- Cool Yule Tools: 2008 Holiday Gift Guide
- 10 kitchen gadgets for the geek gourmet
- Google admits to violating iPhone development terms
- Smartphone smackdown: Storm vs. iPhone
- Google layoffs: 10,000 jobs being cut
Jason Meserve provides up-to-the-minute news on vendor security alerts and fixes.
Mac OS X v10.5.5 update fixes numerous flaws
The new Mac OS X v10.5.5 update fixes flaws in a number of subsystems: ATS, Bind, ClamAV, Directory Services, Finder, ImageIO,
Kernel, libresolv, Login Window, mDNSResponder, OpenSSH, QuickDraw Manager, Ruby, SearchKit, System Configuration, System
Preferences, Time Machine, VideoConference and Wiki Server. The most serious of the vulnerabilities could be exploited to
run malicious code.
Also:
Apple update finally fixes important DNS bug
US-CERT: Apple Updates for Multiple Vulnerabilities
Apple releases security update for Remote Desktop
A design issue exists in the Open Scripting Architecture libraries when determining whether to load scripting addition plugins
into applications running with elevated privileges. Users should upgrade to version 3.2.2 to fix the vulnerability.
**********
Six new patches from Mandriva:
R-base (symlink, file overwrite)
koffice (denial of service, code execution)
mplayer (memory overwrite, code execution)
Apache2 (cross scripting, script injection)
Kolab Server (password retrieval)
**********
Two new fixes from rPath:
mercurial (permissions error)
**********
Two new patches from Debian:
git-core (buffer overflow, code execution)
**********
Today's malware news:
All Your (Data)base Are Belong to Trojan.Eskiuel
Modern SQL databases are flexible, efficient, and can run commands at an OS level easily-a perfect target from a malicious
code perspective! Our honeypot servers are full of plenty of worms that spread by email, IM, file-sharing, or network vulnerabilities,
so finding a Trojan that targets SQL databases is always an unusual surprise for a virus researcher. Symantec Security Response,
09/17/2008.
Recent Microsoft Vulnerability Exploited in the Wild
Not surprisingly, attackers are again targeting vulnerabilities from the latest set of Microsoft Security Bulletins. This
time around, it is the Microsoft Media Encoder ActiveX overflow patched in MS08-053. This attack chronology is another example
of the rapid adoption of public exploits into widely deployed exploit toolkits. Symantec Security Response, 09/15/2008.
JavaScript Injection Attack
JavaScript injection attacks seem to be the in thing these days. Malware writers are increasingly utilizing such attacks as
a better means to spread their work. F-Secure, 09/18/2008.
Jason Meserve is multimedia editor at Network World.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment