* Patches from VMWare, Cisco, Microsoft, others * Nigerian scammers do a take-off on Three Kings * Next-generation multimedia networks face security challenges, and other interesting reading
Today’s bug patches and security alerts:
Cisco reports multilple flaws IOS FTP Server
The Cisco IOS FTP Server, which is not enabled by default, is vulnerable to denial-of-service attacks, improper validation of credentials and the ability to read or write any file in the device’s filesystem, according to Cisco. A free update is available to fix the issues.
**********
VMWare patches denial-of-service issues
A flaw in the way certain VMWare applications handle memory on Windows-based guest operating systems could be exploited in a denial-of-service attack. VMWare does not believe an attacker could exploit the flaw “to escalate privileges or escape virtual containment.”
**********
Microsoft’s fixes nasty DNS server, Exchange flaws
Microsoft has released its May set of security patches, fixing critical bugs in Windows, Office and Exchange. Seven groups of patches, called updates in Microsoft parlance, were released Tuesday, fixing a total of 19 bugs. Microsoft rates all seven of these updates as critical, but security experts said that IT administrators should be particularly concerned with the MS07-026 and MS07-029 updates, which fix flaws in Exchange and the Windows DNS (Domain Name System) server. IDG News Service, 05/08/07.
Microsoft advisories:
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
Vulnerability in Microsoft Office Could Allow Remote Code Execution
Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution
Cumulative Security Update for Internet Explorer
Vulnerability in CAPICOM Could Allow Remote Code Execution
Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution
Related:
**********
Two new updates from rPath:
**********
Two new fixes from Ubuntu:
**********
Two new patches from Debian:
ldap-account-manager (multiple flaws)
**********
Three new fixes from Mandriva:
Python 2.4 and 2.5 (multiple flaws)
**********
Six new patches from Gentoo:
MySQL (denial of service flaws)
LibXfont, TightVNC (multiple flaws)
IPsec-Tools (denial of service)
GIMP (buffer overflow, code execution)
Lighttpd (denial of service flaws)
**********
Today’s malware news:
Nigerian scammers do a take-off on Three Kings
A twist on the classic Nigerian e-mail scam that steals from the plot of the George Clooney movie Three Kings is hitting inboxes, Symantec said Monday. Computerworld, 05/08/07.
**********
From the interesting reading department:
Next-generation multimedia networks face security challenges
There may be no hotter topic in telecom right now than IP Multimedia Subsystem (IMS), an evolving standard that promises to offer a common way for multiple wireless and wireline networks to deliver multimedia applications. Network World, 05/08/07.
Avinti upgrade targets blended threats
Avinti on Wednesday announced a new version of its e-mail security software designed to catch inbound messages with active content and embedded URLs that can expose recipients to Internet threats. Network World, 05/09/07.
Cybercrime update: Is organized crime moving into cybersphere?
As if FBI special agent Tim O’Brien and his cybercrime fighting comrades don’t already have their hands full with bot herders, virus writers and other loosely-aligned crooks, now people are wondering when more traditional organized crime will grab a piece of the action. NetworkWorld.com, 05/09/07.




