* Patches from Gentoo, Mandriva, Ubuntu * Google Gadgets can be misused by phishers, and other interesting reading
endif; ?>Today’s malware news:
Yesterday, we analyzed a sample of a new Trojan, called Infostealer.Monstres, which was attempting to access the online recruitment Web site, Monster.com. It was also uploading data to a remote server. When we accessed this remote server, we found over 1.6 million entries with personal information belonging to several hundred thousand people. Symantec Security Response Weblog, 08/17/07.
Also: Identity attack spreads; 1.6M records stolen from Monster.com
We have in the past repeatedly warned that free things on the internet do not always come cost free. And today, we have to make a kind reminder as we came across a new example. Symantec Security Response Weblog, 08/18/07.
**********
Today’s bug patches and security alerts:
Thirteen new patches from Gentoo:
Mozilla Firefox, Thunderbird et al (multiple flaws)
SquirrelMail (multiple flaws, code execution)
Xfce Terminal (code execution)
libarchive (denial of service, code execution)
Xvid (array indexing flaw, code execution)
Macromedia Flash Player (code execution)
**********
Thirteen new updates from Mandriva:
CUPS (integer overflow, code execution)
koffice (integer overflow, code execution)
kdegraphics (integer overflow, code execution)
poppler (integer overflow, code execution)
pdftohtml (integer overflow, code execution)
gPDF (integer overflow, code execution)
xpdf (integer overflow, code execution)
tcpdump (buffer overflow, code execution)
xine-ui (format string, code execution)
**********
Two new fixes from Ubuntu:
**********
From the interesting reading department:
The summer of spam: record growth, record irritation
There is 17% more spam heading for in-boxes today than there was yesterday, and spam watchers say it could get even worse before the summer is over. Network World, 08/16/07.
Microsoft patches Patchguard, miss Purple Pill
Microsoft has updated its 64-bit kernel protection for Windows Vista, which most of us know as PatchGuard, but which Microsoft calls Kernel Patch Protection. This is Microsoft’s third PatchGuard update, in what has become a cat and mouse game between the software giant and security researchers. IDG News Service, 08/16/07.
Study finds Internet rife with attack codes
Even seemingly safe Web addresses are rife with attack code aiming at vulnerable clients, according to a new study from the Honeynet Project. The study also found that methods such as blacklists can be surprisingly successful in stopping client-side attacks. TechWorld, 08/16/07.
Researcher: Google Gadgets can be misused by phishers
The domain used to host small Google Gadget applications written by Web developers could be misused by phishers, a Web security researcher said Friday. IDG News Service, 08/17/07.
Vista stricken by embarrassing gadget hole
Security vendor Finjan has claimed the credit for spotting an embarrassing flaw in Windows Vista, which Microsoft only patched this week in its monthly updates. The exploit involves one of the most apparently innocent elements of Vista, namely the sidebar ‘gadgets’ whereby users load one from a selection of small utilities on to the desktop. TechWorld, 08/15/07.
Colleges struggle with mandates to prohibit portable storage
The needs of students and faculty have prevented universities from implementing mandates that prohibit the use of unapproved portable storage media, but those devices pose a real threat to institutional security. Computerworld, 08/17/07.




