Multiple patches from Microsoft and Cisco

Opinion
Feb 15, 20074 mins

* Patches from Microsoft, Cisco, Trustix, others * 'Storm Trojan' ignites worm war * Drive-by Web attack could hit home routers, and other interesting reading

Editor’s note: Bruce Schneier gave an interesting talk at the LinuxWorld OpenSolutions Summit in slushy New York yesterday. .

Today’s bug patches and security alerts:

Attackers seize on new zero-day in Word

Microsoft’s Word and Office programs have been targeted again, with the company warning that hackers may already exploiting a new vulnerability found in the applications. IDG News Service, 02/15/07.

Microsoft fixes critical flaw in security products

Microsoft released its February set of security updates Tuesday, including critical fixes for bugs in Office and the scanning engine used by the company’s security products. The security software flaw is of particular concern because it could, in theory, be very easily exploited by an attacker to run unauthorized software on a victim’s PC. IDG News Service, 02/13/07.

US-CERT advisory

Microsoft advisories:

Vulnerability in HTML Help ActiveX Control Could Allow Remote Code Execution

Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution

Vulnerability in Microsoft Malware Protection Engine Could Allow Remote Code Execution

Vulnerabilities in Microsoft Word Could Allow Remote Code Execution

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution

Cumulative Security Update for Internet Explorer

Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution

Vulnerability in Windows Shell Could Allow Elevation of Privilege

Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege

Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege

Vulnerability in Microsoft MFC Could Allow Remote Code Execution

Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution

**********

Cisco issues three security advisories

Multiple IOS IPS Vulnerabilities

A couple of flaws in the IOS software could allow packets to evade inspection and be exploited in a denial of service attack against affected devices.

Multiple Vulnerabilities in Cisco PIX and ASA Appliances

More packet inspection problems were found in Cisco PIX and ASA products as well as a privilege escalation vulnerability. A free update is available.

Multiple Vulnerabilities in Firewall Services Module

Accoring to the Cisco advisory, “Multiple vulnerabilities exist in the Cisco Firewall Services Module (FWSM). These vulnerabilities occur in the processing of specific Hypertext Transfer Protocol (HTTP), Secure HTTP (HTTPS), Session Initiation Protocol (SIP), and Simple Network Management Protocol

(SNMP) traffic. If verbose logging is enabled for debugging purposes, a vulnerability exists when the FWSM processes packets destined to itself. All of these vulnerabilities may result in a reload of the device.”

**********

New ‘multi’ patch from Trustix

The latest update from Trustix fixes flaws in fetchmail, gd, php, postgresql and samba. The most serious of the flaws could be exploited in a denial-of-service attack or to execute arbitrary code.

**********

Five new updates from Gentoo:

RAR, UnRAR (buffer overflow, code execution)

Snort (denial of service)

ProFTPD (privilege escalation)

Samba (multiple flaws)

X.Org X server (multiple flaws)

**********

Virus/malware news of the day:

Valentine’s Day worm makes the rounds

According to F-Secure, an Spam-like e-mail is making the rounds, “disguising itself as a Valentine’s eCard notification. When you click on the link in the e-mail, it will redirect you to a page that asks you to install a fake Macromedia Flash Player (Adobe Flash Player). This fake player is actually a trojan that downloads and installs a BZub variant onto the system.”

‘Storm Trojan’ ignites worm war

The Trojan horse that pumped up spam volumes in January is at it again, researchers said today, and is now spreading over instant messaging and engaging in attacks on rival malware. Computerworld, 02/12/07.

**********

From the interesting reading department:

Drive-by Web attack could hit home routers

If you haven’t changed the default password on your home router, do so now. That’s what researchers at Symantec and Indiana University are saying, after publishing the results of tests that show how attackers could take over your home router using malicious JavaScript code. IDG News Service, 02/14/07.

U.S. government readying massive cybersecurity test

The U.S. Department of Homeland Security (DHS) is planning a large-scale test of the nation’s response to a cyberattack, to be held in early 2008. IDG News Service, 02/12/07.

FBI: Now where did I put those laptops — and weapons?

The FBI is losing fewer laptops — and weapons — these days than it used to, but the criminal justice organization still needs better controls in place to protect its assets, including potentially sensitive data. Network World, 02/13/07.