* Patches from Gentoo, Ubuntu, rPath, others * Orkut worm demonstrates vulnerability of service * VoIP vulnerabilities increasing, but not exploits, and other interesting reading
In our last newsletter of 2008, we bring you two potential flaws being investigated by Google in the Google Toolbar and GMail. Also, Cisco patches a firewall bug; Apple keeps the patch parade coming with fixes for OS X and Safari; Microsoft’s latest patches may have crippled IE; and Juniper is bitten by a BGP bug. Happy New Year!
Google Toolbar flaw opens door for phishers
Google is working to fix a bug in the Google Toolbar that could allow criminals to steal data or install malicious software on a system, a security researcher warned Tuesday.
Aviv Raff On .NET blog: Google Toolbar Dialog Spoofing Vulnerability
IE, Gmail bugs allow hijacking of accounts on public PCs
Microsoft’s Internet Explorer (IE) browser has an unpatched vulnerability that could let hackers hijack, then access, Google Inc. Gmail accounts, a California security company warned Monday. Computerworld, 12/18/07.
**********
According to the Cisco advisory, “A vulnerability exists in the Cisco Firewall Services Module (FWSM), a high-speed, integrated firewall module for Cisco Catalyst 6500 switches and Cisco 7600 Series routers, that may result in a reload of the FWSM. The only affected FWSM System Software Version is 3.2(3).”
**********
Apple patches keep coming: Mac OS, Safari beta fixed
Apple kept its rush of year-end security patches coming Monday, issuing a flurry of fixes for its Mac OS X operating system and the test version of its Safari browser. Monday’s patches included a whopping 31 updates for the Apple operating system. The Mac OS X patches fix components ranging from the Address Book and iChat software to under-the-covers operating system components such as ColorSync, the IO Storage Family, and the Perl, Python and Ruby programming languages. IDG News Service, 12/18/07.
Apple Updates:
Safari 3 Beta Update 3.0.4 Security Update
**********
Microsoft security update cripples IE
Microsoft confirmed Monday that it is investigating reports that a security update for Internet Explorer issued last week has crippled some users’ ability to get on the Web with the browser. Computerworld, 12/18/07.
**********
BGP bug bites Juniper software
Juniper Networks has issued a security bulletin warning users of a bug in its JUNOS router software. The glitch reportedly created problems for service providers last week in processing Border Gateway Protocol (BGP) traffic. It allowed malformed packets to induce “interface flapping,” in which the interface of a network device is left going up and down repeatedly, according to British IT blog The Register. Network World, 12/18/07.
The Register: Traffic snags on Juniper router glitch
**********
Asterisk warns of authentication flaw in PBX
According to the Asterisk advisory, “Due to the way database-based registrations (“realtime”) are processed, IP addresses are not checked when the username is correct and there is no password. An attacker may impersonate any user using host-based authentication without a secret, simply by guessing the username of that user.”
**********
Four new patches from Debian:
MyDNS (buffer overflow, denial of service)
centericq (buffer overflow, code execution
link-grammar (buffer overflow, code execution)
**********
Two new updates from Gentoo:
**********
Two new fixes from Ubuntu:
GD library (denial of service, code execution)
**********
Three new patches from rPath:
**********
Today’s malware news:
Orkut worm demonstrates vulnerability of service
Google’s Orkut social networking site appeared to have been hit by a relatively harmless worm, but one that demonstrated the continuing vulnerability of Web applications. IDG News Service, 12/19/07.
Security to the Core blog: Orkut XSS Worm
Some clown is spamming around an attachment called Happynewyear.exe. When run, this malware drops a nice Christmas tree to your desktop and Systray. F-Secure Antivirus Research blog, 12/18/07.
Fake Adult Friend Finder Greeting Cards
A batch of fake Adult Friend Finder greeting cards were distributed over the weekend. F-Secure Antivirus Research blog, 12/17/07.
**********
From the interesting reading department:
VoIP vulnerabilities increasing, but not exploits
PBXs are servers on corporate networks and are susceptible to the many exploits that networks in general are heir to, such as denial-of-service and buffer overflows. There have been few exploits so far, however, and none that were widespread or crippling to businesses. NetworkWorld.com 12/17/07.
Successful phishing attacks up, online survey shows
Phishing attacks on U.S. consumers were more successful this year than last, says Gartner. The good news? Phishing victims appear to be getting more help from banks and PayPal to recover their losses. NetworkWorld.com 12/17/07.
Privacy, data breaches still run rampant, shows survey of IT pros
If it seems as though digital privacy invasions and personal-data breaches happen every day in corporate America, these survey results will only reinforce that notion. Network World, 12/17/07.
Getting Acquainted With Rock Phishing
Antiphishing filters basically work either on block listing or on heuristics. “Rock phish” attacks are quite a recent phenomenon that has posed a major challenge to both of the above mentioned antiphishing filters, simply because the unique structure of a Rock phish attack circumvents antiphishing filters. Symantec Security Response blog, 12/18/07.




