* Patches from Debian, Mandriva, Gentoo, others * Phishers point scam at Apple's iTunes * FBI warns of e-mail scams offering to help Chinese quake victims, and other interesting reading
endif; ?>Cisco is out with two patches this week, one for the Secure Shell server (SSH) implementation in its IOS software running on many of its switches and the other for its Unified Customer Voice Portal that could could be exploited to create superuser accounts. PayPal is also out with warning about potential flaws in its EV-SSL implementation, which could be exploited to steal user information.
Cisco warns of DoS vulnerability in IOS Secure Shell
Multiple flaws in Cisco IOS’s Secure Shell (SSH) implementation could be exploited by attackers to cause the device the reload, resulting in a denial of service. Only devices configured to accept SSH connections are affected. A free update is available.
Cisco patches Voice Portal flaw
According to a Cisco advisory, “A vulnerability exists in the Cisco Unified Customer Voice Portal (CVP) where an authenticated user can create, modify, or delete a superuser account. Cisco has released free software updates that address this vulnerability.”
**********
PayPal flaw raises questions about EV-SSL
eBay’s PayPal has acknowledged a serious cross-site scripting (XSS) flaw that could be used to steal user credentials or cookies. The page affected used an Extended Validation SSL (EV-SSL) certificate, according to Harry Sintonen, the Finnish researcher who discovered the flaw, casting doubt on the claims of EV-SSL to assure users of more secure web pages. TechWorld, 05/19/2008.
**********
Seven new patches from Debian:
libfishsound (integer overflow, code execution)
gnome-peercast (buffer overflows, code execution)
peercast (buffer overflows, code execution)
phpgedview (design flaw, privilege escalation)
netpbm-free (stack overflow, code execution)
**********
Two new fixes from Mandriva:
**********
Three new updates from Gentoo:
Mozilla Firefox, Thunderbird, SeaMonkey and XULRunner (multiple flaws, code execution)
Perl (denial of servide, code execution)
**********
Today’s malware news:
Phishers point scam at Apple’s iTunes
Phishers have targeted users of Apple’s iTunes music store with sophisticated identity theft attacks for the first time, a security company said Tuesday. People began receiving spammed messages Monday telling them that they must correct a problem with their iTunes account, said Andrew Lochart, an executive with e-mail security vendor Proofpoint. Computerworld, 05/21/2008.
Phishing Piers on Legitimate Sites
Let’s say that you want to phish for PayPal accounts. One might attempt to register something such as paypol-sevice.com. But that’s too obvious and is likely to be discovered and abused before the phishing even begins. F-Secure blog, 05/21/2008.
Warning! Your PC Is Infected! Click Here To……Blahblahblah
How many times have you seen that message appear in your life? If I had a nickel for every time I saw this message I would not be writing this blog. I would be playing golf in Florida or I could afford a full tank of gas instead of just getting a quarter tank. The SpywareGuide Greynets Blog, 05/19/2008.
**********
From the interesting reading department:
FBI warns of e-mail scams offering to help Chinese quake victims
The FBI is warning Americans looking to send donations in the aftermath of the massive May 12 earthquake in China to beware of a rising number of e-mail scams that tout “relief” efforts. Computerworld, 05/21/2008.
Hacker compromised Red Cross earthquake relief site
Hurricane Katrina proved a fertile ground for fraudsters to scam money off those willing to help the needy. Now the China earthquake has bread a new variant of the morally reprehensible, with donated funds being siphoned off one charity site. Computerworld Australia, 05/19/2008.
This Site is Safe from Hackers. Is it really?
Antivirus and antimalware developers have been in the spotlight for the last month or so and have been the focus of malware developers for much longer over the plan to run the Race to Zero contest at this year’s DefCon in Las Vegas. Now, it might be the turn of companies that produce and promote ‘This Site is Safe from Hackers’-style certification and coverage for their clients to share the spotlight. Computerworld, 05/19/2008.
XP SP3 update corrupts Windows registry, users claim
Symantec Corp. today denied that its consumer security software, including Norton Internet Security and Norton 360, is to blame for wreaking havoc on some users’ PCs after they upgraded to Windows XP Service Pack 3. Computerworld, 05/20/2008.
Anti-malware group scolds Apple over Safari ‘carpet bomb’
An anti-malware organization has called on Apple Inc. to beef up its Safari Web browser to protect users from exploits that could let attackers download malicious code to a Mac or Windows user’s desktop. Computerworld, 05/21/2008.
Vista laid low by new malware figures
It looks as if Vista’s reputation for improved security could be heading for the pages of history. PC Tools has renewed last week’s attack on the platform with new figures that appear to back up its claim that Vista is almost as vulnerable as its predecessors. TechWorld, 05/19/2008.




