Apple patches Safari, Mac OS X

Opinion
Jun 25, 20073 mins

* Patches from Mandriva, Debian and Ubuntu * Sites serve up Mpack attacks, and other interesting reading

Today’s bug patches and security alerts:

Apple patches Safari beta browser a second time

Apple Inc. today issued security updates to patch four vulnerabilities in Mac OS X and the Safari beta, marking the second time in eight days that the company has had to fix its newest browser, which runs on both Mac and Windows XP and Vista machines. The 2007-006 update for Mac OS X 10.3, “Panther” and 10.4 “Tiger,” fixes a pair of problems in Safari — the production-quality versions bundled with the operating system — including a memory corruption vulnerability that could end with an attacker in control of the Mac. Computerworld, 06/22/07

Apple’s Safari download site

Apple releases Mac OS X updateA new update from Apple for most newer versions of Mac OS X 10 includes patches for the included WebCore and WebKit applications. The most serious of the flaws could be exploited to run malicious code on a non-updated system.

**********

Six new patches from Mandriva

Webmin (cross scripting attack)

xfsdump (non-secure temp files)

Emacs (denial of service)

MadWifi (denial of service)

Thunderbird (multiple flaws)

ProFTPD (multiple flaws)

**********

Six new fixes from Debian:

Evolution Data Server (code execution)

ClamAV (multiple flaws)

MaraDNS (denial of service)

EKG (multiple flaws)

tinymux (buffer overflow, code execution)

Emacs (denial of service)

**********

Two new fixes from Ubuntu:

Red Hat Cluster Suite (denial of service)

Evolution (code execution)

**********

Today’s malware news:

Sites serve up Mpack attacks

Several hundred sites are surprising unwitting users with a smorgasbord of exploits via Mpack, the already notorious hacker tool kit that launched massive attacks earlier this week from a network of more than 10,000 compromised domains. Computerworld, 06/22/07.

‘Zlob’ malware hijacks YouTube

YouTube is again being used to distribute malware, this time a variant of the nuisance Zlob adware. According to Secure Computing, attackers are using a fake video link on the site to initiate infection with the Trojan, which bombards its victims with adware, before installing data-stealing code. TechWorld, 06/21/07.

**********

From the interesting reading department:

Symantec offers free software as amends for antivirus snafu

Five weeks after an errant virus update crippled thousands of Chinese PCs, Symantec Corp. has decided to compensate users by giving them free backup software and extending the subscription to the same anti-virus software that knocked out their computers. Computerworld, 06/24/07.

Pentagon shuts down systems after cyber-attack

The U.S. Department of Defense took an estimated 1,500 computers offline Wednesday after a security breach within the Office of the Secretary of Defense (OSD). IDG News Service, 06/21/07.

MI5 attacks botnets

MI5 Networks updates its Webgate software to support antibot functionality and teams with IBM, Sophos and Sunbelt Software to provide URL filtering, antivirus and antispyware support. Network World, 06/21/07.

Shades of Voldemort: Hacker claims to post Harry Potter’s ending on Web

A hacker claims to have posted key plot details to the final Harry Potter book, but the publisher warned the details could be fake. Computerworld, 06/21/07.