Flaw puts BIND 8 out to pasture; Cisco warns of DoS flaw

Opinion
Sep 6, 20074 mins

* Flaw puts BIND 8 out to pasture * Cisco warns of DoS flaw * A Time-to-Patch: Apple 2006, and other interesting reading

Question of the week:

Now the the iPhone has been out for a while and Apple has just announced the iPod Touch (an iPhone without the phone parts but with 802.11b and g support) what is your company’s stance of the devices? Are you allowing them on the network or completely ignoring users’ requests to support them?

The price drop on the iPhone (now just $399) may mean more showing up on the corporate doorstep between now and Christmas. Send me your thoughts on Apple’s wireless intruders.

Today’s bug patches and security alerts:

Serious flaw marks end of life for Bind 8 DNS serverA security researcher has found a serious vulnerability in an aging yet widely used software program used for the Internet’s addressing system, prompting the software’s maintainers to retire the affected version. The flaw within Berkeley Internet Name Domain 8 (Bind 8) software could misdirect users to a fraudulent Web site even if a user typed in the correct URL, wrote Amit Klein, chief technology officer for security vendor Trusteer Ltd. Klein discovered the problem. Users should upgrade to Bind 9. Computerworld, 09/05/07.

Amit Klein’s advisory

ISC interim patch

**********

Cisco warns of DoS flaw in Content Switching Module

According to Cisco’s advisory, “The Cisco Content Switching Modules (CSM) and Cisco Content Switching Module with SSL (CSM-S) contain two vulnerabilities that can lead to a denial of service (DoS) condition. The first vulnerability exists when processing TCP packets, and the second vulnerability affects devices with service termination enabled.” A free update is available.

Cisco patches Video Surveillance IP Gateway

Cisco is warning of an authentication flaw in its Video Surveillance IP Gateway video encoder and decoder, Services Platform (SP), and Integrated Services Platform (ISP) devices. Attackers could exploit the flaws to gain full administrative control over an affected device. A free update is available.

**********

MIT patches kadmind RPC libraryAccording to the MIT advisory, “The krb5 Kerberos administration daemon (kadmind) is vulnerable to a stack buffer overflow in the RPCSEC_GSS authentication flavor of the RPC library. Third-party applications using the RPC library provided with MIT krb5 may also be affected.”

Related updates:

Debian

rPath

Ubuntu

**********

Firefox still vulnerable to attacks from protocol-handling bugs

Firefox remains vulnerable to attacks exploiting protocol-handling bugs, even though it was patched twice in July, a pair of security researchers said this weekend. Billy Rios and Nate McFeters, who spelled out design and functionality vulnerabilities in Windows’ Uniform Resource Identifier (URI) protocol handling as recently as mid-August, said Saturday that they have uncovered another way hackers could send malicious code to users via browsers. Computerworld, 09/04/07.

Rios’ blog: Firefox File Handling Woes

**********

Critical bugs plague QuickBooks’ online service, warns US-CERT

The federal government’s cyberdefense arm today warned users of the popular QuickBooks small-business accounting software that they risk losing data and control of their PCs to hackers. According to two advisories published by the U.S. Computer Emergency Readiness Team (US-CERT), the ActiveX control that enables Intuit Inc.’s QuickBooks Online Edition contains flaws that attackers can exploit simply by getting users to view an HTML e-mail message or visit a malicious Web site. Computerworld, 09/05/07.

US-CERT advisories:

Intuit QuickBooks Online Edition ActiveX control stack buffer overflows

Intuit QuickBooks Online Edition ActiveX control fails to properly restrict access to methods

**********

Two new patches from rPath:

Fetchmail (denial of service)

gd/PHP (multiple flaws)

**********

Two new updates from Mandriva:

Tar (arbitrary file overwrite)

ClamAV (denial of service)

**********

Today’s malware news:

Storm worm spoils Labor Day for some

The Storm worm takes no holidays; over this past long weekend this busy piece of malware emerged as part of a spam campaign that pointed recipients to a Web site wishing them a happy Labor Day, then downloaded an “exploit cocktail.” Network World, 09/05/07.

Custom-built botnet steals eBay accounts

Online auction site eBay has been targeted by identity thieves, who are wielding a botnet that uses brute force to uncover valid account log-in information, a Tel Aviv-based security company said Monday. The brute-force attacks are launched by a large botnet that the identity thieves have built using a sophisticated, multistage campaign that begins with compromised legitimate Web sites. Computerworld, 09/04/07.

**********

From the interesting reading department:

A Time-to-Patch: Apple 2006

In a study of updates that Apple shipped last year to remedy serious security holes in products such as QuickTime and iTunes, Security Fix found that the company released patches to plug at least 104 critical security vulnerabilities. That is more than twice the number of severe security holes that the company patched in all of 2004 and 2005 combined. Security Fix blog, 09/04/07.

E-mail system attack caused no damage, US DOD says

A hacking attempt against the U.S. Department of Defense unclassified e-mail system earlier in the year caused minor administrative disruptions and personal inconveniences, but no adverse impact, a military spokesman said Tuesday. IDG News Service, 09/04/07.