Microsoft and Safari patches rule the day

Opinion
Jun 14, 20073 mins

* Patches from Microsoft, Apple, Debian, others * New type of image spam hides in e-mail wallpaper * Hackers access personal info on varsity faculty members, and other interesting reading

Today’s bug patches and security alerts:

Microsoft patches bugs in Windows, IE, Outlook Express

As Microsoft Tuesday patched 15 vulnerabilities in its operating system, browser, and other software, security experts argued over which should be fixed first. The month’s six updates fixed multiple bugs in all currently-supported versions of Windows; in Internet Explorer (IE), both IE 6 and IE 7; in yet another member of the Office family; and in the entry-level e-mail clients Outlook Express and Windows Mail. Of the 15 flaws, 9 were labeled critical, Microsoft’s most serious threat ranking, while 2 were pegged as important and 2 judged moderate. Computerworld, 06/12/07.

Microsoft advisories:

Vulnerability in the Windows Schannel Security Package Could Allow Remote Code Execution

Cumulative Security Update for Internet Explorer

Cumulative Security Update for Outlook Express and Windows Mail

Vulnerability in Win32 API Could Allow Remote Code Execution

Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution

Vulnerability in Windows Vista Could Allow Information Disclosure

Related US-CERT advisory

**********

Apple patches flaws in Safari beta for Windows

Apple launched a Safari beta for Windows this week and already needs to issue security patches for it. A couple of flaws could allow for code to be run on an affected machine when a user visits a malicious Web site. Users should download the latest version of Safari to fix the problems.

**********

Five new updates from Debian:

Freetype (integer overflow, code execution)

lighttpd (denial of service)

Icedove (multiple flaws)

Xulrunner (multiple flaws)

OpenOffice.org (heap overflow, code execution)

**********

Three new fixes from Mandriva:

libexif (integer overflow, code execution)

Thunderbird (multiple flaws)

Firefox (multiple flaws)

**********

Four new patches from Ubuntu:

libexif (integer overflow, code execution)

libgd2 (buffer overflow, code execution)

libpng (denial of service)

xscreensaver (authentication bypass)

**********

Today’s malware news:

New type of image spam hides in e-mail wallpaper

A new type of image spam found this week is able to bypass many filters by presenting a message as wallpaper within an e-mail, according to the vendor Secure Computing. Network World, 06/13/07.

FBI: Operation Bot Roast finds over 1 million botnet victims

The Department of Justice and FBI today said ongoing investigations have identified more than 1 million botnet crime victims. Network World, 06/13/07.

**********

From the interesting reading department:

Hackers access personal info on varsity faculty members

About 6,000 current and former University of Virginia (UVa) faculty members are being notified that their names, Social Security numbers and birth dates may have been stolen by computer hackers between May 2005 and April 19 of this year. Computerworld, 06/11/07.

Hackers audition Yahoo Messenger exploits

Users of Yahoo’s Messenger software should patch the program as soon as possible, security vendors said today, because hackers are now using exploits that target the instant messaging application. Computerworld, 06/11/07.

How DOE lab secured campus with wireless

The terms “wireless” and “security” don’t always go hand-in-hand. But the Energy Department’s Pacific Northwest National Laboratory is proving that these concepts are compatible with an innovative system that uses cutting-edge wireless technology to improve campus security. Network World, 06/12/07.