* Patches from Mozilla, Trustix, Mandriva, others * Google accidentally sends out Kama Sutra worm * What's with all this spam?, and other interesting reading
Today’s bug patches and security alerts:
Multiple flaws in Cisco Secure Desktop
Three flaws have been found in Cisco’s Secure Desktop product, which could be exploited to gain access to sensitive information. One flaw could leave behind information used in an SSL VPN session. A second flaw could allow users to leave the VPN session while it is still active. The third could be exploited to gain elevated privileges. Cisco has made a free update available to fix the vulnerabilities.
**********
Microsoft vulnerability rooted in ActiveX controlx
Microsoft is investigating reports of a vulnerability in a Windows ActiveX control that could allow an attacker to remotely take control of a computer, according to an advisory issued Friday. One security company rated the vulnerability critical, while Microsoft said it allowed only limited attacks. IDG News Service, 11/06/06.
How to disable the affected ActiveX Control
**********
US-CERT warns of Mozilla flaws
With a variety of patches coming out recently for Mozilla-based applications, the folks at US-CERT thought it would be good to release an all-encompassing advisory. The gist: “The Mozilla web browser and derived products contain several vulnerabilities, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.”
**********
Trustix released ‘multi’ update
The latest update from Trustix fixes vulnerabilities in mutt, pam_ldap and php. Attackers could exploit the most serious of the flaws to run malicious code on an affected machine.
**********
Six new patches from Mandriva:
rpm (heap overflow, code execution)
pam_ldap (unauthorized access to suspended accounts)
wv (integer overflow, code execution)
texinfo (buffer overflow, denial of service)
**********
Three new updates from Gentoo:
Qt (integer overflow, denial of service)
Screen (character handling, code execution)
**********
Two new fixes from Debian:
ingo1 (shell command execution)
**********
Today’s big virus-related news:
Google accidentally sends out Kama Sutra worm
Google Inc. accidentally sent out e-mail containing a mass mailing worm to about 50,000 members of an e-mail discussion list focused on its Google Video Blog, the company said Tuesday. IDG News Service, 11/08/06.
**********
From the interesting reading department:
Review of Windows Vista final code shows security needs admin attention
Overall, we can’t say that we don’t like the Vista Ultimate code that was released to manufacturing by Microsoft on Wednesday and will subsequently be available for corporate volume customers by the end of the month. After all, from our testing we can confirm that it contains vastly improved graphics, offers very flexible installation options and gives administrators stronger control over the operating system’s security settings.
What’s with all this spam?
Researchers and IT managers are confirming security vendors’ claims that spam levels have spiked in the past month — some say by as much as 80 % — and show no signs decreasing. Network World, 11/08/06.
Firefox 1.5 support ending April 24
Users of Firefox 1.5 should plan to upgrade their browser by April 24 of next year at the very latest, according to Mozilla Corp. IDG News Service, 11/08/06.




