Skype forgets to tell users about patch

Opinion
Dec 13, 20072 mins

Is it a good thing when a vendor doesn’t tell you about a vulnerability and doesn’t tell you about the patch it released for said flaw? Skype users get to answer that question this week. Also, Microsoft Patch Tuesday brings three critical flaws and Debian, rPath, Mandriva and Gentoo released fixes.

Oops! Skype forgets to tell users of bug or patch job

Skype Ltd. blamed an “unintentional communication oversight” for not notifying users a month ago that it had patched the Windows version of its voice-over-IP client software against a critical bug. Computerworld, 12/10/07.

Skype security blog: Vulnerability in Skype for Windows versions older than 3.6.x.216

**********

Microsoft Patch Tuesday has three on critical list

Microsoft Tuesday released two critical patches for Windows and one for Internet Explorer that is being actively exploited, according to Microsoft. Critical patch MS07-069 affects versions 5.01, 6.0 and 7.0 of Internet Explorer, including 7.0 in Vista, and could allow remote code execution when a user views a Web page. Microsoft said hackers are already exploiting this vulnerability. Network World, 12/11/07.

Microsoft “critical” advisories:

Vulnerabilities in DirectX Could Allow Remote Code Execution

Vulnerability in Windows Media File Format Could Allow Remote Code Execution

Cumulative Security Update for Internet Explorer

Also:

US-CERT advisory

Exploit menaces media players from Microsoft, AOL

**********

Three new updates from rPath:

mod_dav_svn subversion (information disclosure)

e2fsprogs (multiple flaws)

Samba (code execution)

**********

Five new patches from Debian:

ruby-gnome2 (format string, code execution)

libnss-ldap (denial of service)

htdig (cross scripting attack)

Linux 2.6.18 (multiple flaws)

Samba (code execution)

**********

Four new fixes from Mandriva:

Samba (code execution)

MySQL (multiple flaws)

e2fsprogs (multiple flaws)

tomcat5 (multiple flaws)

**********

Eight new patches from Gentoo:

Samba (code execution)

ruby-gnome2 (format string, code execution)

Qt library (multiple flaws)

Lookup (non-secure temp files)

Firebird (multiple flaws)

PEAR::MDB2 (information disclosure)

Cairo (code execution)

GNU Emacs (multiple flaws)

**********

Today’s malware news:

Holiday time fertile ground for IM, Web-based threats

Symantec’s holiday spam listing is seeing an increase in threats which capitalize on the concept of a trusted source or Web site. Computerworld, 12/12/07.

DNS attack could signal Phishing 2.0

Researchers at Google and the Georgia Institute of Technology are studying a virtually undetectable form of attack that quietly controls where victims go on the Internet. IDG News Service, 12/11/07.