Four more Windows flaws patched

Opinion
Apr 12, 20073 mins

* Patches from Microsoft, Apple, Mandriva, others * Over 2,000 sites now exploit .ani security flaw * A third of IT managers report data breaches: survey, and other interesting reading

Today’s bug patches and security alerts:

Microsoft issues four critical patches including one for Vista

Microsoft Tuesday released five patches — four on them rated critical — as part of its monthly security update cycle. One of the patches affects Windows Vista. The four patches rated as critical, Microsoft’s highest rating, involve the Windows operating system and Microsoft Content Management Server (CMS). They are: MS07-018, MS07-019, MS07-020 and MS07-021. NetworkWorld.com, 04/10/07.

Related:

Microsoft patches:

Vulnerabilities in GDI Could Allow Remote Code Execution

Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution

Vulnerability in Universal Plug and Play Could Allow Remote Code Execution

Vulnerability in Microsoft Agent Could Allow Remote Code Execution

Vulnerabilities in CSRSS Could Allow Remote Code Execution

Vulnerability in Windows Kernel Could Allow Elevation of Privilege

US-CERT advisory on the Microsoft updates

Latest Vista bug may be tougher nut to crack

The Windows Vista flaw patched yesterday by Microsoft — the second such vulnerability in the operating system to be fixed in the last week — isn’t exactly easy to exploit, according to nCircle Network Security. Computerworld, 04/11/07.

More flaws in Vista?

Microsoft contests reports of new Office flaws

Microsoft is disputing reports of new three flaws in its Office software while also taking issue in how the alleged flaws were disclosed, the company said Wednesday. IDG News Service, 04/11/07.

**********

Apple updates firmware for AirPort Extreme BaseStation with 802.11n

The firmware for Apple’s AirPort Extreme BaseStation with 802.11n has IPv6 support turned on by default, which may allow remote users to gain unauthorized access to certain network services. Version 7.1 of the firmware fixes this flaw in the AirPort Extreme BaseStation with 802.11n.

**********

Google fixes security hole in Chinese software tool

Google has closed a security hole in a recently released Chinese-input software tool that lies at the heart of a dispute with Chinese Internet company Sohu.com. IDG News Service, 04/08/07.

**********

Two new updates from Ubuntu:

kernel (multiple flaws)

ipsec-tools (denial of service)

**********

Seven new patches from Mandriva:

qt4 (tag injection)

krb5 (multiple flaws)

xorg-x11 (memory corruption, code execution)

tightvnc (memory corruption, code execution)

freetype2 (integer overflow, code execution)

madwifi-source (denial of service)

apache-mod_perl (denial of service)

**********

Malware news of the day:

Over 2,000 sites now exploit .ani security flaw

More than 2,000 unique Web sites have been rigged to exploit the animated cursor security flaw in Microsoft’s software, according to security vendor Websense. IDG News Service, 04/10/07.

**********

From the interesting reading department:

A third of IT managers report data breaches: survey

In a recent survey of 83 corporate IT managers, 28 acknowledged having had to cope with a data breach, and half of those respondents reported significant related costs. Network World, 04/11/07.

Researcher creates Bluetooth crack tool

A security researcher has demonstrated that it’s possible to put together a Bluetooth sniffer out of an inexpensive wireless dongle, raising fresh questions about the security of the wireless technology. TechWorld, 04/10/07.

Sophos: China fixing spam problem; U.S. is not

The amount of spam pumping out of China dropped precipitously in the first three months of 2007, security vendor Sophos reported Wednesday. IDG News Service, 04/11/07.

Cybersecurity group calls for new gov’t approaches

The U.S. government should explore new incentives for companies to invest in cybersecurity instead of focusing on regulation, a cybersecurity trade group said. IDG News Service, 04/11/07.