* Patches from Microsoft, Gentoo, rPath, others * US-CERT warns of Sun Solaris Telnet Worm * Black Hat: Much ado about RFID, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
New patch for Windows XP available?
Last night, my two Windows XP machines alerted me that I needed to install a new update from Microsoft. Odd, the “Patch Tuesday” updates for February installed two weeks ago and we’re still a week-plus away from the March update. According to my Windows Update history, Security Update for Windows XP (KB923689) was installed: “A security issue has been identified that could allow an attacker to remotely compromise your Windows-based system using Windows Media file formats and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.”
This may be an update of an update, but the timing did seem odd.
Vista bug forces legit users to reactivate OS
A bug in Windows Vista’s built-in antipiracy technology is telling some users that they need to reactivate the operating system after they install new device drivers or run newly installed software. Computerworld, 02/27/07.
Researchers spot first remote code Office 2007 bug
EEye Digital Security said Friday that it’s found the first Office 2007 remote code vulnerability and has alerted Microsoft’s bug team. Computerworld, 02/23/07.
**********
Cisco Catalyst systems vulnerable to attack
Cisco is warning that a security hole in its Catalyst 6000, 6500 series and Cisco 7600 series that have a Network Analysis Module could allow an attacker to gain complete control of the system. This vulnerability affects systems that run IOS or Catalyst Operating System (CatOS), says Cisco, which has a fix available. Network World’s CiscoNet, 02/28/2007.
Cisco MPLS Packet vulnerability advisory
Cisco NAM (Network Analysis Module) vulnerability advisory
**********
Four new updates from Gentoo:
MPlayer (buffer overflow, code execution)
**********
Two new patches from rPath:
**********
Today’s virus and malware news:
US-CERT warns of Sun Solaris Telnet Worm
According to the US-CERT advisory, “A worm is exploiting a vulnerability in the telnet daemon (in.telnetd) on unpatched Sun Solaris systems. The vulnerability allows the worm (or any attacker) to log in via telnet (23/tcp) with elevated privileges.”
Storm Trojan variant spreads in blogs, forums, Webmail
A new variant of the “Storm” Trojan is injecting its come-on into blogs, Web-based message forums and Webmail as part of an effort to spread itself to an ever-wideningnet of PCs, according to a security researcher. Computerworld, 02/27/07.
We have two reports of people receiving links to a Warezov-infected file via Skype. Now, some older Warezov variants have used other Instant Messaging client in a similar fashion, but not Skype. 02/27/07.
There’s something new spreading on MySpace. It ends up modifying existing profiles. 02/27/07.
**********
From the interesting reading department:
Black Hat: Much ado about RFID
IOActive, a small security consulting company, brought out some big guns to help defend itself against an RFID giant at the Black Hat conference here Wednesday. Leveraging the American Civil Liberties Union (ACLU) and the U.S. Department of Homeland Security (DHS), IOActive hosted a panel discussion that turned into a pep rally to support the small company’s fight to disclose RFID security flaws that were detailed in a presentation RFID card vendor HID quashed. Network World, 02/28/07.
Why MassMutual’s security chief doesn’t have to outrun bears
Financial firm’s security lead sets policies, educates users and ensures his infrastructure is more secure than the competition’s. Network World, 02/28/07.
Symantec paints less-than-rosy picture of Vista security
Symantec Wednesday published four technically oriented studies on Microsoft Vista security in what it says is an effort to inform enterprise managers and software developers about what it views as both limitations and positive changes in the operating system. The four white papers reveal their technical bent in weighty titles that include “An Analysis of Address Space Layout Randomization on Windows Vista,” “An Analysis of GS protections in Windows Vista,” “The Impact of Malicious Code on Windows Vista,” and the less technical summary entitled “Microsoft Windows Vista and Security.” Network World, 02/28/07.
Lockdown taps other security gear to check malware attacks
A pending upgrade is designed to enable Lockdown Networks’ network access control gear to quarantine rogue devices that are detected by other security equipment on the network. Network World, 02/28/07.




