Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Patch Tuesday Lite on tap from Microsoft

Patches from Microsoft, VMware, Ubuntu, others Hackers launch PDF attacks, exploit just-patched Reader bug Android may not need antivirus software, researcher says, and other interesting reading
Security: Threat Alert By Jason Meserve , Network World , 11/10/2008
Sign up for this newsletter now!

Jason Meserve provides up-to-the-minute news on vendor security alerts and fixes.

  • Share/Email
  • Comment
  • Print

Microsoft plans puny patch slate next week
Microsoft Thursday said it will release only two security updates on Tuesday -- down from the 11 issued in October's mammoth Patch Tuesday -- to fix bugs in Windows and Office. One of the two will be rated "critical," Microsoft's highest threat ranking, while the other will be tagged as "important," the next-lowest rating. Both of the updates will address vulnerabilities that can be used to execute remote code, a description that generally means hackers could leverage the bugs in order to plant their own malicious code on vulnerable PCs, often by convincing users to open a file attachment or tricking them into visiting a rogue Web site. Computerworld, 11/06/2008.

Microsoft advanced advisory
**********

VMware patches Hosted products and ESX/ESXi
According to the VMware advisory, "VMware Hosted products and patches for ESX and ESXi resolve multiple security issues. A flaw in the CPU hardware emulation may allow for a privilege escalation on virtual machine guest operating systems. In addition a directory traversal issue is resolved."
**********

Three new patches from Ubuntu:

Dovecot (denial of service)

Netpbm (buffer overflow, code execution)

Tk (buffer overflow, code execution)
**********

Two new updates from Debian:

net-snmp (multiple flaws)

mysql-dfsg-5.0 (bypass authorization)
**********

Two new fixes from Mandriva:

Ruby (multiple flaws)

kernel 2.6 (multiple flaws)
**********

Today's malware news:

Hackers launch PDF attacks, exploit just-patched Reader bug
Attackers are exploiting one of the vulnerabilities in Adobe Reader that was patched earlier this week, a security researcher warned Friday as he urged users to update as soon as possible. Computerworld, 11/07/2008.

Thousands hit in broad Web hack
Hackers have launched a massive Web hacking campaign, putting malicious links on as many as 10,000 servers, security vendor Kaspersky Lab warned Friday. IDG News Service, 11/08/2008.
**********

From the interesting reading department:

Rape Support Site Hacked, Becomes A Home For Phishers
This is a particularly thoughtless and poor-taste hack. This is Rapecrisiscenter.org, a support site for people in the Central Massachusetts area. Unfortunately, the site has apparently suffered multiple attacks which may or may not be related. The SpywareGuide Greynets Blog, 11/6/2008.

Jason Meserve is multimedia editor at Network World.

  • Share/Email
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed