RTSP) bug in QuickTime is also present in the Mac versions of Apple Inc.’s media player.
Symantec: Zero-Day Exploit for Apple QuickTime Vulnerability
**********
Lotus Notes vulnerable to e-mail attack
A serious bug in IBM’s Lotus Notes software could be used by attackers to run unauthorized software on a victim’s PC, researchers at Core Security Technologies reported Tuesday. The flaw lies in the Autonomy KeyView software used by Lotus Notes to process Lotus 1-2-3 files. Core’s researchers found that when they opened a specially crafted Lotus 1-2-3 e-mail attachment in Lotus Notes, they could run unauthorized software on the PC. IDG News Service, 11/28/07.
**********
Four new patches from Ubuntu:
link-grammar (denial of service)
**********
Six new updates from Debian:
tk8.3 (buffer overflow, code execution)
libopenssl-ruby (multiple flaws)
**********
Two new fixes from Mandriva:
cpio (buffer overflow, code execution)
**********
Two new patches from Gentoo:
nss_ldap (information disclosure)
**********
Today’s malware news:
Google expunges malware sites from search results
Google Inc. has purged its index of the thousands of malware sites that wormed their way into results lists for hundreds of legitimate search phrases, researchers confirmed today. “They look gone to us,” said Alex Eckelberry, the CEO of Sunbelt Software, the company that broke the news Monday of a massive, coordinated campaign by attackers to spread malware through search results on Google, Yahoo, Microsoft Live Search and other sites. Computerworld, 11/28/07.
Fake YouTube URLs Downloading Suspicious Executable
Malicious code writers have always used popular Web brand names to spread malicious code through spam vectors and these days the YouTube brand name is popping up more and more. Symantec Security Response blog, 11/28/07.




