NEWS

Microsoft, Skype, Apple — The BugBlog Report 5/22/06

Written by Bruce Kratofil
Published May 22, 2006
Part of BugBlog

A zero-day bug has been discovered in Microsoft Word, with exploits using this bug already being noticed. If you open a maliciously designed Word document, the bug may be triggered to run hostile code on your computer, including reconfiguration of security software. It appears, according to the Internet Storm Center, that these attacks come from China or Taiwan. Read more at ISC; in the meantime, be careful of opening suspicious Microsoft Word attachments.

There is a bug in the Skype for Windows client that may allow an attacker to initiate a transfer of a specifically named file from one Skype user to another. This will happen if you can get the victim to follow a bad Skype URL. This has been fixed in Skype 2.5, release 2.5.*.79 or later, and in Skype 2.0, release 2.0.*.105 or later. Get links to these updates at Skype Security.

Apple's Security Update 2006-003 squashes a bug in LaunchServices for Mac OS X 10.4.6 Client and Server. According to Apple, a long file name extension may interfere with Download Validation. This may let an attacker design a file with unsafe content, but appears to be safe to Mac OS X 10.4, which will then let an application, such as Safari, open the file. The security update does a better job of checking long file name extensions. Security Update 2006-003 includes many more fixes for bugs that may allow an attacker to run hostile code on your computer.

Bruce Kratofil blogs on bugs and other things that can go wrong with your computer at The BugBlog, and writes about computers and economics at BJK Research
Keep reading for information and comments on this article, and add some feedback of your own!
Microsoft, Skype, Apple — The BugBlog Report 5/22/06
Published: May 22, 2006
Type: News
Section: Sci/Tech
Filed Under: Sci/Tech: Computers, Sci/Tech: Internet, Sci/Tech: Software
Part of a feature: BugBlog
Writer: Bruce Kratofil
Bruce Kratofil's BC Writer page
Bruce Kratofil's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
Articles in this series
BC articles by Bruce Kratofil
Sci/Tech: Computers
Sci/Tech: Internet
Sci/Tech: Software
All Sci/Tech Articles
Bruce Kratofil's personal weblog
All News articles
All BC articles
All BC Comments

Comments

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/48103)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments