* Patches from Microsoft, Cisco, Mozilla, others * Worm fears shut down Skype video feature * 'Hacker Safe' seal: Web site shield, or target?, and other interesting reading
Cisco and Microsoft lead the patch parade with updates for PIX and ASA (Cisco) as well as an updated Patch Tuesday fix (Microsoft) that adds protection for Windows Small Business Server. Also: Mozilla is looking into a Firefox flaw that could lead to data being leaked, and Sun has patched 370 bugs in Java. If that’s not enough, Skype took the dramatic step of shutting down the video chat feature over worm fears.
Cisco warns of Application Velocity System, PIX and ASA flaws
Cisco Wednesday issued two new security alerts: one warning of default passwords in its Application Velocity System (AVS), and the other warning of a crafted IP packet flaw in its Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA). That vulnerability could result in a reload of the devices. NetworkWorld.com, 01/23/08.
Related advisories:
Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability
Cisco Security Advisory: Default Passwords in the Application Velocity System
**********
Windows Small Business Server at risk from critical flaw
Microsoft said Wednesday that another one of its operating system products is vulnerable to a critical vulnerability, first patched two weeks ago. In an update to its MS08-001 security bulletin, Microsoft said that the latest release of Windows Small Business Server was also critically at risk from a bug in Windows’ networking software.
Updated Microsoft bulletin: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution
**********
Mozilla says that flaw could lead to data leak
Mozilla is working to fix a browser flaw that could give attackers unauthorized access to data on a victim’s machine. The problem is similar to other data leakage flaws found in the open-source browser, according to researcher Gerry Eisenhaur, who first reported the problem on Saturday. IDG News Service, 01/23/08.
Thor Larholm blog: Remote variable leakage
**********
Java SE 6 updates 1.6.0_04 includes 370 bug fixes
A new update from Sun for the Java runtime environment fixes some 370 flaws. Windows users that upgrade should make sure older versions of Java are uninstalled after completeting the update.
**********
Three new patches from Mandriva:
xine-lib (heap overflows, code execution)
gftp (boundary errors, code execution)
**********
Today’s malware news:
We have been working on an interesting Symbian worm over the last few days. It affects S60 2nd Edition phones. The SymbOS/Beselo family of worms is very similar to Commwarrior. In fact at first we actually misidentified Beselo.A as Commwarrior.Y. Like Commwarrior, Beselo worms spread via MMS and Bluetooth using social engineering to trick users into installing an incoming SIS application installation file. F-Secure blog, 01/22/08.
Worm fears shut down Skype video feature
Skype has been forced to turn off a video-sharing feature in its software because it could be misused to launch a self-copying worm attack against Skype users, security researchers said Tuesday.
First case of “drive-by pharming” identified in the wild
The theory is now a reality. Symantec reported Tuesday that drive-by pharming, in which a hacker changes the DNS settings on a customer’s broadband router or wireless access point and directs the link to a fraudulent Web site, has been observed in the wild.
Podcast: How not to fall victim to drive-by pharming attacks
Attack against Linux Apache servers intensifying
A mass attack ongoing for the past month against Linux Apache Web servers has become increasingly successful because its break-in method makes use of an automated password and installation process, according to a security researcher monitoring its progress. Network World, 01/22/08.
Best Buy sold infected digital picture frames
Best Buy Co. has confirmed that, during the holidays, it sold digital picture frames that harbored malicious code able to spread to any connected Windows PC. It is not recalling the frames, however.
******
From the interesting reading department:
Mac users warned of bad year for security
The Mac is no longer immune to Windows-like software exploits, and its users should prepare for a rougher year, a report from security vendor Sophos has said. TechWorld, 01/22/08.
‘Hacker Safe’ seal: Web site shield, or target?
More than 80,000 Web sites worldwide display a small green logo that proclaims them to be “Hacker Safe.” The logo is provided to them by ScanAlert, a vendor that scans the sites of its clients daily in search of security vulnerabilities. Computerworld, 01/22/08.




