Linux vendors issue multiple patches

Opinion
Jun 7, 20074 mins

* Patches from Ubuntu, Debian, Mandriva, others * Stealthy attack serves malicious code only once * How secure is your security software?, and other interesting reading

Today’s bug patches and security alerts:

Ubuntu patches Thunderbird flaws

Multiple flaws in the Thunderbird mail client have been patched in this update for Ubuntu users. One flaw could allow an attacker to pose as a mail server to steal passwords.

**********

Debian updates Samba, again

A previous update for Debian’s implementation of Samba contains a regression error, “which broke connection to domain member servers in some scenarios.”

**********

Eight new patches from Mandriva:

lha (non-secure temp files)

libpng (denial of service)

ClamAV (denial of service)

file (buffer overflow, code execution)

mutt (multiple flaws)

mplayer (buffer overflow, code execution)

util-linux (authentication bypass)

php-pear (backdoor installer)

**********

Three new fixes from Gentoo:

ELinks (code execution)

Evolution (code execution)

libexif (integer overflow)

**********

Three new updates from rPath:

Firefox/Thunderbird (multiple flaws)

mutt (multiple flaws)

libexif (integer overflow)

**********

Today’s malware news:

Real News with Real Malware

The latest malware spam run is using gripping news headlines as e-mail subjects to hook in unsuspecting victims. And while this is not something new, the use of actual news headlines can make it more difficult to distinguish it as malicious. F-Secure Blog, 06/05/07.

The Beginning of the Arabic Virus Era

If a virus uses a language other than English, it is most often Chinese, German, Spanish, Portuguese or Russian, and sometimes Indonesian/Malay, Japanese or Thai. It is rare to find an Arabic-aware virus. At least we’ve thought so until now. Security Response Weblog, 06/06/07.

Stealthy attack serves malicious code only once

A new hacking method is causing concern for the lengths it goes to avoid detection by security software and researchers. The attack involves a Web site that has been hacked to host malicious code, an increasingly common trap on the Internet. If a user visits one of the sites with an unpatched machine, it’s possible that the computer can become automatically infected with code that can record keystrokes and steal financial data typed into forms. IDG News Service, 06/04/07.

**********

From the interesting reading department:

How secure is your security software?

Think that commercial software you just bought has been adequately tested and is ready for deployment? Think again. According to a panel of vulnerability research experts who spoke at the Gartner IT Security Summit held here this week, enterprises should test vendor software for vulnerabilities before deploying, much like they should be testing their home-grown applications. Network World, 06/05/07.

Google: Attack code more likely on Microsoft IIS

Web sites running Microsoft’s Web server software are twice as likely to be hosting malicious code as other Web sites, according to research from Google. IDG News Service, 06/05/07.

Firefox 3.0 may block sites fingered by Google

Mozilla Corp. is considering adding a tool to Firefox 3.0 that would automatically block Web sites thought to harbor malicious downloads, but the company’s security chief refused to spell out details, saying Mozilla is “not ready to talk about the feature.” Computerworld, 06/05/07.

McAfee: Search results can be dangerous

The odds of a search engine directing you to a risky Web site are getting slimmer, but some companies are better at filtering out bad links than others, McAfee reported Monday. IDG News Service, 06/04/07.

IBM to acquire Watchfire

IBM Tuesday announced its intent to acquire vulnerability-assessment security firm Watchfire for an undisclosed price. Network World, 06/06/07.

Firefox flaws raise Mozilla security doubts

The Mozilla Foundation said last week it has patched several serious security flaws in the popular Firefox browser, bugs that also affect the SeaMonkey browser and the Thunderbird e-mail application. TechWorld, 06/04/07.

Study: U.S. government still lacking data protection

More than half of U.S. government employees unofficially work at home on nights or weekends, raising concerns about the security of the data they’re working on, according to a study released Monday. IDG News Service, 06/04/07.

The Slingbox Pro: Information Leakage and Variable Bitrate (VBR) Fingerprints

To address viewer privacy, the Slingbox Pro uses encryption. But does the use of encryption fully protect the privacy of a user’s viewing habits? We studied this question at the University of Washington, and we found that the answer to this questions is No — despite the use of encryption, a passive eavesdropper can still learn private information about what someone is watching via their Slingbox Pro. Freedom to Tinker blog.