* Patches from Cisco, Ubuntu, Debian * Code posted for IE attack * Q&A: New IAB chair mulls DNS security, unwanted Internet traffic, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Cisco warns of CallManager, Presence Server flaws
According to the Cisco advisory, “Cisco Unified CallManager (CUCM) and Cisco Unified Presence Server (CUPS) contain multiple vulnerabilities which may result in the failure of CUCM or CUPS functionality, resulting in a Denial of Service (DoS) condition. There are no workarounds for these vulnerabilities. Cisco has made free software available to address these vulnerabilities for affected customers.”
**********
Six new patches from Ubuntu:
Network Audio System (multiple flaws)
XMMS (image handling, code execution)
OpenOffice.org (multiple flaws)
Firefox (ftp handling, information disclosure)
Evolution (format string, code execution)
**********
Two new updates from Debian:
Network Audio System (multiple flaws)
OpenOffice.org (multiple flaws)
**********
Malware news of the day:
Code posted for IE attack
New software has been published on the Internet that could be used to exploit a known flaw in Internet Explorer. The code, which was posted Monday to the Milw0rm.com Web site, exploits a recently patched flaw in Microsoft’s browser. It could be used to run unauthorized software on a computer that was not updated with the latest Microsoft patches, security experts warn. IDG News Service, 03/26/07.
**********
From the interesting reading department:
Q&A: New IAB chair mulls DNS security, unwanted Internet traffic
IAB chair Olaf Kolkman says DNSSEC isn’t a failure, but it will take a while for the security extensions to become widely deployed. Network World, 03/28/07.
Breach of data at TJX is called the biggest ever
At least 45.7 million credit and debit card numbers were stolen by hackers who accessed the computer systems at the TJX Cos. at its headquarters in Framingham and in the United Kingdom over a period of several years, making it the biggest breach of personal data ever reported, according to security specialists. Boston Globe, 03/29/07.
Should felons be allowed to be IT managers?
Or should circumstances be considered on a case-by-case basis? One Nebraska county seems to think so. Network World, 03/28/07.
Startup aims to keep network security vendors honest
With the help of one of the world’s best-known hackers, a little-known Austin startup hopes to give Internet service providers and enterprises a way to tell if their networking hardware is living up to its promises. IDG News Service, 03/28/07.
Hackers build private IM to keep out the law
Hackers have built their own encrypted IM program to shield themselves from law enforcement trying to spy on their communication channels. IDG News Service, 03/28/07.




