Mozilla patches 8 Firefox bugs

Opinion
Dec 21, 20063 mins

* Patches from Apple, Gentoo, Mandriva, others * Big virus-related news of the week * Trend Micro: Windows zero-day exploit for sale, and other interesting reading

This is our last newsletter of 2006. We’ll be back the first week in January.

Happy Holidays!

Today’s bug patches and security alerts:

Mozilla fixes bugs with first update to Firefox 2.0

Mozilla has released the first update for the Firefox 2.0 browser to fix eight security vulnerabilities. According to the company, release 2.0.0.1 of Firefox fixes flaws in memory corruption as well as the way the browser executes RSS, Javascript and CSS (cascading style sheets) code, among other vulnerabilities. Mozilla also patched similar flaws in its Firefox 1.5 browser.

Firefox known vulnerabilities listing

Related Secunia advisory

**********

Apple patches QuickTime flaw

A flaw in the way QuickTime for Java interacts with local data has been changed so that data may not be stolen from an affected system. A free update is available from Apple.

**********

Four new updates from Gentoo:

ClamAV (denial of service)

pam_ldap (unauthorized access via locked account)

imlib2 (multiple flaws)

Ruby (denial of service)

**********

Two new patches from Mandriva:

proftpd (stack overflow, code execution)

dbus (denial of service)

**********

Three patches from Debian:

Linux 2.4.27 (multiple flaws)

ClamAV (denial of service)

sql-ledger (multiple flaws)

**********

Miscellaneous Linux updates:

Ubuntu – Mono (application source disclosure)

rPath – libgsf (denial of service, code execution)

Trustix – ClamAV (denial of service)

OpenPKG – proftpd (stack overflow, code execution)

**********

Big virus-related news of the week:

Worm may be spreading via Skype chat

Computer security analysts are studying reports of a worm that may be circulating via a feature in Skype’s popular VoIP service. IDG News Service, 12/19/06.

Websense advisory

Top 5 viruses for the week of 12/4, as reported by CA:

1. Win32/Stration.WJ

2. Win32/Stration Family

3. Win32.Mytob.CZ

4. Win32.Mydoom.N

5. Win32.Mydoom.O

**********

From the interesting reading department:

Trend Micro: Windows zero-day exploit for sale

An online criminal has offered to sell software that exploits an unpatched bug in Microsoft’s Windows Vista operating system, according to security vendor Trend Micro. IDG News Service, 12/18/06.

Apple to get a month of security bugs

Apple will soon be a member of the “month of bugs” club. On Jan. 1, two security researchers will begin publishing details of a flood of security vulnerabilities in Apple’s products. Their plan is to disclose one bug per day for the entire month, they said Tuesday. IDG News Service, 12/19/06.

Kaspersky: Malware quality drops, quantity rises

They just don’t make malware like they used to. Or at least like they did earlier this year. Even low-quality malware, however, is taxing the resources of security companies because it is being detected in ever-higher numbers. IDG News Service, 12/18/06.

Kaspersky: Vista will not changes security concerns

Vista’s arrival will not thaw Microsoft’s security misery, the CEO of Russian security company Kaspersky Lab has said in a chilly broadside against the software giant. TechWorld, 12/20/06.

HP tightens security in HP-UX

HP is enhancing security features on the HP-UX operating system for its Integrity line of servers amid growing customer concern about recent network security breaches. HP is announcing Monday the availability of a free upgrade to HP-UX 11i v2 that automatically encrypts data as it is stored. HP has offered this capability before, but this upgrade puts the encryption capability right into the operating system. IDG News Service, 12/18/06.

The Panda Software virus yearbook 2006

Sure, it’s a marketing ploy. But it is an interesting read.