Cisco warns of SIP handling flaw in IOS devices

Opinion
Feb 1, 20073 mins

* Patches from Debian, OpenPKG, Gentoo * Virus located in TomTom GPS systems * How Schwab shuts out hackers, and other interesting reading

Editor’s Note: I am attending DEMO 2007 this week in Palm Desert, Calif. 68 companies are here demonstrating their wares. Check out all of Network World’s coverage here.

Today’s bug patches and security alerts:

Cisco warns of SIP handling flaw in IOS devices

According to the Cisco advisory, “Cisco devices running IOS which support voice and are not configured for Session Initiated Protocol (SIP) are vulnerable to a crash under yet to be determined conditions, but isolated to traffic destined to Port 5060. SIP is enabled by default on all Advanced images which support voice and do not contain the fix for CSCsb25337. There are no reports of this vulnerability on the devices which are properly configured for SIP processing. Workarounds exist to mitigate the effects of this problem.”

**********

Two new updates from Debian:

libgtop2 (code execution)

bind9 (denial of service)

**********

Two new patches from OpenPKG:

bind (denial of service)

cvstrac (denial of service)

**********

Four new updates from Gentoo:

thttpd (authentication bypass)

eLinks (arbitrary Samba command execution)

KSirc (denial of service)

X.Org X server (multiple flaws)

**********

Latest virus news:

Virus located in TomTom GPS systems

If you’ve picked up a TomTom GPS over the past few months, you may have bought more than you bargained for. TomTom International confirmed Monday that some of its latest GO 910 devices have shipped with a virus pre-installed. IDG News Service, 01/29/07.

Related: F-Secure blog entry

**********

From the interesting reading department:

How Schwab shuts out hackers

It’s a simple promise that Charles Schwab & Co. makes to its customers, but one with security ramifications that ripple throughout the company: “Schwab will cover 100% of any losses in any of your Schwab accounts due to unauthorized activity.” Network World, 01/29/07.

See the video interview with Schwab.com’s Kostas Konstantinides

Hype vs. reality in VoIP security

VoIP, like many new technologies, suffers from having security as an afterthought. Headlines tell of VoIP vulnerabilities that can lead to eavesdropping, a new form of spam, even denial-of-service attacks that can take down the one communication network that businesses rely on most. Network World, 01/30/07.

Expert: Phishing and other social attacks threaten VoIP

VoIP is susceptible to the same types of attacks that threaten other network applications, but there are some potential new ones that focus directly on VoIP. David Endler, chairman and founder of the VoIP Security Alliance and director of security research for TippingPoint, spoke with Network World Senior Editor Tim Greene about VoIP security issues and what you can do to protect your assets. Network World, 01/29/07.

Vontu upgrade catches data leaks at end points New version tracks copying to USB drives, iPods

Vontu on Monday announced a new version of its data leak protection suite, which now protects sensitive information from being copied onto removable media without permission. Network World, 01/29/07.

Trade group gives U.S. government low cybersecurity grade

The Cyber Security Industry Alliance has given the U.S. government D grades on its cybersecurity efforts in 2006, and renew edits call for the U.S. Congress to pass a comprehensive data protection law in 2007. IDG News Service, 01/31/07.