* Patches from Apple, Trustix, Mandriva, others * Beware new Tilebot variant that exploits known Windows flaws as it spreads between network shares * Researchers: OpenOffice.org security 'insufficient', and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Symantec identifies Vista weaknesses
Symantec has released a report outlining some weaknesses in the kernel protection mechanisms built into a beta version of Windows Live. The report found several potential weaknesses — among them the tight integration of content copy protection (known as digital rights management, or DRM) into the operating system. TechWorld, 08/10/06.
**********
Apple releases security update for Mac Book Pro
An wide-ranging update released earlier this month for the Mac OS did not include two patches for Mac Book Pro users. This latest update fixes flaws in OpenSSH and ImageIO for Mac Book Pro. Other Mac systems already received this update.
**********
Trustix releases a new “multi” update
The newest “multi” update from Trustix fixes flaws in ClamAV and the Trustix Linux kernel. The most serious of the flaws could be exploited to cause a buffer overflow.
**********
SuSE, Mandriva, Gentoo patch ClamAV
According to the SuSE advisory, “Damian Put discovered a bug in the UPX decoder used for scanning UPX compressed Windows executables. The bug allows for a heap buffer overflow and may potentially be exploitable to execute arbitrary code. ClamAV has been version updated to Version 0.88.4 in order to fix this problem.”
**********
According to the Ubuntu advisory, “An integer overflow was found in the handling of the MaxRecordSize field in the WMF header parser. By tricking a user into opening a specially crafted WMF image file with an application that uses this library, an attacker could exploit this to execute arbitrary code with the user’s privileges.”
**********
Today’s roundup of virus alerts:
Worm fears raised after release of Windows malware
Attack code exploiting a recently-patched vulnerability in Microsoft’s Windows operating system has been posted to the Internet, prompting concerns of a widespread attack. IDG News Service, 08/10/06.
Troj/Agent-CST — A Windows Trojan designed to steal information from the infected host. It is installed as “win???32.dll” in the Windows System folder. (Sophos)
Troj/Tfactory-A — A Trojan that claims to remove spyware and adware, but actually does the opposite. It installs a number of files in the system directory, including “officescan.exe”, and creates a number of fake spyware files. (Sophos)
Troj/Zapchas-BX — A Trojan based on the mIRC client. It is designed to allow backdoor access through an IRC channel and installs a number of files in the Windows System folder, including “svchost.exe”. (Sophos)
Troj/Goldun-DS — This Trojan monitors Internet activity in an effort to steal passwords, particularly to the site e-gold.com. It drops the file “vmmdiag3.exe” on the infected host. (Sophos)
W32/Tilebot-GE — A new Tilebot variant that exploits known Windows flaws as it spreads between network shares. It drops “win325b.exe” in the Windows folder and allows backdoor access through IRC. (Sophos)
W32/Brontok-BG — An e-mail Trojan that spreads through a message titled “Foto Liburanku di Bali” or “My Photo on Paris” and comes with an attachment called “Picture.zip”. If opened, the virus drops a number of randomly named files in the Windows and System folders. It modifies the Windows HOSTS file to limit access to security-related Web sites. (Sophos)
**********
From the interesting reading department:
Researchers: OpenOffice.org security ‘insufficient’
With Microsoft’s Office suite now being targeted by hackers, researchers at the French Ministry of Defense say users of the OpenOffice.org software may be at even greater risk from computer viruses. IDG News Service, 08/11/06.
All-in-one security devices face challenges
The multipurpose security appliances that consolidate firewall/VPN, content filtering, intrusion prevention and more into a single box are winning favor as easy-to-manage devices. But the open secret about these unified threat management (UTM) appliances is that they take a bite out of bandwidth as they inspect content. Network World, 08/09/06.
How one firm secures mobile workers
A small, fast-growing medical staffing company in Irving, Texas, has been learning as it goes about how to create and enforce secure computing for its traveling account managers. NetworkWorld.com, 08/09/06.




