Chrome dinged; Patches from Cisco

Opinion
Sep 4, 20082 mins

* Chrome dinged * Patches from Cisco

When will companies learn to stop proclaiming new products as the most secure? It only invites attacks. Just ask Google. The company touted its new Chrome browser as being built from the ground up and therefore not vulnerable to some of the same issues as other older browsers. Well, it only took 48 hours for flaws in Chrome to be uncovered. Granted, Chrome is only in “beta” at the moment, so that might by Google some leeway, but from here, there’s definitely a scratch on that shiny new Chrome.

Cisco patches flaws in ASA and PIX

According to to Cisco, “Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances that may result in a reload of the device or disclosure of confidential information.” Updates are available for affected systems.

Cisco fixes denial-of-service flaw in Secure ACS

A flaw in the way Cisco’s Secure ACS system handles RADIUS EAP packets could be exploited in a denial-of-service attack against an affected system. Cisco has released an update for this issue.

**********

Early security issues tarnish Google’s Chrome

Security researchers have reported finding vulnerabilities in Google’s new Web browser a day after it was released in beta. IDG News Service, 09/03/2008.

Also:

Chrome gets first ding

Video: Chrome a good start, but has a ways to go

**********

Four new updates from Mandriva:

python-django (cross site scripting)

libtiff (denial of service, code execution)

opensc (authentication bypass)

wordnet (heap overflow, code execution)

**********

Three new fixes from FreeBSD:

icmp6 (denial of service)

nmount (buffer overflow, code execution)

amd64 swapgs (code execution)

**********

Two new patches from Ubuntu:

tiff (denial of service, code execution)

Yelp (format string, code execution)

**********

Two new fixes from Debian:

wordnet (heap overflow, code execution)

slash (SQL injection, cross scripting)