Cisco, Microsoft and Apple security issues

Opinion
Nov 2, 20064 mins

* Cisco, Microsoft and Apple security issues * Top 10 reported virus infections for the past week from Sophos * Hackers break into water system network, and other interesting reading

Cisco, Microsoft and Apple security issues

Today’s bug patches and security alerts:

Vulnerability found in Visual Studio 2005

A vulnerability in Visual Studio 2005 could let an attacker execute code on a targeted Windows machine, Microsoft said Wednesday. Danish security vendor Secunia rated the vulnerability as “extremely critical” since it hasn’t been patched and there are unconfirmed reports it’s being exploited, Secunia CTO Thomas Kristensen said. IDG News Service, 11/01/06.

Secunia advisory

Microsoft response

New Windows attack can kill firewall

Hackers have published code that could let an attacker disable the Windows Firewall on certain Windows XP machines. IDG News Service, 10/30/06.

nCircle blog item about the attack

**********

Flaw found in Cisco Security Agent Management Center

According to a Cisco advisory, “Cisco Security Agent Management Center (CSAMC) contains an administrator authentication bypass vulnerability when configured to use an external Lightweight Directory Access Protocol (LDAP) server for authentication.” A free update is available to fix the issue.

**********

Apple releases XTools update to fix flaw

A flaw in GDB, a GNU debugger application that comes with XTools, could be exploited to run malicious code on an affected machine, according to an Apple advisory. Users should upgrade to XTools 2.4.1 to fix the flaw.

**********

Trustix releases fix for postgresql

Two flaws in the postgresql database application for Trustix have been fixed. The flaws could be exploited to crash the database server and potentially execute SQL commands.

**********

SuSE patches php4, php5

Two vulnerabilities in the PHP scripting engine could be exploited to run malicious code on an affected machine. SuSE has update its implementations of PHP4 and PHP5 to fix the flaws.

**********

New updates from Ubuntu:

wvWare (integer overflow, code execution)

mutt (race condition, local file execution)

Ruby (denial of service)

screen (denial of service)

**********

New patches from Debian:

screen (denial of service)

Ethereal (multiple flaws)

qt-x11-free (integer overflow, code execution)

**********

Two new updates from OpenPKG:

screen (denial of service)

wordpress (multiple flaws)

**********

Mandriva releases two fixes:

postgresql (denial of service)

ImageMagick (multiple buffer overflows, code execution)

**********

Three fixes from Gentoo:

Asterisk (multiple flaws)

PHP (integer overflow, code execution)

Cheese Tracker (buffer overflow, code execution)

**********

Top 10 viruses for the month of October, according to Sophos:

1. W32/Netsky-P (15.2%)W32/Mytob-AS (12.2%)W32/Stratio-Zip (5.7%)W32/Bagle-Zip (5.3%)W32/Netsky-D (5.1%)W32/Stratio-AY (4.3%)W32/Mytob-C (3.5%)W32/Zafi-B (3.4%)W32/Nyxem-D (3.1%)W32/Mytob-E (2.6%)

2.

3.

4.

5.

6.

7.

8.

9.

10.

**********

From the interesting reading department:

Spam that delivers a pink slip

Last week, a handful of employees at Dekalb Medical Center in Decatur, Ga., received e-mails saying they were being laid off. The subject line read “Urgent — employment issue,” and the sender listed on the message was at dekalb.org, which is the domain the medical center uses. The e-mail contained a link to a Web site that claimed to offer career-counseling information. NetworkWorld.com, 11/01/06.

Hackers break into water system network

An infected laptop gave hackers access to computer systems at a Harrisburg, Pennsylvania, water treatment plant earlier this month. IDG News Service, 10/31/06.

Hacker project puts spotlight back on Mac security

The security of Apple Computer Inc.’s wireless drivers is under scrutiny again, thanks to a new hacker project. IDG News Service, 11/01/06.

Conflicts lead to tense times in security

I just returned from the Information Security Decisions conference, where I had many opportunities to compare notes with fellow security practitioners. Two big issues keep coming up in which conflicting interests are leaving us with nearly insoluble problems. Network World, 11/02/06.

SophosLabs chief on lookout for hidden viruses, world’s stupidest spammers

As global director of Sophos Labs for the past year, Mark Harris says he has been pleasantly surprised not to have been woken up in the middle of the night every time a new virus strikes. He attributes that to the round-the-clock handoff of antivirus and antispam research and analysis work between Sophos’ labs in Boston, Vancouver, Abington, U.K. and Sydney, Australia. Network World, 10/30/06.