Patch Tuesday, Part Deux

Opinion
Apr 9, 20072 mins

* Patches from Microsoft, Ubuntu, Debian, others * Top 10 viruses for March 2007 * Has the end arrived for desktop antivirus?, and other interesting reading

Today’s bug patches and security alerts:

After emergency fix, more Microsoft patches ahead

Microsoft isn’t finished with its security fixes for the month. Next week the software maker plans to release five more sets of patches fixing critical flaws in Windows and the Microsoft Content Management Server. IDG News Service, 04/05/07.

Microsoft Advance Notice

**********

Ubuntu patches X.org flaws

Two flaws have been found the X.org implementation for Ubuntu. Both are buffer overflow vulnerabilities that can be exploited to run malicious code on an affected machine.

**********

Debian patches man-db

According to the Debian advisory, “A buffer overflow has been discovered in the man command that could allow an attacker to execute code as the man user by providing specially crafted arguments to the -H flag. This is likely to be an issue only on machines with the man and mandb programs installed setuid.”

**********

Three new updates from Mandriva:

freetype2 (integer overflows, code execution)

tightvnc (integer overflow, code execution)

xorg-x11 (multiple flaws)

**********

Two new patches from Gentoo:

libwpd (multiple flaws)

Evince (stack overflow, code execution)

**********

Top 10 viruses for March 2007, as reported by Sophos:

1. Netsky (32.7%)

2. Mytob (30.4%)

3. Sality (7.8%)

4. MyDoom (5.2%)

5. Bagle (4.1%)

6. Zafi (3.4%)

7. Stratio (2.6%)

8. Nyxem (2.6%)

9. Clagger (2.4%)

10. DwnLdr (2.0%)

**********

From the interesting reading department:

Has the end arrived for desktop antivirus?

Analysts say traditional desktop antivirus, signature-based protection won’t protect corporate jewels — whitelisting, behavior-blocking technology is the answer. Network World, 04/05/07.

Virtualization security risks being overlooked, Gartner warns

Companies in a rush to deploy virtualization technologies for server consolidation efforts could wind up overlooking many security issues and exposing themselves to risks, warns research firm Gartner. Network World, 04/06/07.