Quarterly Oracle security update lacking key fixes

Opinion
Apr 19, 20073 mins

* Patches from rPath, Mandriva, Gentoo, others * New worm wriggles around on Skype * IRS warns of tax phishing scheme, and other interesting reading

Today’s bug patches and security alerts:

Oracle updates leave critical Windows flaw unpatched

Some Oracle customers using the Windows operating system will have to wait another two weeks to receive a critical software update to their database software, thanks to a glitch that came up in testing the company’s latest patches. IDG News Service, 04/17/07

Oracle advisory

NGSSoftware analysis of the patches (PDF)

**********

Microsoft: DNS patch to come by May 8, maybe

Microsoft hopes to fix by May 8 a critical flaw in Windows DNS servers that is being exploited by online criminals, the company said late Tuesday. IDG News Service, 04/18/07.

Also:

Port scans could foreshadow Windows DNS Server exploit

A major spike in activity targeting TCP Port 1025 on Windows systems may be a sign that attackers are gathering intelligence for an upcoming attack against unpatched servers, Symantec warned Monday. Computerworld, 04/16/07.

**********

Akamai Download Manager patched

A stack overflow in Akamai’s Download Manager application could be exploited to run malicious code on an affected system. For the vulnerability to be exploited, an affected client would have to visit a malicious URL.

**********

Watchfire online community shares vulnerability testing knowledge

Watchfire is opening up its Web application-vulnerability software so customers can create their own security tests of corporate applications. This capability, which lets users extend features based on individual needs, is part of Version 7.5 of Watchfire’s AppScan platform.

**********

Wi-Fi bug found in Linux

A bug has been found in a major Linux Wi-Fi driver that can allow an attacker to take control of a laptop — even when it is not on a Wi-Fi network. PC World, 4/14/07.

Related:

Gentoo patch

**********

Four new updates from rPath:

dovecot (information exposure)

php (multiple flaws)

lighttpd (denial of service)

kernel (multiple flaws)

**********

Three new patches from Mandriva:

cups (denial of service)

freeradius (denial of service)

ipsec-tools (denial of service)

**********

Six new fixes from Gentoo:

FreeRADIUS (denial of service)

File (denial of service)

OpenOffice.org (multiple flaws)

Vixie Cron (denial of service)

Inkscape (format string flaws, code execution)

xine-lib (heap overflow, code execution)

**********

Virus/malware news of the day:

New worm wriggles around on Skype

A worm targeting Skype’s VoIP application is harvesting e-mail addresses and directing users to a range of sites hosting other malicious software, security vendors said Monday. IDG News Service, 04/16/07.

**********

From the interesting reading department:

IRS warns of tax phishing scheme

The U.S. Internal Revenue Service is warning taxpayers to be wary of e-mail messages that provide links to supposedly free tax-filing services endorsed by the agency. IDG News Service, 04/16/07.

Where’s the virtual security?

Deployment of products that transform physical servers into “virtual machines” has resulted in nothing short of a data center revolution. But virtualization of everything from operating systems to applications increasingly has critics asking: Where’s the security? Network World, 04/18/07.

What VMware thinks about security

Enterprises should be able to adapt their security practices pretty naturally to VMware environments, an executive at EMC’s virtualization outfit says. Network World, 04/18/07.

Network downtime unavoidable, IT execs say

A majority of IT executives expect they will experience in 2007 at least a few hours of network downtime, which could affect their revenue. Network World, 04/17/07.