* Patches from Apple, SuSE, rPath, others * Symantec: Storm Trojan worst outbreak since 2005 * Widgets: The next big security threat?, and other interesting reading
Today’s bug patches and security alerts:
Apple patches security flaw in QuickTime
Apple has patched a vulnerability in its QuickTime media player that could give a hacker control over a computer. The problem concerns a buffer overflow that can occur when QuickTime processes a RTSP URL, which directs the player to a streaming file and allows a user to play and pause it. IDG News Service, 01/24/07.
**********
US-CERT warns of Java vulnerabilities
According to the US-CERT advisory, the Sun Java Runtime Environment (JRE) contains multiple flaws that could be exploited to run malicious code on an affected system.
**********
US-CERT warns of multiple flaws in Cisco IOS
According the advisory, “Several vulnerabilities have been discovered in Cisco’s Internet Operating System (IOS). A remote attacker may be able to execute arbitrary code on an affected device, cause an affected device to reload the operating system, or cause other types of denial of service.”
Related Cisco advisories:
Cisco Security Advisory: Crafted TCP Packet Can Cause Denial of Service
Cisco Security Advisory: Crafted IP Option Vulnerability
Cisco Security Advisory: Cisco Security Advisory: IPv6 Routing Header Vulnerability
**********
Two new updates from SuSE:
xine (multiple format string flaws)
**********
Five new patches from rPath:
libgtop (denial of service, code execution)
poppler (denial of service, code execution)
**********
Nine new fixes from Gentoo:
Centericq (buffer overflow, code execution)
OpenLDAP (non-secure temp files)
xine (multiple format string flaws)
libgtop (denial of service, code execution)
Adobe Acrobat Reader (multiple flaws)
Mod_auth_kerb (denial of service)
Fetchmail (denial of service, password disclosure)
**********
Three updates from Mandriva:
kdegraphics (denial of service, code execution)
**********
Two new fixes from Debian:
**********
Three new patches from Ubuntu:
BlueZ (keyboard/mouse control)
**********
Today’s virus-related news:
Symantec: Storm Trojan worst outbreak since 2005
Malicious software that was sent out in millions of spam messages over the weekend has now infected about 300,000 computers, making it the worst malware outbreak since 2005, Symantec said Monday. IDG News Service, 01/22/07.
(Note: An anonymous poster correctly pointed out that clicking on .exe file attachments in e-mail is pretty stupid.)
**********
From the interesting reading department:
Widgets: The next big security threat?
Desktop gadgets and widgets that display system information and other data, like weather forecasts, are becoming so popular they could become the next big security threat, says Eric Chien, security response engineer at Symantec. Computerworld, 01/23/07.
Latest McAfee upgrade jams up Lotus Notes
The latest upgrade to McAfee’s VirusScan Enterprise security software is causing hiccups for some versions of IBM’s Lotus Notes, the companies warned. IDG News Service, 01/23/07.
Researcher says PatchGuard changes helped Microsoft
Microsoft has come under fire for quietly releasing a fix to its PatchGuard kernel protection software in order to improve the performance of its Virtual Server 2005 product. IDG News Service, 01/19/07.
Hackers steal from customers of U.S. federal savings plan
Hackers stole $35,000 from two dozen users of the Thrift Savings Plan (TSP), a retirement savings and investment plan for U.S. federal employees. Computerworld, 01/19/07.
Google antiphishing site exposes private user data
Google has removed a few user names and passwords posted inadvertently to a phishing blacklist it compiles and makes publicly available on the Web, the Mountain View, Calif., company said Monday. IDG News Service, 01/22/07.
Identity theft pays, just ask Martha Coakley
As anybody who has ever been the victim of identity theft knows, the reason it’s so common is because it pays. And why does it pay? Because identity thieves never go to jail. IDG News Service, 01/22/07.
Cloudmark upgrades e-mail security software
E-mail security vendor Cloudmark on Tuesday released an upgrade to its Authority software that includes an e-mail rescanning feature designed to catch the latest Internet threats. Network World, 01/23/07.




