Security Bulletin
of October 11, 2006
Overview
Who is Affected
Recommended Actions
Administrative Users
Academic and
All Home Windows Users
Academic and
All Home Macintosh Users
Tips for Safer Computing
Further Assistance
Other Bulletins
Recent CERT Alerts
|
ADMINISTRATIVE
Staff: If you use a computer at HOME,
please read on.
STUDENTS, FACULTY,
ADMINISTRATIVE STAFF, ACADEMIC STAFF
AND ALL HOME USERS must follow the
recommendations below.
I.
OVERVIEW
Serious security holes have been
identified in Microsoft Windows,
Microsoft Explorer, Microsoft Office,
Macintosh OS X version 10.3.9 (Panther)
and version 10.4.7 (Tiger), Safari
and Flash. Many of these threats
could allow a remote user to take
over your computer.
October 2, Apple released
Security Update 2006-006 to address
these vulnerabilities. October 10,
Microsoft released ten updates, including
six updates designated as critical,
and one designated as important.
To protect your computer, and other
computers on the network, follow
the instructions for your system(s)
below.
II. WHO
IS AFFECTED?
Both Macintosh and Windows computers
are vulnerable to at least some of
these serious security threats.
III. RECOMMENDED
ACTION - ADMINISTRATIVE USERS ON CAMPUS
Administrative Computing will upgrade systems in Administrative Offices, but you must upgrade your home systems. Please follow the recommended actions
for Window or Macintosh home systems.
IV. RECOMMENDED
ACTION - STUDENTS, FACULTY, ACADEMIC
STAFF, and ALL HOME WNDOWS COMPUTER USERS
- Install all Windows
critical updates. Open
INTERNET EXPLORER
and go to http://update.microsoft.com/
-
If you have not yet done so, set
your computer to automatically
download new Microsoft updates.
- Office 2000 users must install
updates from a second site. Open
INTERNET EXPLORER and navigate
to http://office.microsoft.com/officeupdate
- If you have not yet done
so, install
Windows Defender from
http://www.microsoft.com/athome/security/spyware/software/
This free program from Microsoft
that helps protect your computer
against pop-ups, slow performance
and security threats caused by
spyware and other potentially unwanted
software.
- New versions of our McAfee anti-virus
software were made available late
August. If you have not yet done
so, follow
the directions at http://www.haverford.edu/acc/virus/xpantivirus.html to install VirusScan 8.
V. RECOMMENDED
ACTION - STUDENTS, FACULTY, ACADEMIC
STAFF, and ALL HOME MACINTOSH COMPUTER USERS
- Install all Macintosh OS
critical updates.
- Under the Apple Menu select System Preferences.
- Double-click on Software Update.
- Check the option to Automatically check for updates weekly.
- Run Check Now
- Install required updates
and reboot if prompted.
- Repeat steps above until
all needed updates are installed.
- If you have not yet done so,
set your computer to automatically
download new Mac updates.
- Install all Office critical updates. Navigate to http://www.microsoft.com/mac/downloads.aspx and
install the updates appropriate
to your version of Office.
- New versions of our McAfee antivirus
software were made available late
August. If you have not yet installed
the current versions, following
the directions at http://www.haverford.edu/acc/virus/macantivirus.html.
- Confirm that you have the most recent virus definitions.
- Double-click on the Virex icon.
- Click on the eUpdate button.
VI. PRACTICE SAFER COMPUTING ALL THE TIME
Always follow the guidelines to Protect Your Computer at http://www.haverford.edu/acc/protect/.
VII. FOR FURTHER
ASSISTANCE
Students, faculty and academic
staff please contact Academic Computing:
Telephone: 610-896-1480
Email: helpdesk@haverford.edu
Web: http://www.haverford.edu/acc/helpdesk/
In Person: Stokes 204 9am to 5pm,
Monday through Friday and until 9am
to 9pm on Tuesdays.
Administrative staff please
contact Administrative Computing:
Telephone: 610-896-1355
Email: admincc@haverford.edu
VI. MORE INFORMATION
Additional information about computer
security and current threats can be found at the following sites:
- United States Computer Emergency Readiness Team (US-CERT )
- <http://www.us-cert.gov/nav/nt01/>
- McAfee Avert Threat Center
- <http://www.mcafee.com/us/threat_center/default.asp>
- Microsoft Security
- <http://www.microsoft.com/security/>
- Apple Product Security
- <http://www.apple.com/support/security/>
|