Skip Links

Network World

  • Social Web 
  • Email 
  • Close

To patch or not to patch

Patches from Ubuntu, Debian, Mandriva, others 'Experimental' security fix is malware, Microsoft says Black box for the enterprise protects data from terrorists, hurricanes, and other interesting reading
Security: Threat Alert By Jason Meserve , Network World , 10/16/2008
Sign up for this newsletter now!

Jason Meserve provides up-to-the-minute news on vendor security alerts and fixes.

  • Share/Email
  • Comment
  • Print

Microsoft reveals critical holes in Active Directory, mainframe gateway
Microsoft Tuesday issued four critical patches to close 10 vulnerabilities, some on critical IT systems such as Active Directory. The platforms affected by the critical vulnerabilities include Active Directory, Internet Explorer, Host Integration Server and Excel. In all, Microsoft issued 11 patches (see complete list here). In addition to the four that were critical, six were listed as important and one as moderate.

Microsoft October Patch Tuesday advisory
**********

Adobe patches Flash clickjacking and clipboard-poisoning bugs
Adobe Systems Inc. patched five vulnerabilities in Flash today, including one that could be used in "clickjacking" attacks to secretly spy on users through their webcams. That fix, and others, were rolled into Flash Player 10, the new version of the popular browser plug-in the company launched earlier today. Computerworld. 10/15/2008.

Adobe: Flash Player update available to address security vulnerabilities
**********

Oracle issues 36 patches, but is anyone applying them?
Many database administrators don't always apply security patches to their environments in a speedy fashion, but that's not stopping Oracle Corp. from releasing dozens of them on a quarterly basis. The latest batch was released yesterday and includes fixes for 36 newly discovered vulnerabilities across a wide range of Oracle products. Computerworld, 10/15/2008.

Oracle Critical Patch Update Advisory - October 2008
**********

Half dozen new patches from Ubuntu:

CUPS (multiple flaws)

exiv2 (denial of service)

libexif (denial of service)

D-Bus (security policy bypass)

LittleCMS (denial of service)

Ruby (multiple flaws)
**********

Five new fixes from Debian:

libxml2 (buffer overflow, code execution)

linux-2.6 (denial of service, privilege escalation)

ruby1.9 (multiple flaws)

ruby1.8 (multiple flaws)

openldap2.3 (denial of service)
**********

Four new updates from Mandriva:

D-Bus (security policy bypass)

libxml2 (buffer overflow, code execution)

CUPS (multiple flaws)

mono (HTTP injection)
**********

Today's malware news:

'Experimental' security fix is malware, Microsoft says
Scammers are sending out phoney e-mails that claim to include critical Windows security alerts, Microsoft warned Monday. IDG News Service, 10/13/2008.

Jason Meserve is multimedia editor at Network World.

  • Share/Email
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed