* Patches from Microsoft, Cisco, Trustix, others * 'Storm Trojan' ignites worm war * Drive-by Web attack could hit home routers, and other interesting reading
Editor’s note: Bruce Schneier gave an interesting talk at the LinuxWorld OpenSolutions Summit in slushy New York yesterday. .
Today’s bug patches and security alerts:
Attackers seize on new zero-day in Word
Microsoft’s Word and Office programs have been targeted again, with the company warning that hackers may already exploiting a new vulnerability found in the applications. IDG News Service, 02/15/07.
Microsoft fixes critical flaw in security products
Microsoft released its February set of security updates Tuesday, including critical fixes for bugs in Office and the scanning engine used by the company’s security products. The security software flaw is of particular concern because it could, in theory, be very easily exploited by an attacker to run unauthorized software on a victim’s PC. IDG News Service, 02/13/07.
Microsoft advisories:
Vulnerability in HTML Help ActiveX Control Could Allow Remote Code Execution
Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution
Vulnerability in Microsoft Malware Protection Engine Could Allow Remote Code Execution
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
Cumulative Security Update for Internet Explorer
Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution
Vulnerability in Windows Shell Could Allow Elevation of Privilege
Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege
Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege
Vulnerability in Microsoft MFC Could Allow Remote Code Execution
Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution
**********
Cisco issues three security advisories
Multiple IOS IPS Vulnerabilities
A couple of flaws in the IOS software could allow packets to evade inspection and be exploited in a denial of service attack against affected devices.
Multiple Vulnerabilities in Cisco PIX and ASA Appliances
More packet inspection problems were found in Cisco PIX and ASA products as well as a privilege escalation vulnerability. A free update is available.
Multiple Vulnerabilities in Firewall Services Module
Accoring to the Cisco advisory, “Multiple vulnerabilities exist in the Cisco Firewall Services Module (FWSM). These vulnerabilities occur in the processing of specific Hypertext Transfer Protocol (HTTP), Secure HTTP (HTTPS), Session Initiation Protocol (SIP), and Simple Network Management Protocol
(SNMP) traffic. If verbose logging is enabled for debugging purposes, a vulnerability exists when the FWSM processes packets destined to itself. All of these vulnerabilities may result in a reload of the device.”
**********
New ‘multi’ patch from Trustix
The latest update from Trustix fixes flaws in fetchmail, gd, php, postgresql and samba. The most serious of the flaws could be exploited in a denial-of-service attack or to execute arbitrary code.
**********
Five new updates from Gentoo:
RAR, UnRAR (buffer overflow, code execution)
ProFTPD (privilege escalation)
X.Org X server (multiple flaws)
**********
Virus/malware news of the day:
Valentine’s Day worm makes the rounds
According to F-Secure, an Spam-like e-mail is making the rounds, “disguising itself as a Valentine’s eCard notification. When you click on the link in the e-mail, it will redirect you to a page that asks you to install a fake Macromedia Flash Player (Adobe Flash Player). This fake player is actually a trojan that downloads and installs a BZub variant onto the system.”
‘Storm Trojan’ ignites worm war
The Trojan horse that pumped up spam volumes in January is at it again, researchers said today, and is now spreading over instant messaging and engaging in attacks on rival malware. Computerworld, 02/12/07.
**********
From the interesting reading department:
Drive-by Web attack could hit home routers
If you haven’t changed the default password on your home router, do so now. That’s what researchers at Symantec and Indiana University are saying, after publishing the results of tests that show how attackers could take over your home router using malicious JavaScript code. IDG News Service, 02/14/07.
U.S. government readying massive cybersecurity test
The U.S. Department of Homeland Security (DHS) is planning a large-scale test of the nation’s response to a cyberattack, to be held in early 2008. IDG News Service, 02/12/07.
FBI: Now where did I put those laptops — and weapons?
The FBI is losing fewer laptops — and weapons — these days than it used to, but the criminal justice organization still needs better controls in place to protect its assets, including potentially sensitive data. Network World, 02/13/07.




