Security 10918 Published by Philipp Esselbach 0

Internet privacy researcher Richard Smith released on Thursday a list of four issues that continue to undermine the security of Microsoft's Outlook 2002 and could leave the major mail program open to attack by virus writers.

Read more

Security 10918 Published by Philipp Esselbach 0

Thanks to Ryan for sending me this security alert from WatchGuard:

In a post to NTBugtraq on March 14, Radim EliCZ Picha described a design flaw in the Windows NT and 2000 debugging subsystem that could result in elevated privileges. Picha also included exploit code. Experts at WatchGuard have confirmed that a hacker can use this exploit to elevate any local user, even Guest, to local Administrator. There is no direct impact on WatchGuard products. Administrators using Windows NT and 2000, servers and workstations, should recognize this vulnerability and know how to defend against it. A patch is not yet available.

Security 10918 Published by Philipp Esselbach 0

A security flaw in open-source software used by Linux and Unix systems for compression may affect some Microsoft products that also use the code.

As reported earlier this week by CNET News.com, a flaw in the zlib software-compression library could leave much of the systems based on the open-source operating system Linux open to attack.

Read more

Security 10918 Published by Philipp Esselbach 0

A worm posing as an old-fashioned photograph of a girl holding a flower is making the rounds on the Internet. MyLife (w32.mylife@mm) is a 30,720-byte worm written in Visual Basic and compressed using UPX. If executed, the worm will attempt to mail copies of itself to everyone in the user's address book and will attempt to delete critical Windows files. Fortunately, a bug in the current worm code prevents MyLife from deleting any files.

Read more