* Patches from Cisco, Mozilla, Gentoo, others * Criminals target CA's BrightStor in new attack * What spooks Microsoft's chief security advisor, and other interesting reading
Cisco kicked off its bi-annual IOS Patch Wednesday with five new fixes for its venerable router operating system. Most of the patched flaws were of the denial-of-service variety. Mozilla came out with 10 new fixes for Firefox as well. Users should already be getting Version 2.0.13 as part of Firefox’s automated patch system. Also today, attackers are going after flaws in Excel, CA’s BrightStor backup system and possibly D-Link routers.
Cisco’s first Patch Wednesday produces five IOS alerts
Cisco Wednesday ‘celebrated’ its first six-monthly patch schedule for IOS by delivering five separate security alerts. The alerts affect Cisco IOS Multicast VPN (MPVN); IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Router Switch Processor 720; IOS user datagram protocol delivery; and IOS’ Data-link Switching feature. Cisco Subnet, 03/26/08.
Cisco advisories:
Cisco IOS Multicast Virtual Private Network (MVPN) Data Leak
Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
Cisco IOS Virtual Private Dial-up Network Denial of Service Vulnerability
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
**********
Mozilla fixes 10 Firefox flaws, half seen as ‘critical’
Mozilla yesterday patched 10 vulnerabilities, half of them marked “critical,” in its open-source browser as it updated Firefox to Version 2.0.0.13. The new Mozilla Messaging Inc. spin-off, however, was not able to provide a matching update to its Thunderbird e-mail client, which shares five of the Firefox flaws that were fixed. Computerworld, 03/26/08.
Firefox 2.0.0.13 release notes
**********
Two new fixes from Gentoo:
MIT Kerberos 5 (multiple flaws)
**********
Two new updates from Mandriva:
wml (symlink attack, file overwrite)
**********
Three new patches from Debian:
serendipity (cross scripting flaw)
debian-goodies (elevated privileges)
**********
Two new updates from Ubuntu:
**********
Two new updates from rPath:
gnome-ssh-askpass (session hijack)
**********
Today’s malware news:
Criminals target CA’s BrightStor in new attack
Just days after Microsoft warned of attacks targeting its Jet Database Engine software, cybercriminals have found a new program to attack: CA’s BrightStor ARCserve Backup. The new attack was reported Monday by Symantec, which said that a malicious Web page with a .cn domain was serving the attack code. IDG News Service, 03/25/08.
Hackers seize on Excel vulnerability
Researchers at Symantec said late Tuesday they’ve spotted a Web site that tries to exploit computers lacking one of the recently issued patches for versions of Microsoft’s Excel spreadsheet program. The vulnerability involves a malicious Excel file that when opened can allow a hacker to execute other code on a PC. IDG News Service, 03/26/08.
Also: Microsoft admits it knew about, but didn’t patch, bugs
Symantec suspects bot in attacks on D-Link routers
Suspicious port scanning that’s been tracked back to D-Link routers may mean a worm or bot is on the loose and infiltrating the popular brand’s devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today. Computerworld, 03/25/08.
**********
From the interesting reading department:
What spooks Microsoft’s chief security advisor
Microsoft’s U.S. general manager/chief security advisor for its National Security Team thinks like a true security professional: In every bit of good news, Bret Arsenault wonders what bad news could be lurking behind it. Network World, 03/26/08.
Vista Service Pack 1: 573 fixes in limbo
Service Pack 1 for Windows Vista is (almost) ready for prime time. SP1 contains a whopping 573 bug fixes and patches that have accumulated since Vista first shipped in early 2007, plus some performance improvements. I advise you to get it–but only after the wrinkles are ironed out. PC World, 03/25/08.
Yet another laptop theft: Agilent warns 51,000 workers of potential data compromise
In what is becoming an increasingly familiar story these days, the theft of a laptop PC containing unencrypted confidential data has prompted yet another organization to issue a warning notice to tens of thousands of people. Computerworld, 03/25/08.
Laptop with info on heart patients stolen from researcher
The unencrypted medical information of about 2,500 participants in a cardiac study conducted by the National Heart, Lung and Blood Institute (NHLBI) may have been compromised by the theft of a laptop PC last month. Computerworld, 03/24/08.
Update: Facebook fixes security lapse that exposed photos
Even after last week’s unveiling of privacy upgrades, a security lapse on the Facebook Inc. social network early this week still exposed restricted photos to anyone using the site, according to an Associated Press report later confirmed by the company to Computerworld, 03/26/08.




