ALERT!

--Microsoft Security Bulletin MS02-050: Certificate Validation Flaw Could Enable Identity Spoofing (Q328145). This one was issued last night and it affects Macs--Microsoft Office for Mac, Microsoft Internet Explorer for Mac, or Microsoft Outlook Express. So far the only patches are for Windows NT 4.0 and Windows XP, not the Mac client applications which are listed as moderate risks. A patch for them will be forthcoming in due course according to Microsoft. From the FAQ:

The vulnerability could enable an attacker to create bogus a digital certificate that would nevertheless pass validation. Depending on the usage, this could enable a variety of attacks, such as:

* Creating a web site that could successfully pose as a different web site, in the hope that visitors would provide sensitive information to it.
* Sending an email whose digital signature would attest that it was sent by someone other than the actual sender.
* Posing as another user by providing a bogus digital certificate as authentication.
* Digitally signing a dangerous program in the guise of a trustworthy user or company, in order to convince a user that it was safe to run it.

Pretty nasty stuff if you have a PayPal account or visit on line credit card pages. It's time to lay off the M$ apps until a patch comes out.

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive