* Patches from Mozilla, Askterisk, FreeBSD, others * Merry Christmas and so on * Government-sponsored cyberattacks on the rise, McAfee says, and other interesting reading
For the second time in a week, Mozilla has released an update to its popular Firefox browser. Version 2.0.0.11, which should have started to auto-download over the weekend, fixes a flaw in one of Firefox’s rendering engines. Also today, Cisco confirms the ability eavesdrop of VoIP calls and two new patches for the Asterisk IP PBX system.
Mozilla scrambles to patch Firefox for second time this week
A bug in rendering “canvas” HTML elements worked its way into Firefox 2.0.0.10, the edition Mozilla released Monday to fix six other vulnerabilities. Canvas elements, which were first used by Apple Inc. in its Safari browser, let Web site designers dynamically render bitmap images in HTML. Firefox, Safari and Opera support Canvas natively; Microsoft’s Internet Explorer does so with a plug-in.
Firefox known vulnerabilities page
**********
Cisco confirms ability to eavesdrop on remote calls using its VoIP phones
Cisco confirmed it is possible to eavesdrop on remote conversations using Cisco VoIP phones. In its security response, Cisco says: “an attacker with valid Extension Mobility authentication credentials could cause a Cisco Unified IP Phone configured to use the Extension Mobility feature to transmit or receive a Real-Time Transport Protocol (RTP) audio stream.” NetworkWorld.com, 11/29/07.
**********
Two new updates for Asterisk
The Askterisk team has released two new security updates for its open source IP PBX system. The first patch deals with a SQL injection vulnerability in cdr_pgsql module. A second update fixes a similar flaw in the res_config_pgsql code. Both flaws could be exploited by an attacker to compromise the administrator database.
**********
Two new fixes from FreeBSD:
core (random number generator not so random)
**********
Three new patches from rPath:
**********
Today’s malware news:
It’s December, and we’ve already seen the first malware runs using fake Christmas Cards as the lure. F-Secure Antivirus Research blog, 12/02/07.
**********
Interesting reading:
Government-sponsored cyberattacks on the rise, McAfee says
Governments and allied groups worldwide are using the Internet to spy and launch cyberattacks on their enemies, targeting critical systems including electricity, air traffic control, financial markets and government computer networks. Network World, 11/29/07.
Google looks for help finding malicious Web sites
Google is asking everyday Web surfers to help with its efforts to stamp out malicious Web sites. The company has created an online form designed to make it easy for people to report sites they suspect of hosting malicious code. IDG News Service, 11/30/07.
Insider charged with hacking California canal system
A former employee of a small California canal system has been charged with installing unauthorized software and damaging the computer used to divert water from the Sacramento River. IDG News Service, 11/29/07.
The Mpack and IcePack exploit packages have been on sale for some time. Now, free releases of these tools are being distributed, but are these free distributions all they are supposed to be? While examining these free releases we discovered some surprises. Symantec Security Response blog, 11/30/07.
Exploit for Apple QuickTime Vulnerability in the Wild
On November 25, we blogged about a proof of concept exploit code for Apple’s QuickTime RTSP Response Header Remote Stack Based Buffer Overflow Vulnerability being disclosed to the public. Now a week has passed and Symantec’s DeepSight honeynet has spotted at least one active exploitation in the wild. Symantec Security Response blog, 12/01/07.
US-CERT advisory: Apple QuickTime RTSP Buffer Overflow
Police raid botmaster blamed for 1 million infections
Police have raided the home of the alleged ringleader of an international group of cybercriminals said to be responsible for infecting more than one million computers. IDG News Service, 11/29/07.




