* Patches from Cisco, Google, Ubuntu, others * Microsoft falls victim to shady 'scareware' * Phishing scam uses Google Maps to locate victims, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Cisco warns of multiple flaws in 802.1X Supplicant
A number of vulnerabilities in the Cisco Secure Services Client, which is part of the company’s 802.1X authentication system, could be exploited to gain elevated privileges and disclose sensitive information. An update is available.
Cisco warns of Unified IP Conference Station and IP Phone flaws
According to Cisco, “Certain Cisco Unified IP Conference Station and IP Phone devices contain vulnerabilities which may allow unauthorized users to gain administrative access to vulnerable devices.” Affected products include Unified IP Conference Station 7935 and 7936 as well as Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G and 7971G.
Cisco says 77 of routers open to ‘drive-by pharming’
Cisco is warning users that nearly 80 of its routers are vulnerable to a hack tactic that got play last week. Dubbed “drive-by pharming” by Symantec and university researchers who first publicized the danger in a paper, the attack involves luring users to malicious sites where a device’s default password is used to redirect them to bogus sites. Once they are at those sites, their identities could be stolen or malware could be force-fed to their computers. Computerworld, 02/20/07.
**********
Google Shuts Hole in Desktop Product
A potentially devastating hole in Google Inc.’s prevalent desktop search product could have exposed personal files on users’ computers to data thieves. Google fixed the defect within weeks of being informed about it and says it has no evidence the vulnerability was exploited. WashingtonPost.com, 02/21/07.
**********
Firefox update postponed by newest bug
Mozilla will delay the next security update for Firefox so it can test a fix for a flaw that could be used by attackers to skirt security restrictions. Computerworld, 02/20/07.
**********
Two new updates from Ubuntu:
MoinMoin (cross-scripting attack)
**********
Half dozen patches from Mandriva:
gnucash (symlink attack, code execution)
**********
Virus/Malware news of the week:
Microsoft falls victim to shady ‘scareware’
Microsoft said it moved quickly to remove a banner advertisement that appeared on its instant-messaging program for a software application that falsely hypes security threats on a user’s computer. IDG News Service, 02/20/07.
**********
From the interesting reading department:
Phishing scam uses Google Maps to locate victims
Account holders with at least two Australian banks have become victims of a phishing scam in which malicious code reveals the physical location of affected IP addresses using Google Maps. Bank account holders in Germany and the U.S. have also been targeted. Computerworld, 02/20/07.
Windows Defender fails in new malware test
Windows Defender has been slated in a new test that found it could detect barely half of the malware thrown at it during the last year. TechWorld, 02/20/07.
Watchfire tools ease security checks
Watchfire is upgrading its application vulnerability-testing software so it’s easier for Web software developers to run scans on code and to close security holes. Network World, 02/21/07.
Data thieves target supermarket chain’s checkout lines
Supermarket chain Stop & Shop issued a news release onto the wire Saturday during the long weekend to say that it has been hit by identity thieves. Network World, 02/20/07.




