Oracle releases delayed patch

Opinion
Apr 23, 20073 mins

* Patches from Oracle, Apple, Trustix, others * Spammers, hackers seize on Virginia Tech shootings * Hacker breaks into Mac at security conference, and other interesting reading

Today’s bug patches security alerts:

Oracle releases delayed Windows database patch

Oracle probably worried some DBAs earlier this week when it released its Critical Patch Update, but neglected its most critical database flaw of the quarter for 9.2.0.8 users on the Windows platform. At the time, Oracle said this fix would come on April 30, but now it looks like Oracle has found a way to get the patch out. IDG News Service, 04/20/07.

Oracle advisory

**********

Nortel warns of three VPN Router product flaws

Nortel this week warned of several backdoors, and other flaws, in its VPN and secure routing products that could allow unauthorized remote access to an enterprise network. User accounts used for diagnostics on Nortel VPN routers (formerly known as Contivity) could be used to gain access to a corporate VPN. In another potential vulnerability, unauthorized remote users could also gain administrative access to a VPN router through a Web interface. A third vulnerability could result in someone cracking users’ VPN passwords. Network World, 04/20/07.

Nortel advisory

**********

Apple issues wide-ranging update for Mac OS X

The latest update from Apple fixes flaws in AFP Client, AirPort, CarbonCore, diskdev_cmds, fetchmail, ftpd, GNU Tar, Help Viewer, HID Family, Installer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, VideoConference, WebDAV, and WebFoundation. The most serious of the flaws could be exploited to run malicious code on an affected system.

Related US-CERT advisory

**********

Trustix releases ‘multi’ update

A new security update from Trustix fixes flaws in ClamAV, FreeRadius and FreeType. All three flaws could be exploited to gain access to an affected system or potentially run arbitrary code.

**********

Five new updates from Mandriva:

PHP for Linux 2007.1 (multiple flaws)

PHP for Linux 2007.0, Corporate 4.0 (multiple flaws)

PHP for Corporate 4.0 (multiple flaws)

PHP for Corporate 3.0, Multi Network Firewall 2.0 (multiple flaws)

sqlite (buffer overflow, code execution)

**********

Malware and virus news of the day

Spammers, hackers seize on Virginia Tech shootings

Spammers and hackers are using the slayings at Virginia Tech as a gory lure to infect computers with malicious software, security experts noted Thursday. IDG News Service, 04/19/07.

**********

From the interesting reading department:

Hacker breaks into Mac at security conference

A hacker managed to break into a Mac and win a $10,000 prize as part of a contest started at the CanSecWest security conference in Vancouver. IDG News Service, 04/20/07.

Security experts warn satellite navigation users

Two security experts have discovered a way to inject false messages — some amusing and others potentially frightening –into car satellite navigation systems. IDG News Service, 04/20/07.