Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Bugs and Fixes: Stymie Malicious Media, Attacks

October 23, 2009 04:35 PM ET

PC World - Essential OS fixes are big this month. And fans of free software need to update their Firefox and OpenOffice copies.

Apple's QuickTime 7.6.4 update revises the program's handling of .fpx, .mov, and .mp4 files on Windows XP, Vista, or 7, or Mac OS X (not Snow Leopard). In QuickTime, click Help•Update Existing Software to ensure that you have version 7.6.4 (for details, see Apple's "About the security content of QuickTime 7.6.4" page).

Microsoft's patch plugs a security hole in the way Windows 2000, XP, Server 2003, Vista, and Server 2008 (but not Windows 7) process .asf or .mp3 media files. Microsoft's Security Bulletin MS09-047 lists many vulnerable combinations of Windows Media Format Runtime and OS versions; run Windows Update to confirm you have the fix.

Network Flaws

Windows Vista and Server 2008 are vulnerable to several network-based security flaws. One, an SMBv2 file-sharing hole could let a re­­mote attacker take over a machine. Microsoft hasn't yet released a patch, but the company has posted a "Fix It" for disabling SMBv2. File sharing should work, but it may be slow.

Microsoft did patch a flaw that malicious TCP/IP packets sent across a network might exploit. On Vista and Server 2008, that could mean a full takeover; on Windows 2000, Server 2003, and XP, a system crash is likelier. Microsoft won't re­­lease a patch for Windows 2000 (see Microsoft Security Bulletin MS09-048) or XP (which by de­­fault doesn't accept the perilous packets).

A network problem in the Wireless LAN AutoConfig Service (see Microsoft Security Bulletin MS09-049) could let remote attackers "own" vulnerable Vista or Server 2008 systems. PCs that lack wireless cards or run other Windows versions are safe. A firewall will help block such Web-based assaults.

Two more Microsoft patches correct critical flaws that might let code hidden on a Web page run commands on a vulnerable PC. One, in the JScript Scripting Engine (see Microsoft Security Bulletin MS09-045), affects Windows 2000, XP, Server 2003, Vista, and Server 2008. The other involves the DHTML Editing Component ActiveX control (see Microsoft Security Bulletin MS09-046), and is critical for Windows XP and 2000 only. Windows Update has both fixes, as usual.

Fixes for Free Software

If you use the OpenOffice productivity suite, update to version 3.1.1 or later to avoid a critical problem in how OpenOffice handles Microsoft Word documents. If you open a tainted .doc file, an at­­tacker could take over your PC. Click Help•Check for Updates to see whether you have the latest version (for more details, see OpenOffice.org's 3.1.1 Release Notes).

Firefox versions 3.5.3 and 3.0.14 correct three critical flaws. Click Help•Check for Updates, and see Mozilla's security advisories for Firefox 3.0 and for Firefox 3.5.

Firefox 3.0 and 3.5 include a security feature that warns you to update Flash if your version is vulnerable; they also provide a link to the Flash download site.

If you use Mac OS X versions 10.4 through 10.5.8, fire up Software Update to pick up Security Update 2009-005, which fixes image file, PDF file, or Web site holes.


Originally published on www.pcworld.com. Click here to read the original story.

Jump to comments

Apple

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs