Storm Worm, Symantec, and Java - The BugBlog Report 1/22/07
Published January 22, 2007
Here are some of the most significant bugs from the past week from BugBlog:
If you want information on the storms hitting Europe, stick to the Weather Channel. Do not open an email attachment that comes with the subject line "230 dead as storm batters Europe". If you do, you may end up with the Storm Worm Trojan Horse that opens a back door on your computer and will later steal data or send out spam. Read more at ZDnet.com.
It's not quite Night of the Living Dead, but an army of remotely controlled zombie computers are targeting computers running old versions of Symantec Client Security and Symantec AntiVirus Corporate Edition. You can read about the details at ZDnet.com. Note that Symantec's consumer software, Norton Antivirus and Norton Internet Security, are not affected. Symantec actually patched the hole being used on 5/25/2006, so victims have had ample time to apply the fix. The original Symantec fix is at Symantec.com.
There is a critical bug in the way that Sun Microsystems Java Runtime Environment handles GIF images. An attacker may be able to use this bug to raise the privileges of a Java applet. This could allow hostile code to run on a computer, outside the confines of the Java sandbox. Sun has updates at Sun.com. They credit the Zero-Day Initiative and Tipping Point for finding this bug.
- Storm Worm, Symantec, and Java - The BugBlog Report 1/22/07
- Published: January 22, 2007
- Type: News
- Section: Sci/Tech
- Filed Under: Sci/Tech: Computers, Sci/Tech: Internet, Sci/Tech: Software
- Part of a feature: BugBlog
- Writer: Bruce Kratofil
- Bruce Kratofil's BC Writer page
- Bruce Kratofil's personal site
- Spread the Word
- Like this article?
- Email this
Save to del.icio.us


![Norton Internet Security 2007 [Old Version] Norton Internet Security 2007 [Old Version]](http://ecx.images-amazon.com/images/I/51JZVHCCFML._SY90_.jpg)


![Zonealarm Internet Security Suite [Old Version] Zonealarm Internet Security Suite [Old Version]](http://ecx.images-amazon.com/images/I/51PACV7AWXL._SY90_.jpg)

