* Patches from Microsoft, Ubuntu, Debian, others * Top 5 virus incidents of the week, according to CA * Exploit code hiding in cache servers, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Microsoft patch bonanza
MS06-057 – Vulnerability in Windows Explorer Could Allow Remote Code Execution
MS06-058 – Vulnerability in Microsoft PowerPoint Could Allow Remote Code Execution
MS06-059 – Vulnerability in Microsoft Excel Could Allow Remote Code Execution
MS06-060 – Vulnerability in Microsoft Word Could Allow Remote Code Execution
MS06-061 – Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution
MS06-062 – Vulnerability in Microsoft Office Could Allow Remote Code Execution
MS06-063 – Vulnerability in Server Service Could Allow Denial of Service
MS06-056 – Vulnerability in ASP.NET 2.0 Could Allow Information Disclosure
MS06-065 – Vulnerability in Windows Object Packager Could Allow Remote Execution
MS06-064 – Vulnerabilities in TCP/IP IPv6 Could Allow Denial of Service
Related:
US-CERT advisory: Microsoft Updates for Vulnerabilities in Windows, Office, and Internet Explorer
Microsoft malfunction fouls Patch Tuesday releases
Microsoft Tuesday published 26 security bulletins related to vulnerabilities in its Windows and Office products, but had network problems that kept it from making the software patches available via Microsoft Update, Automatic Updates, Windows Server Update Services and Windows Update v6. NetworkWorld.com, 10/10/06.
**********
Cisco warns of flaw in Secure Desktop
A flaw in the Cisco Secure Desktop could leave information created during an SSL VPN session to be left outside the secure environment. This means cookies, temporary files, browser history and other information could be left behind and exposed after the SSL session ends. Workarounds are available.
**********
New updates from Mandriva
Kernel (multiple flaws, denial of service)
python (format string, code execution)
**********
New patches for Debian
libwmf (buffer overflow, code execution)
migrationtools (temp files, denial of service)
**********
New fixes for Ubuntu
python (format string, code execution)
awstats (cross scripting attack)
libmusicbrainz (multiple buffer overflows)
**********
Top 5 virus incidents of the week, according to CA:
**********
From the interesting reading department:
Exploit code hiding in cache servers
Malicious code is living on weeks after it has been removed from Web sites thanks to an unexpected culprit: cache servers. According to Finjan Software, which has just released its latest Web trends report, caching technology used by search engines, ISPs and large companies has been discovered to harbor certain kinds of malicious code even after the Web site that hosted it has been taken down. TechWorld, 10/12/06.
Study: Home PC users most attacked by hackers
Ordinary PC users – not large corporate networks – are targeted the most by hackers due to weaker security measures, according to the latest report by Symantec. According to Symantec’s Internet Security Threat Report, which covers the first half of the year, about 86% of all attacks are leveled at home users while the rest are targeted at the financial services sector. Computerworld, 10/11/06.




