CA, Asterisk patch critical flaws

Opinion
Jun 9, 20083 mins

* Patches from CA, Asterisk, Microsoft * SoundBot Exploits Network Vulerabilities * 6 burning questions about network security, and other interesting reading

Not a lot of new patches over the weekend, but CA and Asterisk users should be wary of two highly rated flaws with patches available. For CA, the company’s Secure Content Manager could be exploited to run malicious code. For Asterisk, an exploited flaw in an Addon module could result in a denial of service. And, don’t forget, tomorrow is Microsoft’s Patch Tuesday June release.

CA patches Secure Content Manager

A high risk flaw in CA’s Secure Conent Manager’s HTTP Gateway could be exploited by attackers in a denial-of-service attack or to run malicious code on a non-patched system. CA rates the flaw high and is urging users to download the available patch.

**********

Asterisk patches flaw in Addon driver

A remotely-exploitable flaw in the Asterisk ooh323 channel driver, which is part of the Asterisk Addons and uses a TCP connection to pass commands internally. Attackers could exploit this mechanism to cause the system to crash, resulting in a denial of service. A fix is available.

**********

Bluetooth, IE to get critical Microsoft patches

Microsoft plans to issue seven sets of security patches next week, including critical fixes for DirectX, Internet Explorer and Bluetooth wireless software for Windows. The updates are due Tuesday, the day Microsoft had previously scheduled to release its security patches. Fixes are also slated for Active Directory, the Windows Internet Name Service (WINS) and the Pragmatic General Multicast (PGM) protocol, used by Windows to stream media to many recipients. These updates are all rated “important.” IDG News Service, 06/05/2008.

**********

Today’s malware news

SoundBot Exploits Network Vulerabilities

The [SoundBot] worm has the potential to leak sensitive information to the attacker about the victim’s network infrastructure. It manages to do this by not only blocking many of the security applications designed to detect it, but also by using legitimate processes that make removal difficult. The SpywareGuide Greynets Blog, 06/06/2008.

Security firm asks for help cracking ransomware key

A security company on Friday asked for help cracking an encryption key central to an extortion scheme that demands money from users whose PCs have been infected by malware. Computerworld, 06/08/2008.

Related: New crypto virus a looming threat

Surprise ARP attack draws attention

It isn’t often that old hacking methods make significant news, but an ARP attack received widespread attention earlier this week, more so for the perceived target than for the actual attack itself. Computerworld, 06/08/2008.

HP StorageWorks Scanning

The Tipping Point ZDI initiative recently published a security advisory about pre-authentication overflows in HP StorageWorks (CVE-2008-1661). Shortly after the vulnerability was announced, exploit code became public via the Metasploit project. Within a few days, we started seeing an increase in scanning for the two TCP ports the vulnerable daemon listens on: TCP ports 1100 and 1106. Security to the Core blog, 06/06/2008.

**********

From the interesting reading department:

6 burning questions about network security

Security issues often seem to smolder more than burn, but these six are certainly capable of lighting a fire under IT professionals at a moment’s notice. Handle with care. Network World, 06/05/2008.

Spear-phishing attacks have hooked 15,000, says VeriSign

Two groups of criminals have stolen data from an estimated 15,000 victims over the past 15 months, using targeted “spear-phishing” e-mail attacks, according to researchers at VeriSign. IDG News Service, 06/06/2008.

Software Update Prompts Nuclear Plant Shutdown

A nuclear power plant in Georgia was recently forced into an emergency shutdown for 48 hours after a software update was installed on a single computer. Security Fix blog, 06/05/2008.