* Patches from Oracle, Mandriva, Gentoo, others * Beware Apple's latest Video iPod carrying a Windows virus * 10 security trends worth watching, and other interesting reading
Today’s bug patches and security alerts:
Oracle quarterly update features 101 fixes
The Oracle bug eradication team has had a busy quarter, fixing over 100 flaws in various product lines. Naturally, Oracle is urging customers to apply patches as soon as possible to avoid attacks.
Related:
US-CERT: Oracle Updates for Multiple Vulnerabilities
Analysis of latest Oracle update by David Litchfield of NGSSoftware
**********
First security flaw signaled in IE7
Less than 24 hours after the launch of Internet Explorer 7, security researchers are poking holes in the new browser. IDG News Service, 10/19/06.
Trustix releases new ‘multi’ update
Give the folks at Trustix credit, at least its updates of multiple products come more than once a month or, worse, quarterly. This update fixes flaws in ClamAV, the kernel, PHP, PHP4, Python and xorg-x11. The flaws could be exploited in denial-of-service attacks and to run malicious code on an affected system.
**********
A couple of flaws have been found and patched in the Bugzilla bug-tracking system. The most serious of the vulnerabilities could be exploited in a cross-scripting attack. According to the Bugzilla advisory, “We strongly advise that 2.18.x users upgrade to 2.18.6. 2.20.x users should upgrade to 2.20.3. 2.22 users, and users of 2.16.x or below, should upgrade to 2.22.1.”
**********
New updates from Ubuntu:
binutils (buffer overflow, code execution)
Xsession (race condition, information leak)
**********
New patches from Mandriva:
**********
New fixes from Gentoo:
Mozilla Network Security Service (digital signature forgery)
**********
Today’s virus news:
Apple’s latest Video iPod carries Windows virus
Apple’s support Web site today contains a posting warning customers that a small percentage of Video iPods shipped starting in September contain a Windows virus. This announcement follows a similar incident with fast-food giant McDonald’s, which distributed a series of virus-infected MP3 players in Japan as prizes in a contest. Network World, 10/18/06.
Cloudmark introduces zombie-catching service
Messaging security vendor Cloudmark on Monday announced a service designed to help ISPs and enterprises catch and clean PCs on their networks that have been infected by zombies. Network World, 10/18/06/
**********
From the interesting reading department:
How well do you know your network?
The information security officer for a network of healthcare centers in New York found an employee sending confidential payroll information to a recruiter. A California-based semiconductor manufacturing technology provider caught a worker e-mailing PowerPoint slides detailing product plans to a former colleague at a competitor to show off the “cool things” he was working on. A network administrator for a school district in Indiana nabbed a student trying to finagle school lunch account information stored on an off-limits server. NetworkWorld.com, 10/18/06.
10 security trends worth watching
In a keynote speech that was Webcast at last month’s Hack in the Box Security Conference in Kuala Lumpur, Malaysia, Bruce Schneier, CTO of U.S. managed security services provider Counterpane Internet Security, identified 10 trends affecting information security today. IDG News Service, 10/17/06.
Hackers’ project hides browser-busting code
Hackers are developing new software that will help hide browser attack code from some types of security software. The software, called VoMM (eVade o’ Matic Module), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software.




