* Patches from Cisco, Ubuntu, Debian, others * Xmas eCard Spam - Malicious Downloader * Ron Paul is not a botmaster, and other interesting reading
Microsoft has finally acknowledged that a 8-year-old Windows flaw is still causing problems; a new database bug has been quashed in OpenOffice.org and Cisco has fixed a hole in its Security Agent for Windows System Driver. Plus, updates from Ubuntu, Debian, Mandriva and Gentoo.
Windows flaw could steer IE to hackers
Microsoft Monday said that a flaw in the way its Windows operating system looks up other computers on the Internet has resurfaced and could expose some customers to online attacks. Microsoft originally patched this flaw in 1999, but it was rediscovered recently in later versions of Windows and was then publicized at a recent hacker conference in New Zealand. The bug has to do with the way Windows systems look for DNS information under certain configurations. IDG News Service, 12/04/07.
**********
OpenOffice quashes database bug
OpenOffice.org fixed a critical flaw today in its suite’s database engine that attackers could use to shanghai a computer, and the project’s organizers urged customers to update to 2.3.1 as soon as possible. The bug in HSQLDB, a lightweight, all-Java SQL database engine, can be used to force OpenOffice to execute Java code planted in a rigged database document. Computerworld, 12/05/07.
**********
Cisco patches flaw in Security Agent for Windows System Driver
A buffer overflow vulnerability in the Cisco Security Agent for Microsoft Windows could be exploited to crash an affected machine or potentially run malicious code on it, according to an advisory from Cisco. A free update is available to fix the problem.
**********
Five new patches from Ubuntu:
Mono (denial of service, code execution)
Perl (denial of service, code execution)
Cairo (buffer overflow, code execution)
PHP (multiple flaws, regression error)
**********
Four new updates from Debian:
OpenOffice.org (code execution)
**********
Four new fixes from Mandriva:
OpenSSL 0.9.8 (buffer overflow, code execution)
vixie-cron (denial of service)
**********
Two new patches from Gentoo:
**********
Today’s malware news:
Xmas eCard Spam – Malicious Downloader
‘Tis the season of exchanging greetings, what with Thanksgiving and Xmas rounding out the year’s end. Unfortunately, malicious code writers are on the job trying to exploit these occasions by sending out mass spam email greeting cards with attractive and fancy links that serve the purpose of downloading malicious files to a victim’s computer. Symantec Security Response blog, 12/04/07.
We’ve recently received questions about a Symbian S60 application circulating the Internet that sends SMS messages at very high rate to an unknown phone number. While we were studying this software we came to realize it’s actually a well-known anti-theft system for Symbian Series 60 phones. F-Secure Antivirus Research blog, 12/04/07.
**********
From the interesting reading department:
Server Log Analysis of Phishing Web Sites
During the last few months, Symantec analyzed several thousands of these log files that highlighted a number interesting and peculiar features. One of these features in question is the distribution of end-user visits over time, from the moment the fraudulent content becomes reachable over the Internet towards its removal. Symantec Security Response blog, 12/03/07.
QuickTime Flaw a Potential Threat to Second Life Fans
A pair of security researchers demonstrated how the same QuickTime flaw could be used to “pick the pockets” of people engaging in various online games and virtual worlds. Dino Dai Zovi and Charles Miller described how the vulnerability might be leveraged to steal money from people who are members of “Second Life.” Washington Post Security Fix blog, 12/03/07.
QuickTime Flaw a Potential Threat to Second Life Fans
How to Secure Your Computer, Disks, and Portable Drives
Perhaps encryption isn’t so easy after all, and some people could use a little primer. This is how I protect my laptop. Schneier on Security, 12/04/07.
CA: Beacon’s reach extends to non-Facebook users
If you think that just because you have never signed up for Facebook you’re immune to the tracking and collecting of user activities outside of this popular social networking site, think again. IDG News Service, 12/03/07.
F-Secure: Malware samples doubled in one year
Finnish security vendor F-Secure has collected twice as many malicious software samples this year than it has over the last 20 years, a trend that highlights the growing danger of malicious software on the Internet. IDG News Service, 12/04/07.
Shell, Rolls Royce reportedly hacked by Chinese spies
Britain’s domestic intelligence agency is warning that cybercrime perpetrated by China is on the rise following hacking attacks against Rolls-Royce and Royal Dutch Shell. IDG News Service, 12/03/07.
Ron Paul spam traced to Ukrainian botnet
Ron Paul is not a botmaster. Security researchers have shut down a network of computers responsible for sending out nearly 200 million spam messages supporting the U.S. presidential candidate last month, and after analyzing the server’s software, it’s clear that there is no such thing as a Ron Paul botnet, according to Joe Stewart, a senior security researcher with SecureWorks. IDG News Service, 12/05/07.




