* Patches from Cisco, Akamai, VMware, others * Just when you thought it was dead, storm is back * Researchers tout new-fangled network worm weapon, and other interesting reading
Busy week with pathces from Cisco for its PIX and ASA appliances; Microsoft clarifying its lack of a Flash update in XP SP3; and patches from Asterisk, Akamai and VMWAre. Plus, how “jailbreak” smartphones could be a great security risk.
Cisco patches flaws in PIX, ASA
A number of flaws have been found in Cisco’s ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. Many of these could be exploit in denial-of-service attacks against affected devices and in some cases bypass access control lists. Fixes are available.
**********
Microsoft clarifies XP SP 3 Flash issue
Amid concerns that users of its Window XP Service Pack 3 operating system may be vulnerable to online attacks, Microsoft has finally broken its silence and explained which XP users need to upgrade their Adobe Flash Player software. IDG News Service, 06/03/2008.
Previously: XP SP3 omits critical security update
**********
Akamai patches flaw in Download Manager
Akamai’s Download Manager software prior to and including version 2.2.3.5 is vulnerable to an attack that allows malicious code to be downloaded and executed on affected systems. To exploit the flaw, users would have to visit a malicious Web site. A new version of the Download Manager is available that fixes the issue.
**********
Asterisk’s team patches DoS vulnerability
A denial-of-service vulnerability has been found in Asterisk’s SIP channel driver. Only select versions of Asterisk are affected by the flaw and updates are available.
**********
VMWare patches flaw in HGFS File System
According to a VMWare advisory, “A heap buffer overflow condition is present in VMware HGFS. Exploitation of this flaw might allow an unprivileged guest process to execute code in the context of the vmx process on the host.” A fix is available.
**********
Two new updates from Gentoo:
mtr (stack overflow, code execution)
**********
Two new patches from Mandriva:
**********
Two new fixes from Ubuntu:
**********
Two new patches from Debian:
**********
Two new updates from rPath:
samba (heap overflow, code execution)
**********
Today’s malware news:
Just when you thought it was dead, storm is back
Despite reports of Storm being killed off, it’s still very much alive. As recently as earlier today we saw an upswing in e-mails being sent out attempting to trick people into visiting Storm sites such as the one below. F-Secure, 06/04/2008.
Yesterday’s post discussed a mystery PDF file that was booby trapped to drop a backdoor. Today we’ll look at how these documents are created. F-Secure, 06/02/2008.
**********
From the interesting reading department:
Researchers tout new-fangled network worm weapon
Can Internet worms be thwarted within minutes of their infection? Researchers at Ohio State University say they can and they have the method to prove it. Layer 8 Blog, 06/04/2008.
Jailbreak apps could make Smartphones a bigger risk
Corporate IT folks already nervous about Smartphone security may have more to worry about than executives failing to use passwords. Jailbreak applications – tools for unlocking phones so any application can be installed – are becoming more popular and easy to use. Security Blog, 06/03/2008.
Sci-fi writers: New tech will bring more security challenges
If IT security professionals think they have challenges now, they should wait until new technologies such as quantum computing and devices embedded in skin arrive in the not-so-distant future, three science-fiction writers said Monday. IDG News Service, 06/02/2008.
Build-Your-Own-Bot Tool Makes Everything Nice And Easy
The trend for slick looking infection file creation programs continues, with a tool designed to make servers for Botnets. I love taking screenshots of the files sitting in folders waiting to be activated, so let’s get that part out of the way first, shall we? The SpywareGuide Greynets Blog, 06/04/2008.
Hong Kong, China Web domains cited as “most dangerous”
Hong Kong and China are the “most dangerous” places to surf the Web based on country domain, according to McAfee’s annual assessment of the riskiest and safest places in cyberspace. Network World, 06/04/2008.
Microsoft: CardSpace attack works but was too rigged
Microsoft is disputing that its CardSpace authentication management technology can be hacked despite a research paper that outlines a proof-of-concept attack. IDG News Service, 06/02/2008.
UnitedHealthcare data breach leads to ID theft
A data breach at UnitedHealthcare has led to a rash of identity-theft crimes at the University of California, Irvine. To date, 155 graduate and medical students at the school have been hit by the scam, in which criminals file false tax returns in the victim’s name and then collect their tax refunds. IDG News Service, 06/03/2008.
Discovery slashes quantum cryptography costs
Researchers at the U.S. National Institute of Standards and Technology (NIST) have demonstrated a technique that could make quantum cryptography significantly cheaper to implement, moving it nearer to possible commercial acceptance. TechWorld, 06/03/2008.




