Recapping Patch Tuesday

Opinion
Nov 16, 20063 mins

* Patches from Microsoft, Trustix, Gentoo, others * Top 10 viruses from the past 7 days, according to Trend Micro * Microsoft labels Google's Gmail as virus, and other interesting reading

Earlier this week, we shared a question from a reader who was having problems with Symantec Anti-Virus and asked fellow readers to submit potential fixes. We got a couple answers that hopefully will help:

Earlier this week, we shared a question from a reader who was having problems with Symantec Anti-Virus and asked fellow readers to submit potential fixes. We got a couple answers that hopefully will help:

Ken writes in:

“I would suggest uninstalling and reinstalling Norton. That usually fixes any problems I have had in the past.” He adds that he used to recommend Symantec to everyone but not longer does.

Tony suggests:

“This might have been tried, but have they checked to see if the personal firewall that comes with the ’05 and ’06 versions is running? If it is, check to see if ports 443 or 8443 are blocked, or even have rules set up for them. Other item to check, is there another firewall that could be in the way?”

And George provided URLs to sites that might hold the answer to our reader’s problem, here, here, here and

here.

Thanks to all who wrote in. If you have a security-related problem that you think our readership could help solve, send me e-mail and we’ll get it into a future newsletter.

Today’s bug patches and security alerts:

Microsoft releases six security updates

Microsoft has issued six security updates, fixing critical bugs in Windows components ranging from Internet Explorer to the Microsoft NetWare client service. The updates were released Tuesday morning local time as part of Microsoft’s monthly cycle of security patches. Five of this month’s updates are rated critical by Microsoft, meaning that these bugs could be exploited by attackers to run unauthorized software on a system without user action. Microsoft rates the sixth update, which fixes the NetWare flaw, as “important.” IDG News Service, 11/14/06.

Microsoft advisories:

Cumulative Security Update for Internet Explorer

Vulnerability in Microsoft Agent Could Allow Remote Code Execution

Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution

Vulnerability in Workstation Service Could Allow Remote Code Execution

Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution

Vulnerabilities in Client Service for NetWare Could Allow Remote Code Execution

Related US-CERT advisory

**********

New Trustix multi patch

A new update from Trustix patches flaws in bind, OpenSSH, RPM and TextInfo. The flaws could be exploited to gain elevated privileges and run malicious code.

**********

Three updates from Gentoo:

OpenSSH (denial of service)

GraphicsMagick (multiple buffer overflows)

RPM (buffer overflow, code execution)

**********

Six patches from Debian:

phpmyadmin (multiple flaws)

bugzilla (multiple flaws)

trac (validation error)

Firfox (multiple flaws)

pdns (buffer overflow, code execution)

OpenSSH (denial of service)

**********

Five patches from VMWare:

VMware ESX Server 2.5.4 Upgrade Patch 1

VMware ESX Server 2.5.3 Upgrade Patch 4

VMware ESX Server 2.1.3 Upgrade Patch 2

VMware ESX Server 2.0.2 Upgrade Patch 2

VMware ESX Server 3.0.0 AMD fxsave/restore issue

**********

Top 10 viruses from the past 7 days, according to Trend Micro:

1. Troj_Generic (20,982)Adw_Websearch.K (13,458)Worm_Nyxem.E (11,493)Html_Netsky.P (8,815)Worm_Netsky.Dam (7,986)Worm_Prskey.A (6,384)Worm_Rontkbr.Gen (4,850)Pe_Parite.A (4,749)Java_Bytever.A (2,782)Adw_Ncase.A (2,735)

2.

3.

4.

5.

6.

7.

8.

9.

10.

**********

From the interesting reading department:

Microsoft labels Google’s Gmail as virus

Microsoft’s fledgling consumer antivirus service, Windows Live OneCare, wrongly identified Google’s Gmail service as a virus infection last week, Microsoft has admitted. TechWorld, 11/15/06.

Security group ranks human error as top security worry

The SANS Institute has some controversial advice for computer security professionals looking to lock down their networks: spear-phish your employees. IDG News Service, 11/15/06.