Security Bulletin
of September 15, 2006
Overview
Who is Affected
Recommended Actions
Administrative Users
Academic and
All Home Windows Users
Academic and
All Home Macintosh Users
Tips for Safer Computing
Further Assistance
Other Bulletins
Recent CERT Alerts
|
ADMINISTRATIVE
Staff: If you use a computer at HOME,
please read on.
STUDENTS, FACULTY,
ADMINISTRATIVE STAFF, ACADEMIC STAFF
AND ALL HOME USERS must follow the
recommendations below.
I.
OVERVIEW
Serious security holes have been
identified in Microsoft Windows,
Microsoft Word, Microsoft Publisher,
and Apple QuickTime and Flash Player.
To protect your computer, and other
computers on the network, follow
the instructions below. This will
install all the applicable critical
and important updates issued by Microsoft
on September 12, 2006. If you missed
earlier Microsoft updates, it will
apply those as well.
In addition to applying the updates
described below, do not open unfamiliar
or unexpected Microsoft Word or
other Office documents, including
those received as email attachments
or hosted on a web site. A vulnerability
in Microsoft Word, for which there
is not yet a fix, could allow an
attacker to gain control of your
computer.
II. WHO
IS AFFECTED?
Both Macintosh and Windows computers
are vulnerable to at least some of
these serious security threats.
III. RECOMMENDED
ACTION - ADMINISTRATIVE USERS ON CAMPUS
Administrative Computing will upgrade systems in Administrative Offices, but you must upgrade your home systems. Please follow the recommended actions
for Window or Macintosh home systems.
IV. RECOMMENDED
ACTION - STUDENTS, FACULTY, ACADEMIC
STAFF, and ALL HOME WNDOWS COMPUTER USERS
- Install all Windows
critical updates. Open
INTERNET EXPLORER
and go to http://update.microsoft.com/
-
If you have not yet done so, set
your computer to automatically
download new Microsoft updates.
- Upgrade
to Apple QuickTime version 7.1.3 at
http://www.apple.com/quicktime/download/win.html
- Install
the latest version of Flash Player on your computer from http://www.macromedia.com/go/getflashplayer/
- Install
Windows Defender from
http://www.microsoft.com/athome/security/spyware/software/
This free program from Microsoft
that helps protect your computer
against pop-ups, slow performance
and security threats caused by
spyware and other potentially unwanted
software.
- Confirm that you have the most
recent virus software, and current
virus definitions at http://www.haverford.edu/acc/virus/xpantivirus.html
V. RECOMMENDED
ACTION - STUDENTS, FACULTY, ACADEMIC
STAFF, and ALL HOME MACINTOSH COMPUTER USERS
- Install all Macintosh OS
critical updates. This will update
QuickTime, and get any other updates
you may have missed.
- Under the Apple Menu select System Preferences.
- Double-click on Software Update.
- Check the option to Automatically check for updates weekly.
- Run Check Now
- Install required updates
and reboot if prompted.
- Repeat steps above until
all needed updates are installed.
- If you have not yet done so,
set your computer to automatically
download new Mac updates.
- Install the latest version
of Flash Player on your
computer from http://www.macromedia.com/go/getflashplayer/
- Install all Office critical updates. Navigate to http://www.microsoft.com/mac/downloads.aspx and
install the updates appropriate
to your version of Office.
- New versions of our McAfee antivirus
software were made available late
August. If you have not yet installed
the current versions, following
the directions at http://www.haverford.edu/acc/virus/macantivirus.html.
- Confirm that you have the most recent virus definitions.
- Double-click on the Virex icon.
- Click on the eUpdate button.
VI. PRACTICE SAFER COMPUTING ALL THE TIME
Always follow the guidelines to Protect Your Computer at http://www.haverford.edu/acc/protect/.
VII. FOR FURTHER
ASSISTANCE
Students, faculty and academic
staff please contact Academic Computing:
Telephone: 610-896-1480
Email: compctr@haverford.edu
Web: http://www.haverford.edu/acc/helpdesk/
In Person: Stokes 204 9am to 5pm,
Monday through Friday and until 9am
to 9pm on Tuesdays.
Administrative staff please
contact Administrative Computing:
Telephone: 610-896-1355
Email: admincc@haverford.edu
VI. MORE INFORMATION
Additional information about computer
security and current threats can be found at the following sites:
- United States Computer Emergency Readiness Team (US-CERT )
- <http://www.us-cert.gov/nav/nt01/>
- McAfee Avert Threat Center
- <http://www.mcafee.com/us/threat_center/default.asp>
- Microsoft Security
- <http://www.microsoft.com/security/>
- Apple Product Security
- <http://www.apple.com/support/security/>
|