No Patch Tuesday this month

Opinion
Mar 12, 20073 mins

* Patches from Apple, Trustix, Ubuntu, others * Q1 Labs matches user IDs with security events, and other interesting reading

Today’s bug patches and security alerts:

No Microsoft security updates coming next week

Microsoft is not planning to release any security updates on Tuesday, one of only a handful of times the company won’t have security patches available since its monthly security updates began in 2003, Microsoft said Thursday. IDG News Service, 03/08/07.

Microsoft confirms OneCare zaps Outlook e-mail

Microsoft has acknowledged that a bug in its Windows Live OneCare security suite has been causing users’ e-mail to vanish from Outlook and Outlook Express. Computerworld, 03/08/07.

**********

Apple patches AirPort Extreme

A flaw in Apple’s Wireless LAN drivers for MAC could result in a denial-of-service attack being launched against an affected machine, including the Core Duo version of Mac mini, MacBook, and MacBook Pro computers equipped with wireless.

**********

New Trustix “multi” update available

The latest update from Trustix fixes flaws in GnuPG and PHP. The GnuPG flaw could be exploited by an attacker to forge a message. Unpatched PHP engines are vulnerable to denial-of-service attacks and potential compromise.

**********

Three new updates from Ubuntu

GnuPG (message forging)

Xine (buffer overflow, code execution)

Ekiga (format string, code execution)

**********

Two new fixes available from Debian:

PHP4 (multiple flaws)

Mozilla (multiple flaws)

**********

Seven new patches from Mandriva:

Kernel (multiple flaws)

GnuPG (message forging)

Ekiga (format string, code execution)

xine-lib (buffer overflow, code execution)

tcpdump (denial of service)

mplayer (buffer overflow, code execution)

kdelibs (denial of service)

**********

Three new updates from Gentoo:

KHTML (cross-scripting flaw)

Smb4K (multiple flaws)

SeaMonkey (multiple flaws)

**********

From the interesting reading department:

Q1 Labs matches user IDs with security events

When network managers are tracking down the source of a security breach, the search often stops cold at the IP address. Network World, 03/09/07.

Now on the menu at Ruby Tuesday: Better security

Restaurant chain Ruby Tuesday is adding more beef to its credit card security measures. Concerned by growing incidents of credit card fraud, the company is in the process of rolling out new point-of-sale (POS) hardware and software at each of the more than 900 Ruby Tuesday restaurants in the U.S. The company is also eliminating its previous practice of storing customer transaction data in its POS systems and has cut the third-party processor that used to handle payment card transactions. Instead, it is directly linked to its merchant bank now. Computerworld, 03/08/07.

Q&A: Shred your data to stay ahead of the pack

Jeff Jonas, the chief scientist and distinguished engineer at IBM’s entity analytic solutions group, has developed a means of sharing corporate data without revealing what that data contains. IDG News Service, 03/09/07.

Tech Update: ‘One of our laptops is missing’

These are words no IT manager ever wants to hear. Beyond the embarrassment, there is the danger of seriously bad publicity, damage to brand equity and legal liability. It is possible that losing even a single mobile computer loaded with sensitive information can kill an otherwise thriving business. The good news is that current technologies and best practices can lower the risk dramatically when mobile computers are lost or stolen. Network World, 03/09/07.

Symantec: Adult spam down, image spam climbs

Pornographic spam dropped to an all-time low in February, as spammers concentrated on health-related products and other general product pitches, according to a report from vendor Symantec Corp. IDG News Service, 03/09/07.