Firefox 2.0.2 fixes flaws

Opinion
Feb 26, 20073 mins

* Patches from Mozilla, Mandriva, Ubuntu, others * F-Secure: Kernel Malware * TJX: Data breach worse than previously believed, and other interesting reading

Editor’s note: Are smokers’ a risk to IT? Check out this video.

Today’s bug patches and security alerts:

Mozilla fixes Firefox bugs

Mozilla Corp. has released an update to its Firefox browser, fixing a number of security flaws in the product. The Firefox 2.0.0.2 release includes a fix for a bug disclosed by security researcher Michal Zalewsky last week. That flaw can be exploited by attackers to manipulate cookie information in the Firefox browser, making it probably the most important fix in the update, according to Window Snyder, Mozilla’s head of security strategy. IDG News Service, 02/23/07.

Firefox users should get this update automatically. All of my machines updated on their own.

Mozilla release notes for Firefox 2.0.2

**********

Second Google Desktop attack reported

Google’s PC search software is vulnerable to a variation on a little-known Web-based attack called anti-DNS pinning, that could give an attacker access to any data indexed by Google Desktop, security researchers said this week. IDG News Service, 02/23/07.

Ha.ckers blog entry on the flaw

**********

Two new updates from Mandriva:

PHP (multiple flaws)

SpamAssassin (denial of service)

**********

Two fixes from OpenPKG:

twiki (code execution)

PHP (multiple flaws)

**********

Three new patches from Ubuntu:

slocate (information disclosure)

Ekiga (format string, code execution)

enigmail (denial of service)

**********

Two new updates from rPath:

kernel (denial of service)

SpamAssassin (denial of service)

**********

Today’s malware news:

F-Secure: Kernel Malware

The paper — “Kernel Malware: The Attack from Within” — is about kernel malware, explaining what they are, how they work, and what makes their detection and removal challenging. It also looks at two interesting malware cases utilizing kernel-mode techniques to avoid detection and to bypass personal firewalls.

**********

From the interesting reading department:

TJX: Data breach worse than previously believed

There’s more bad news from Framingham, Mass.-based retailer TJX Companies regarding the massive data breach disclosed last month. An ongoing investigation of the breach has shown that intruders gained access to TJX systems almost a full-year earlier than first thought — and compromised more payment card data than previously believed, the company said in a statement issued Wednesday. Computerworld, 02/22/07.

Threats you can’t see

You’re no security slouch. You keep your programs up-to-date, and you have antivirus installed. You’re careful about where you surf and what you install on your computer. But last September, if you had visited a blog hosted by HostGator, a top-tier provider based in Florida, your PC’s browser would have been summarily redirected to an infected Web site that exploited a vulnerability in an old Microsoft image format. PC World, 02/21/07.

Mobile devices expose corporate networks to myriad security threats

The latest IT security threat plaguing the corporate office is actually clipped to the belts and purses of a company’s mobile workforce. Network World, 02/22/07.

Toshiba secures quantum key distribution

Researchers at Toshiba have developed a method that they say makes it possible — barring a change in the laws of physics — to absolutely secure distribution of encryption keys across a network. IDG News Service, 02/22/07.