Lucky 7 patches from Microsoft

Opinion
Dec 14, 20062 mins

* Patches from Microsoft, Gentoo, Mandriva, others * Terrorists may try cyberattacks, Russian expert say, and other interesting reading

Today’s bug patches and security alerts:

Microsoft fixes IE, Windows Media Player flaws

Microsoft has rolled out its monthly security updates for December, patching critical flaws in Internet Explorer, Windows Media Format and the Visual Studio 2005 development software. The seven security patches address 11 bugs, including two in the Windows Media Player software. However, no fixes were provided for two Microsoft Word flaws that have been used in a small number of attacks over the past week. IDG News Service, 12/12/06.

Microsoft patches:

Cumulative Security Update for Internet Explorer

Vulnerability in Visual Studio 2005 Could Allow Remote Code Execution

Vulnerability in Windows Media Format Could Allow Remote Code

Vulnerability in SNMP Could Allow Remote Code

Vulnerability in Windows Could Allow Elevation of Privilege

Cumulative Security Update for Outlook Express

Vulnerability in Remote Installation Service Could Allow Remote Code Execution

Related advisories:

US-CERT

Symantec Security Response

Hackers attack using second Word flaw

With its monthly security updates due out Tuesday, Microsoft has a new problem to worry about: Word flaws. The software vendor on Sunday confirmed a report that criminals are e-mailing maliciously crafted Word attachments to victims. While these attacks are not widespread, they are dangerous because the attacker could run unauthorized software on the victim’s computer if the attachment is opened. IDG News Service, 12/11/06.

**********

Eleven new patches from Gentoo:

GnuPG (multiple flaws)

ModPlug (multiple buffer overflows, code execution)

KOffice shared libraries (heap overflow, code execution)

Mozilla Thunderbird (multiple flaws)

Mozilla Firefox (multiple flaws)

SeaMonkey (multiple flaws)

MadWifi (code execution)

Tar (directory traversal, file overwrite)

F-PROT Antivirus (multiple flaws)

libgsf (buffer overflows)

Trac (cross site forgery)

**********

Three new updates from Mandriva:

squirrelmail (cross scripting attack)

kdegraphics (stack overflow, denial of service)

GnuPG (multiple flaws)

**********

Four new Debian patches:

enemies-of-carlotta (missing sanitization checks)

ruby1.8 (denial of service)

ruby1.6 (denial of service)

kernel 2.6.8 (multiple flaws)

**********

Two new fixes from rPath:

evince (code execution)

squirrelmail (cross scripting)

**********

From the interesting reading department:

Terrorists may try cyberattacks, Russian expert says

A Russian computer security expert predicts that terrorists could seek to target the country’s critical infrastructure through electronic warfare, a strategy that could raise the stakes in how Russia handles computer crime. IDG News Service, 12/13/06.

Breach at UCLA exposes data on 800,000

The University of California, Los Angeles, Tuesday began sending out letters to more than 800,000 individuals whose personal information may have been compromised in a database breach that remained undetected for more than a year. Computerworld, 12/12/06.