New Microsoft Word attack

Opinion
Dec 7, 20063 mins

* Microsoft warns of new Word attack * Patches from Debian, rPath, FreeBSD, others * MySpace worm uses QuickTime for exploit, and other interesting reading

Today’s bug patches and security alerts:

Microsoft warns of new Word attack

There’s now one more reason to be careful about opening Microsoft Office attachments. Microsoft Corp. warned Tuesday of a new, unpatched memory corruption error in its word-processing software, and said that it was investigating reports of “limited” attacks that exploit the problem. IDG News Service, 12/05/06.

Microsoft advisory

Related Secunia advisory

**********

Two new patches from rPath:

GnuPG (malicious code execution)

kernel (denial of service)

**********

Two patches from FreeBSD:

gtar (symlink attack, file overwrite)

kernel memory (integer overflow, information disclosure)

**********

Three new updates from Ubuntu:

Evince (buffer overflow, code execution)

libgsf (heap overflow, code execution)

xine-lib (buffer overflow, code execution)

**********

New patches from Debian:

Mozilla (multiple flaws)

Mozilla Thunderbird (multiple flaws)

Mozilla Firefox (multiple flaws)

elinks (shell command execution)

asterisk (integer overflow, code execution)

**********

Three new fixes from Mandriva:

ruby (denial of service)

xine-lib (denial of service, code execution)

gv (stack overflow, code execution)

**********

Big virus news of the week:

MySpace worm uses QuickTime for exploit

The social-networking site MySpace.com is under what one computer security analyst calls an “amazingly virulent” attack caused by a worm that steals logon credentials and spreads spam that promotes adware sites. IDG News Service, 12/04/06.

**********

From the interesting reading department:

Disney protected with homegrown security, compliance software

The Walt Disney Co. is locking down its applications with cutting-edge identity management innovations developed in-house that are helping the entertainment giant meet its security, compliance and auditing goals. Network World, 12/06/06.

2006: The year in security

Though Internet-crippling virus attacks now seem to be a thing of the past, PC users didn’t feel a lot more secure in 2006. That’s because online attacks have become more sneaky and professional, as a new breed of financially motivated cyber criminals has emerged as enemy number one. Microsoft Corp. patched more bugs than ever and whole new classes of flaws were discovered in kernel-level drivers, office suites and on widely used Web sites. Vendors’ chatter about security is at an all-time high, but the bad guys are still finding lots of places to attack. IDG News Service, 12/06/06.

EEye opens doors on zero-day flaws

EEye has produced a new service that will specifically track “zero-day” security holes. TechWorld, 12/06/06.

Murder by numbers: Software that can predict would-be killers?

The crime rate in Philadelphia may be worse than people thought. The city today said it is working with University of Pennsylvania criminologist Richard Berk to develop software that can forecast who might commit murder. NetworkWorld.com, 12/04/06.