* Patches from Cisco, Debian, Gentoo, others * Top 10 viruses for the past seven days * Microsoft: No patch yet for DNS Server bug, and other interesting reading
endif; ?>Slightly off-topic to lead off: My colleagues at Wainhouse Research are running their annual survey looking at Web conferencing usage. If you’ve got an opinion on the topic, you could win a cool prize.
How is Web Conferencing being used? What are the most important features?
Take a short survey and Wainhouse Research will send you a free high-level summary of the results. Here’s your chance to influence vendors and service providers – who very much want to know how you feel – and win an Apple iPod or Amazon gift certificates (up to $500) for your time. Click here to take the survey.
Today’s bug patches and security alerts:
Cisco patches Crafted IP Option Vulnerability
According to the Cisco advisory: Cisco routers and switches running Cisco IOS or Cisco IOS XR software may be vulnerable to a remotely exploitable crafted IP option Denial of Service (DoS) attack. Exploitation of the vulnerability may potentially allow for arbitrary code execution. The vulnerability may be exploited after processing an Internet Control Message Protocol (ICMP) packet, Protocol Independent Multicast version 2 (PIMv2) packet, Pragmatic General Multicast (PGM) packet, or URL Rendezvous Directory (URD) packet containing a specific crafted IP option in the packet’s IP header. No other IP protocols are affected by this issue.
Cisco fixes Default Passwords in NetFlow Collection Engine
Cisco is warning that its NetFlow Collection Engines prior use default accounts identical username and password. Attackers could exploit this to gain access to an affected system. An update is available.
**********
Three new updates from Debian:
aircrack-ng (buffer overflow, code execution)
webcalendar (script injection)
**********
Six new patches from Gentoo:
aircrack-ng (buffer overflow, code execution)
3proxy (buffer overflow, code execution)
NAS (buffer overflow, code execution)
**********
Two new fixes from Mandriva:
zziplib (buffer overflow, code execution)
**********
Top 10 viruses for the past seven days, according to Trend Micro:
1. Troj_Generic (18,679)
2. Expl_Anicmoo.Gen (13,317)
3. Worm_Anig.F (7,279)
4. Troj_Agent.Mzz (6,282)
5. Worm_Nyxem.E (6,013)
6. Possible_Infostl (5,841)
7. Troj_Dloader.Lcx (5,530)
8. Html_Netsky.P (5,302)
9. Worm_Anig.A (4,986)
10. Worm_Netsky.P (4,976)
**********
From the interesting reading department:
Microsoft: No patch yet for DNS Server bug
Microsoft’s security team Sunday said it is still working on a patch for a critical bug in the company’s server software. Computerworld, 04/23/07.
Experts: U.S. vulnerable to major cyberattacks
The U.S. government needs to take action now to avoid crippling cyberattacks that could shut down major communications systems nationwide, a group of cybersecurity experts told U.S. lawmakers Wednesday. IDG News Service, 04/25/07.
New approaches to malware detection coming into view
The traditional signature-based method to detect viruses and other malware is increasingly seen as an insufficient defense given the rapid pace at which attackers are churning out virus and spyware variants. All of which raises the question: What’s next?




