101 fixed from Oracle

Opinion
Oct 19, 20063 mins

* Patches from Oracle, Mandriva, Gentoo, others * Beware Apple's latest Video iPod carrying a Windows virus * 10 security trends worth watching, and other interesting reading

Today’s bug patches and security alerts:

Oracle quarterly update features 101 fixes

The Oracle bug eradication team has had a busy quarter, fixing over 100 flaws in various product lines. Naturally, Oracle is urging customers to apply patches as soon as possible to avoid attacks.

Related:

US-CERT: Oracle Updates for Multiple Vulnerabilities

Analysis of latest Oracle update by David Litchfield of NGSSoftware

**********

First security flaw signaled in IE7

Less than 24 hours after the launch of Internet Explorer 7, security researchers are poking holes in the new browser. IDG News Service, 10/19/06.

Trustix releases new ‘multi’ update

Give the folks at Trustix credit, at least its updates of multiple products come more than once a month or, worse, quarterly. This update fixes flaws in ClamAV, the kernel, PHP, PHP4, Python and xorg-x11. The flaws could be exploited in denial-of-service attacks and to run malicious code on an affected system.

**********

New Bugzilla update available

A couple of flaws have been found and patched in the Bugzilla bug-tracking system. The most serious of the vulnerabilities could be exploited in a cross-scripting attack. According to the Bugzilla advisory, “We strongly advise that 2.18.x users upgrade to 2.18.6. 2.20.x users should upgrade to 2.20.3. 2.22 users, and users of 2.16.x or below, should upgrade to 2.22.1.”

**********

New updates from Ubuntu:

binutils (buffer overflow, code execution)

libksba (denial of service)

Xsession (race condition, information leak)

**********

New patches from Mandriva:

PHP (multiple flaws)

ClamAV (multiple flaws)

libksba (denial of service)

**********

New fixes from Gentoo:

Python (buffer overflow)

Mozilla Network Security Service (digital signature forgery)

CAPI4Hylafax (code execution)

Seamonkey (multiple flaws)

**********

Today’s virus news:

Apple’s latest Video iPod carries Windows virus

Apple’s support Web site today contains a posting warning customers that a small percentage of Video iPods shipped starting in September contain a Windows virus. This announcement follows a similar incident with fast-food giant McDonald’s, which distributed a series of virus-infected MP3 players in Japan as prizes in a contest. Network World, 10/18/06.

Cloudmark introduces zombie-catching service

Messaging security vendor Cloudmark on Monday announced a service designed to help ISPs and enterprises catch and clean PCs on their networks that have been infected by zombies. Network World, 10/18/06/

**********

From the interesting reading department:

How well do you know your network?

The information security officer for a network of healthcare centers in New York found an employee sending confidential payroll information to a recruiter. A California-based semiconductor manufacturing technology provider caught a worker e-mailing PowerPoint slides detailing product plans to a former colleague at a competitor to show off the “cool things” he was working on. A network administrator for a school district in Indiana nabbed a student trying to finagle school lunch account information stored on an off-limits server. NetworkWorld.com, 10/18/06.

10 security trends worth watching

In a keynote speech that was Webcast at last month’s Hack in the Box Security Conference in Kuala Lumpur, Malaysia, Bruce Schneier, CTO of U.S. managed security services provider Counterpane Internet Security, identified 10 trends affecting information security today. IDG News Service, 10/17/06.

Hackers’ project hides browser-busting code

Hackers are developing new software that will help hide browser attack code from some types of security software. The software, called VoMM (eVade o’ Matic Module), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software.