Cisco patches flaws in PIX, ASA appliances

Opinion
May 3, 20073 mins

* Patches from Cisco, Apple, Debian, others * How to find your security holes, and other interesting reading

Today’s bug patches and security alerts:

Cisco patches LDAP and VPN vulnerabilities in PIX and ASA appliances

According to a Cisco advisory, “Multiple vulnerabilities exist in the Cisco Adaptive Security Appliance (ASA) and PIX security appliances. These vulnerabilities include two Lightweight Directory Access Protocol (LDAP) authentication bypass vulnerabilities and two denial-of-service (DoS) vulnerabilities.” Both flaws could be exploited to allow unauthorized traffic on a network.

**********

Apple patches QuickTime bug

Apple’s QuickTime for Java is vulnerable to a heap overflow that could be exploited to run malicious code on an unpatched system. Users should upgrade to QuickTime 7.1.6 to fix the problem.

Related:

Apple patches hack challenge’s QuickTime bug

Apple updates Mac OS X again

For the second time in two weeks, Apple has released an update for its Mac OS X operating system. This is intended to fix flaws in AirPort and FTPServer. The vulnerabilities are minor in nature.

**********

Security flaws found in PhotoShop

Not too often that we report security flaws in image editing applications: Secunia is reporting (here and here) that there are unpatched flaws in Adobe PhotoShop CS2 and the new CS3 edition. For the flaws to be exploited, a user would have to open a specially-crafted BMP or PNG image, which could trigger a buffer overflow. In English: Just open images from trusted sources (and really, the same goes for e-mail attachments.)

Secunia advisories;

Adobe Photoshop BMP.8BI Bitmap File Handling Buffer Overflow

Adobe Products PNG.8BI PNG File Handling Buffer Overflow

**********

Five new updates from Debian:

Linux kernel 2.6 (multiple flaws)

WordPress (multiple flaws)

qemu (multiple flaws)

PHP5 (multiple flaws)

PHP4 (multiple flaws)

**********

Two new fixes from Mandriva:

Quagga (denial of service)

ktorrent (directory traversal)

**********

Five new patches from Gentoo:

Quagga (denial of service)

Apache mod_perl (denial of service)

Tomcat (information disclosure)

FreeType (code execution)

Ktorrent (multiple flaws)

**********

From the interesting reading department:

Opinion: How to find your security holes

Exploiters on the Internet have caused billions of dollars in damages. These exploiters are intelligent cyber terrorists, criminals and hackers who have a plethora of tools available in their war chests ranging from spyware, rootkits, Trojans, viruses, worms, bots, and zombies to various other blended threats. Network World, 04/30/07.

Data breaches seen to threaten IT job security

A majority of IT professionals believe they will lose their jobs if their organization suffers a security breach. Network World, 05/02/07.

Gartner: Hack contests bad for business

A pair of Gartner analysts Tuesday denounced a recent hack challenge that uncovered a still-unpatched QuickTime bug, calling it “a risky endeavor” and urging sponsors to reconsider such public contests. Computerworld, 05/01/07.

Opinion: The color of information security

If information security were a color, it most definitely would be gray. Like life in general, information security is rarely black and white. As an information security consultant, most questions asked of me and my colleagues are answered in the same way: It depends. Network World, 05/01/07.

Steak n Shake beefs up security

Credit card security may not exactly be a top-of-mind item for customers dining on steak burgers and milkshakes at any of the 450-odd Steak n Shake restaurants scattered around the Midwest and Southeast. Computerworld, 04/30/07.

Symantec slips, but closes in on AV product delivery

Symantec is slipping on its target delivery time for the next major upgrade of its security product for enterprises, code-named Hamlet, while it irons out final code wrinkles during beta testing. IDG News Service, 05/02/07.

GAO report targets data breach guidelines

Report says agencies need to know how and when to offer credit monitoring and other services to reduce the risk of identity theft. NetworkWorld.com, 04/30/07.