21 patch salute from Cisco

Opinion
Aug 13, 20074 mins

* Patches from Apple, Symantec, Trustix, others * Yo! There is a Complaint Against You Lodged with the FTC/FBI/IRS * Why virtual honeypots are sweet, and other interesting reading

Today’s bug patches and security alerts:

Cisco issued 21 patches hours before site blacked out

A Web site blackout yesterday prevented Cisco customers from retrieving 21 critical patches for about three hours yesterday, shortly after the fixes were posted by the network hardware maker. The 21 patches, deployed in four updates, were posted three hours before the blackout, and would repair IOS against a swath of vulnerabilities, some of which could result in attackers injecting their own code into vulnerable Cisco hardware. Three of the four IOS updates, according to Cisco’s advisories, plug holes that attackers can, or might be able to, exploit with remote code.

Cisco advisories:

Cisco IOS Secure Copy Authorization Bypass Vulnerability

Cisco Unified MeetingPlace XSS Vulnerability

**********

Microsoft plans 9 security updates for this week

Microsoft will release nine sets of security patches next week, including six critical updates for Windows, Office, Internet Explorer and its Visual Basic development software.

Microsoft advanced advisory

**********

Apple patches Mac Pro, iMac software

Apple has shipped software updates for its newly-introduced iMac and for its pro-grade desktop, the Mac Pro. The company has furnished limited detail as to the substance of this software update, saying only that it, “provides important bug fixes and is recommended for 20-inch and 24-inch iMac models with 2.0, 2.4, or 2.8GHz processors.”

**********

Symantec patches critical Norton flaw

A bug in the way Norton Antivirus software uses the ActiveX programming language could cause serious problems for users of Symantec’s products. On Thursday, Symantec patched the flaw warning that a bug in two ActiveX controls used by Symantec’s client software could allow an attacker to run unauthorized software on a victim’s computer. Security vendor Secunia rates the problem as “highly critical.” IDG News Service, 08/09/07.

Symantec advisory

Secunia advisory

**********

Trustix releases ‘multi’ update

A new patch rollout from Trustix fixes flaws in file, gd and mutt. The most serious of the flaws could be exploited by triggering a buffer overflow, allowing attackers to run malicious code on an affected system.

**********

Today’s malware news:

Yo! There is a Complaint Against You Lodged with the FTC/FBI/IRS

Ok, you can substitute whatever agency name you want, but the story is nearly always the same. A little while ago I blogged about Advanced TDS, another Mpack-type clone and mentioned how professional some of the malware creators are becoming. Symantec Security Response Weblob, 08/06/07.

**********

From the interesting reading department:

Why virtual honeypots are sweet

A honeypot is simply a “closely monitored computing resource that we want to be probed, attacked or compromised,” Niels Provos and Thorsten Holz tell us in their new book, Virtual Honeypots. Network World, 08/10/07.

Bug bounty program answers critics

The man who launched both of the security industry’s major bug bounty programs Thursday defended the idea of paying for vulnerabilities, but also said he has responded to critics by putting a tighter lid on bug details to make sure they don’t fall into the wrong hands. Computerworld, 08/09/07.

Using Darknets to See the Light

Firewalls, intrusion detection and prevention systems, antivirus — they’re all old tricks of the trade that IT has traditionally deployed to maintain the security of large and complex networks. But are they enough? Threat volume is rising, propagation speed is increasing, and attacks are becoming more advanced and elusive. Luckily, there are innovative new ways to complement the traditional approach. And security’s bright side may be on the ‘dark’ side. Symantec Security Response Weblog, 08/09/07.

Security firm automates generating attack code

Security firm Immunity has released a tool aimed at largely automating the process of putting together security exploits, a move some believe will lead to a dramatic rise in the number of “zero-day” exploits making the rounds. TechWorld, 08/09/07.

VoIP hacker talks: Service provider nets easy pickings

The technical brains behind the theft of $1 million worth of VoIP minutes from service providers used common, simple attacks to gain illicit access. Network World, 08/10/07.