Is it a good thing when a vendor doesn’t tell you about a vulnerability and doesn’t tell you about the patch it released for said flaw? Skype users get to answer that question this week. Also, Microsoft Patch Tuesday brings three critical flaws and Debian, rPath, Mandriva and Gentoo released fixes.
Oops! Skype forgets to tell users of bug or patch job
Skype Ltd. blamed an “unintentional communication oversight” for not notifying users a month ago that it had patched the Windows version of its voice-over-IP client software against a critical bug. Computerworld, 12/10/07.
Skype security blog: Vulnerability in Skype for Windows versions older than 3.6.x.216
**********
Microsoft Patch Tuesday has three on critical list
Microsoft Tuesday released two critical patches for Windows and one for Internet Explorer that is being actively exploited, according to Microsoft. Critical patch MS07-069 affects versions 5.01, 6.0 and 7.0 of Internet Explorer, including 7.0 in Vista, and could allow remote code execution when a user views a Web page. Microsoft said hackers are already exploiting this vulnerability. Network World, 12/11/07.
Microsoft “critical” advisories:
Vulnerabilities in DirectX Could Allow Remote Code Execution
Vulnerability in Windows Media File Format Could Allow Remote Code Execution
Cumulative Security Update for Internet Explorer
Also:
Exploit menaces media players from Microsoft, AOL
**********
Three new updates from rPath:
mod_dav_svn subversion (information disclosure)
**********
Five new patches from Debian:
ruby-gnome2 (format string, code execution)
libnss-ldap (denial of service)
htdig (cross scripting attack)
**********
Four new fixes from Mandriva:
**********
Eight new patches from Gentoo:
ruby-gnome2 (format string, code execution)
Lookup (non-secure temp files)
PEAR::MDB2 (information disclosure)
**********
Today’s malware news:
Holiday time fertile ground for IM, Web-based threats
Symantec’s holiday spam listing is seeing an increase in threats which capitalize on the concept of a trusted source or Web site. Computerworld, 12/12/07.
DNS attack could signal Phishing 2.0
Researchers at Google and the Georgia Institute of Technology are studying a virtually undetectable form of attack that quietly controls where victims go on the Internet. IDG News Service, 12/11/07.




