Linux vendors release PostgreSQL updates

Opinion
Apr 30, 20073 mins

* Patches from FreeBSD, Ubuntu, Gentoo, others * How the ANI bug got baked into Vista: Microsoft explains * Entrepreneurial hackers buy sponsored links on Google, and other interesting reading

Today’s bug patches and security alerts:

Linux vendors release PostgreSQL updates

A flaw in various implementations of the PostgreSQL database system could be exploited by an attacker to execute malicious code with the privileges of a secured user. Patches are available for the following distributions:

Mandriva

rPath

Trustix

Ubuntu

**********

FreeBSD patches IPv6 stack

A flaw in FreeBSD’s IPv6 implementation could be exploited by an attacker in a denial-of-service attack against an affected host. An update is available.

**********

Three new updates from Ubuntu:

PHP (multiple flaws)

rdesktop (regression error)

X.org (integer overflows, code execution)

**********

Two new patches from Gentoo:

capi4k-utils (buffer overflow, code execution)

BEAST (denial of service)

**********

Malware news of the day:

How the ANI bug got baked into Vista: Microsoft explains

In a postmortem of last month’s Windows animated (.ANI) cursor vulnerability, one of Microsoft Corp.’s security development gurus today spelled out how the bug sneaked into Vista. Michael Howard, an authority on Microsoft’s Security Development Lifecycle (SDL) — a multipart initiative that aims to get developers to design more secure code — posted an extensive entry on the brand-new SDL blog that outlined lessons learned from the ANI vulnerability. Computerworld, 04/27/07.

**********

From the interesting reading department:

Entrepreneurial hackers buy sponsored links on Google

A hacker scheme that involved buying search keywords on Google, then routing users to a malicious site when they clicked on sponsored links, was revealed Wednesday by a security company. Computerworld, 04/26/07.

AOL probing whether teen hacker stole customer data

AOL is investigating the recent hacking of its systems by a New York teen to determine if he managed to obtain customer data. However, the Time Warner Inc. subsidiary thinks it’s unlikely that customer data was compromised. IDG News Service, 04/27/07.

Student evades Cisco NAC; gets suspended

A default setting in Cisco NAC gear allowed a University of Portland student to dodge a security scan by Cisco’s NAC software agent and get on the school network. NetworkWorld.com, 04/26/07.

Security experts not surprised the Mac was hacked

Security researcher Dino Dai Zovi sent a shudder through the Macintosh community late last week when he successfully hacked the Mac with an exploit that he sent to a friend attending the CanSecWest security conference. By gaining shell access to a Mac by pointing the Safari Web browser at a specially-constructed Web page, Dai Zovi won a $10,000 prize from 3Com’s Tipping Point division — and took a lot of Mac users by surprise. MacWorld, 04/26/07.

London hit by malware-infected USB ruse

Joining the infamous Chip & PIN terminal hacks as yet another way to siphon banking details from unlucky Londoners, a group of “malware pur veyors” reportedly dropped off tempting Trojan-infused USB drives in a UK parking lot in hopes that unsuspecting individuals would take the bait and subsequently hand over their banking credentials. Engadget, 04/26/07.