* Patches from Apple, Gentoo, Mandriva, others * Big virus-related news of the week * Trend Micro: Windows zero-day exploit for sale, and other interesting reading
endif; ?>This is our last newsletter of 2006. We’ll be back the first week in January.
Happy Holidays!
Today’s bug patches and security alerts:
Mozilla fixes bugs with first update to Firefox 2.0
Mozilla has released the first update for the Firefox 2.0 browser to fix eight security vulnerabilities. According to the company, release 2.0.0.1 of Firefox fixes flaws in memory corruption as well as the way the browser executes RSS, Javascript and CSS (cascading style sheets) code, among other vulnerabilities. Mozilla also patched similar flaws in its Firefox 1.5 browser.
Firefox known vulnerabilities listing
**********
A flaw in the way QuickTime for Java interacts with local data has been changed so that data may not be stolen from an affected system. A free update is available from Apple.
**********
Four new updates from Gentoo:
pam_ldap (unauthorized access via locked account)
**********
Two new patches from Mandriva:
proftpd (stack overflow, code execution)
**********
Three patches from Debian:
**********
Miscellaneous Linux updates:
Ubuntu – Mono (application source disclosure)
rPath – libgsf (denial of service, code execution)
Trustix – ClamAV (denial of service)
OpenPKG – proftpd (stack overflow, code execution)
**********
Big virus-related news of the week:
Worm may be spreading via Skype chat
Computer security analysts are studying reports of a worm that may be circulating via a feature in Skype’s popular VoIP service. IDG News Service, 12/19/06.
Top 5 viruses for the week of 12/4, as reported by CA:
**********
From the interesting reading department:
Trend Micro: Windows zero-day exploit for sale
An online criminal has offered to sell software that exploits an unpatched bug in Microsoft’s Windows Vista operating system, according to security vendor Trend Micro. IDG News Service, 12/18/06.
Apple to get a month of security bugs
Apple will soon be a member of the “month of bugs” club. On Jan. 1, two security researchers will begin publishing details of a flood of security vulnerabilities in Apple’s products. Their plan is to disclose one bug per day for the entire month, they said Tuesday. IDG News Service, 12/19/06.
Kaspersky: Malware quality drops, quantity rises
They just don’t make malware like they used to. Or at least like they did earlier this year. Even low-quality malware, however, is taxing the resources of security companies because it is being detected in ever-higher numbers. IDG News Service, 12/18/06.
Kaspersky: Vista will not changes security concerns
Vista’s arrival will not thaw Microsoft’s security misery, the CEO of Russian security company Kaspersky Lab has said in a chilly broadside against the software giant. TechWorld, 12/20/06.
HP tightens security in HP-UX
HP is enhancing security features on the HP-UX operating system for its Integrity line of servers amid growing customer concern about recent network security breaches. HP is announcing Monday the availability of a free upgrade to HP-UX 11i v2 that automatically encrypts data as it is stored. HP has offered this capability before, but this upgrade puts the encryption capability right into the operating system. IDG News Service, 12/18/06.
The Panda Software virus yearbook 2006
Sure, it’s a marketing ploy. But it is an interesting read.




