* Patches from FreeBSD, Ubuntu, Gentoo, others * How the ANI bug got baked into Vista: Microsoft explains * Entrepreneurial hackers buy sponsored links on Google, and other interesting reading
Today’s bug patches and security alerts:
Linux vendors release PostgreSQL updates
A flaw in various implementations of the PostgreSQL database system could be exploited by an attacker to execute malicious code with the privileges of a secured user. Patches are available for the following distributions:
**********
A flaw in FreeBSD’s IPv6 implementation could be exploited by an attacker in a denial-of-service attack against an affected host. An update is available.
**********
Three new updates from Ubuntu:
X.org (integer overflows, code execution)
**********
Two new patches from Gentoo:
capi4k-utils (buffer overflow, code execution)
**********
Malware news of the day:
How the ANI bug got baked into Vista: Microsoft explains
In a postmortem of last month’s Windows animated (.ANI) cursor vulnerability, one of Microsoft Corp.’s security development gurus today spelled out how the bug sneaked into Vista. Michael Howard, an authority on Microsoft’s Security Development Lifecycle (SDL) — a multipart initiative that aims to get developers to design more secure code — posted an extensive entry on the brand-new SDL blog that outlined lessons learned from the ANI vulnerability. Computerworld, 04/27/07.
**********
From the interesting reading department:
Entrepreneurial hackers buy sponsored links on Google
A hacker scheme that involved buying search keywords on Google, then routing users to a malicious site when they clicked on sponsored links, was revealed Wednesday by a security company. Computerworld, 04/26/07.
AOL probing whether teen hacker stole customer data
AOL is investigating the recent hacking of its systems by a New York teen to determine if he managed to obtain customer data. However, the Time Warner Inc. subsidiary thinks it’s unlikely that customer data was compromised. IDG News Service, 04/27/07.
Student evades Cisco NAC; gets suspended
A default setting in Cisco NAC gear allowed a University of Portland student to dodge a security scan by Cisco’s NAC software agent and get on the school network. NetworkWorld.com, 04/26/07.
Security experts not surprised the Mac was hacked
Security researcher Dino Dai Zovi sent a shudder through the Macintosh community late last week when he successfully hacked the Mac with an exploit that he sent to a friend attending the CanSecWest security conference. By gaining shell access to a Mac by pointing the Safari Web browser at a specially-constructed Web page, Dai Zovi won a $10,000 prize from 3Com’s Tipping Point division — and took a lot of Mac users by surprise. MacWorld, 04/26/07.
London hit by malware-infected USB ruse
Joining the infamous Chip & PIN terminal hacks as yet another way to siphon banking details from unlucky Londoners, a group of “malware pur veyors” reportedly dropped off tempting Trojan-infused USB drives in a UK parking lot in hopes that unsuspecting individuals would take the bait and subsequently hand over their banking credentials. Engadget, 04/26/07.




