Apple patches Remote Desktop

Opinion
Nov 20, 20062 mins

* Patches from Apple, Gentoo, Mandriva, others * Uncover DHS' Virus Gaffe * Attack code posted for latest Microsoft bugs, and other interesting reading

Note: This is our only newsletter this week. Happy Thanksgiving to all!

Today’s bug patches and security alerts:

Apple patches Remote Desktop 3.1

A flaw in the module used to download/install software upgrades could be exploited by to run malicious code with root privileges, according to Apple.

**********

Two updates from Gentoo:

Libpng (denial of service)

WordPress (multiple flaws)

**********

Three patches from OpenPKG:

texinfo (buffer overflow, code execution)

proftpd (denial of service)

png (denial of service)

**********

Nine updates from Mandriva:

gv (buffer overflow, code execution)

chromium (buffer overflow, code execution)

doxygen (multiple flaws)

pxelinux (multiple flaws)

syslinux (multiple flaws)

libpng (denial of service)

openldap (denial of service)

bind (authentication flaw)

xorg-x11 (integer overflow)

**********

Big virus news of the month:

Uncover DHS’ Virus Gaffe

Wired News issued a request last year under the Freedom of Information Act for documents pertaining to a 2005 computer virus incident that crippled the Department of Homeland Security’s border-screening computers. Wired, 11/02/06.

**********

From the interesting reading department:

Attack code posted for latest Microsoft bugs

Hackers have posted code that could be used to target Microsoft’s Windows operating system in a worm attack. The code, which was published early Thursday on the Milw0rm Web site, works on the Windows 2000 operating system, according to Oliver Friedrichs, director of emerging technologies with Symantec’s Security Response. IDG News Service, 11/16/06.

Security vendor settles charges after getting hacked

Guidance Software Inc., vendor of computer forensics and security products, has settled a complaint filed by the U.S. Federal Trade Commission (FTC), which accused it of failing to take reasonable security measures to protect sensitive computer data. IDG News Service, 11/16/06.