Cisco patches flaws in PIX, ASA

Opinion
Jun 5, 20084 mins

* Patches from Cisco, Akamai, VMware, others * Just when you thought it was dead, storm is back * Researchers tout new-fangled network worm weapon, and other interesting reading

Busy week with pathces from Cisco for its PIX and ASA appliances; Microsoft clarifying its lack of a Flash update in XP SP3; and patches from Asterisk, Akamai and VMWAre. Plus, how “jailbreak” smartphones could be a great security risk.

Cisco patches flaws in PIX, ASA

A number of flaws have been found in Cisco’s ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. Many of these could be exploit in denial-of-service attacks against affected devices and in some cases bypass access control lists. Fixes are available.

**********

Microsoft clarifies XP SP 3 Flash issue

Amid concerns that users of its Window XP Service Pack 3 operating system may be vulnerable to online attacks, Microsoft has finally broken its silence and explained which XP users need to upgrade their Adobe Flash Player software. IDG News Service, 06/03/2008.

Micrososft advisory

Previously: XP SP3 omits critical security update

**********

Akamai patches flaw in Download Manager

Akamai’s Download Manager software prior to and including version 2.2.3.5 is vulnerable to an attack that allows malicious code to be downloaded and executed on affected systems. To exploit the flaw, users would have to visit a malicious Web site. A new version of the Download Manager is available that fixes the issue.

**********

Asterisk’s team patches DoS vulnerability

A denial-of-service vulnerability has been found in Asterisk’s SIP channel driver. Only select versions of Asterisk are affected by the flaw and updates are available.

**********

VMWare patches flaw in HGFS File System

According to a VMWare advisory, “A heap buffer overflow condition is present in VMware HGFS. Exploitation of this flaw might allow an unprivileged guest process to execute code in the context of the vmx process on the host.” A fix is available.

**********

Two new updates from Gentoo:

libxslt (denial of service)

mtr (stack overflow, code execution)

**********

Two new patches from Mandriva:

kernel (multiple flaws)

samba (code execution)

**********

Two new fixes from Ubuntu:

Kernel (multiple flaws)

GnuTLS (multiple flaws)

**********

Two new patches from Debian:

libvorbis (multiple flaws)

ikiwiki (regression error)

**********

Two new updates from rPath:

OpenSSL (denial of service)

samba (heap overflow, code execution)

**********

Today’s malware news:

Just when you thought it was dead, storm is back

Despite reports of Storm being killed off, it’s still very much alive. As recently as earlier today we saw an upswing in e-mails being sent out attempting to trick people into visiting Storm sites such as the one below. F-Secure, 06/04/2008.

Creating Malicous PDF Files

Yesterday’s post discussed a mystery PDF file that was booby trapped to drop a backdoor. Today we’ll look at how these documents are created. F-Secure, 06/02/2008.

**********

From the interesting reading department:

Researchers tout new-fangled network worm weapon

Can Internet worms be thwarted within minutes of their infection? Researchers at Ohio State University say they can and they have the method to prove it. Layer 8 Blog, 06/04/2008.

Jailbreak apps could make Smartphones a bigger risk

Corporate IT folks already nervous about Smartphone security may have more to worry about than executives failing to use passwords. Jailbreak applications – tools for unlocking phones so any application can be installed – are becoming more popular and easy to use. Security Blog, 06/03/2008.

Sci-fi writers: New tech will bring more security challenges

If IT security professionals think they have challenges now, they should wait until new technologies such as quantum computing and devices embedded in skin arrive in the not-so-distant future, three science-fiction writers said Monday. IDG News Service, 06/02/2008.

Build-Your-Own-Bot Tool Makes Everything Nice And Easy

The trend for slick looking infection file creation programs continues, with a tool designed to make servers for Botnets. I love taking screenshots of the files sitting in folders waiting to be activated, so let’s get that part out of the way first, shall we? The SpywareGuide Greynets Blog, 06/04/2008.

Hong Kong, China Web domains cited as “most dangerous”

Hong Kong and China are the “most dangerous” places to surf the Web based on country domain, according to McAfee’s annual assessment of the riskiest and safest places in cyberspace. Network World, 06/04/2008.

Microsoft: CardSpace attack works but was too rigged

Microsoft is disputing that its CardSpace authentication management technology can be hacked despite a research paper that outlines a proof-of-concept attack. IDG News Service, 06/02/2008.

UnitedHealthcare data breach leads to ID theft

A data breach at UnitedHealthcare has led to a rash of identity-theft crimes at the University of California, Irvine. To date, 155 graduate and medical students at the school have been hit by the scam, in which criminals file false tax returns in the victim’s name and then collect their tax refunds. IDG News Service, 06/03/2008.

Discovery slashes quantum cryptography costs

Researchers at the U.S. National Institute of Standards and Technology (NIST) have demonstrated a technique that could make quantum cryptography significantly cheaper to implement, moving it nearer to possible commercial acceptance. TechWorld, 06/03/2008.