Multiple flaws in Cisco Clean Access

Opinion
Jan 4, 20075 mins

* Patches from Cisco, Ubuntu, Trustix, others * "Happy New Year!" worm on the move * Microsoft sees botnets as top cyber-threat, and other interesting reading

With the New Year upon us, we have two podcasts that look at the year ahead:

Major Looming Threats for 2007

Will YouTube become a major source of a computer virus in 2007? Will there be a significant ATM (automated teller machine) attack that cripples banking institutions? How will major operating systems have to “step back in time” in order to move forward? Savant Protection CEO Ken Steinberg (pictured) chats with Senior Editor Keith Shaw about these predictions and a few other security-related threats looming on the horizon for 2007. (15:47)

Top Security Threats for 2007

Are the major security threats of the past few years going to continue, or are there new security threats on the horizon that a network manager needs to know about? Keith Shaw talks with Mike Paquette (pictured), chief strategy officer at Top Layer Networks, about the looming threats for 2007, and what network managers need to be ready for. (11:14)

Do you agree with the experts? What security threats in the upcoming year worry you the most? Drop me line at jmeserve@nww.com with your thoughts and I’ll publish them in an upcoming newsletter.

Happy New Year to all our readers and safe computing in 2007!

Today’s bug patches and security alerts:

Multiple flaws in Cisco Clean Access

Cisco is warning of a flaw in its Clean Access product, which is used to detect, isolate and clean infected systems on a corporate network. One flaw could allow snapshot files to be read. Another results in an unchangeable shared secret, according to a Cisco advisory. Updates are available.

**********

Acrobat Reader plugin vulnerable to attacks

Security researchers are poring over what one vendor has called a “breathtaking” weakness in the Web browser plugin for Adobe Systems Inc.’s Acrobat Reader program, used to open the popular “.pdf” file format. IDG News Service, 01/03/07.

Symantec Weblog entry on the issue

**********

Microsoft acknowledges vulnerability in Vista

A vulnerability that affects four of Microsoft’s operating systems, including Vista, doesn’t appear to pose a great risk, according to one security vendor. IDG News Service, 12/22/06.

Microsoft’s Security Blog entry

**********

Imperva identifies AJAX flaw

Security vendor Imperva has identified a vulnerability in AJAX, which it says an attacker could use to compromise an application based on the Web scripting components known collectively as AJAX (Asynchronous JavaScript + XML). The vulnerability in the Direct Web Reporting component of the AJAX development framework is probably the first server-side-based vulnerability to be identified, according to Imperva, which has issued guidance on a workaround that would let application programmers close the hole. Network World, 01/03/07.

**********

Google closes Gmail cross-site scripting vulnerability

Google has fixed a flaw that would have allowed Web sites to harvest information from Gmail contact lists, a problem that could have let spammers collect reams of new e-mail addresses. IDG News Service, 01/02/07.

**********

“Month of Apple Bugs” to date (1/1 through 1/3):

1. Apple Quicktime rtsp URL Handler Stack-based Buffer Overflow

2. VLC Media Player udp:// Format String Vulnerability

3. Apple Quicktime HREFTrack Cross-Zone Scripting vulnerability

**********

Trustix releases “multi” update

The newest update from Trustix patches flaws in the kernel and ProFTPD. The most serious of the flaws could be exploited to bypass security restrictions.

**********

Two updates from rPath:

Mozilla Thunderbird (multiple flaws)

Mozilla Firefox (multiple flaws)

**********

Two new patches from Ubuntu:

Mozilla Firefox (multiple flaws)

w3m (format string, code execution)

**********

Five updates from Debian:

links2 (insufficient input sanitization, shell command execution)

xine-lib (buffer overflow, code execution)

evince (buffer overflow, code execution)

elog (multiple flaws)

squirrelmail (cross-scripting attack)

**********

Half-dozen patches from OpenPKG:

Ruby (denial of service)

D-Bus (denial of service)

OpenSER (buffer overflow, code execution)

links (insufficient input sanitization, shell command execution)

w3m (format string, code execution)

Cacti (multiple flaws)

**********

Three new fixes from Mandriva:

Kernel (multiple flaws)

libmodplug (multiple buffer overflows)

mono (source code disclosure)

**********

Big virus news of the week:

“Happy New Year!” worm on the move

VeriSign is warning of a new e-mail worm arriving in inboxes with the subject “Happy New Year!” The message, currently being spread from 160 e-mail domains, requires users to click on the attached “postcard.exe” file in order to cause damage. The file will install several different malicious code variants including Tibs, Nwar, Banwarum and Glowa on the computer. It then executes mass mailings from the infected computer. IDG News Service, 12/29/06.

**********

From the interesting reading department:

Microsoft sees botnets as top cyber-threat

If there’s one thing that Aaron Kornblum would like to quash, it’s the botnet armies. These are the remote-controlled PCs that have been taken over without their user’s knowledge. Symantec Corp. counted more than 4.5 million of them during the first six months of the year, and according to Kornblum, they are the backbone of today’s cybercrime. IDG News Service, 12/27/06.

Spam project pulls plug

Antispam blacklist service, The Open Relay Database (ORDB), has pulled the plug after five and a half years because of spammers’ growing sophistication. TechWorld, 12/21/06.

Santa’s Web site hacked

With Christmas fast approaching, Santa Claus reached out for a little help from Stopbadware.org this week. The consumer advocacy group said it was approached by an Incline Village, Nevada, man who has legally changed his name to Santa Claus, who asked them to help figure out why his Web site was being flagged by Google Inc.’s Web site filters. IDG News Service, 12/21/06.