Cisco Secure Access Control Server flaws patched

Opinion
Jan 8, 20073 mins

* Patches from Cisco, Microsoft, Gentoo, others * Top 10 viruses for December, according to Sophos * A new SSL certificate is on the way, and other interesting reading

Today’s bug patches and security alerts:

Cisco warns of flaw in Secure Access Control Server

According to a Cisco advisory, “Certain versions of Cisco Secure Access Control Server (ACS) for Windows and the Cisco Secure ACS Solution Engine (here after both referred to as purely Cisco Secure ACS) are affected by multiple vulnerabilities that cause specific Cisco Secure services to crash. Two of the vulnerabilities may permit arbitrary code execution after exploitation of the specified vulnerability.” A patch is available.

**********

Microsoft pulls four planned security patches

Microsoft has eliminated four of eight previously announced security patches scheduled to be available to system administrators next Tuesday. IDG News Service, 01/05/07.

Microsoft advisory

**********

Patch issued for OpenOffice.org WMF vulnerability

A patch has been widely released for a vulnerability in the OpenOffice.org productivity suite, a problem rated as “highly critical” by one security vendor. The flaw could be exploited by creating a malicious file in the Windows Metafile (WMF) or Enhanced Metafile (EMF) formats. If the file was opened by a user, it could start running unauthorized code on a computer, according to an advisory by Linux distribution vendor Red Hat, which offers the OpenOffice suite with several of its products. IDG News Service, 01/04/07.

NGSSoftware advisory

**********

Adobe calls for upgrades to mitigate vulnerability

Adobe Systems Inc. is urging users to update to the latest versions of Adobe Reader and Acrobat to avoid being affected by a recently discovered cross-site scripting flaw in its software that allows attackers to run malicious JavaScript on a user’s PC. Computerworld, 01/05/07.

**********

Latest “Month of Apple Bugs” advisories:

1/4: iLife iPhoto Photocast XML title Format String Vulnerability

1/5: Apple DiskManagement BOM Local Privilege Escalation Vulnerability

1/6: Multiple Vendor PDF Document Catalog Handling Vulnerability

**********

Two new fixes for Drupal CMS:

Two flaws have been found in the core code of the Drupal open source content management system. Flaw one could be exploited to run malicious code and again administrator privileges on an affected server. Flaw two could be used in a denial-of-service attack against a system.

**********

Three new patches from Gentoo:

DenyHosts (denial of service)

Mozilla Firefox (multiple flaws)

Mozilla Thunderbird (multiple flaws)

**********

Four new updates from OpenPKG:

bzip2 (multiple flaws)

Drupal (multiple flaws)

fetchmail (multiple flaws)

WordPress (privilege escalation, code execution)

**********

Four new updates from Ubuntu:

Firefox (regression error)

Thunderbird (multiple flaws)

D-Bus (local denial of service, data loss)

Avahi (denial of service)

**********

Top 10 viruses for December, according to Sophos:

1. Dref (35.2%)

2.Netsky (22.2%)

3. Mytob (10.7%)

4. Stratio (7.8%)

5. Bagle (5.2%)

6. Zafi (4.8%)

7. MyDoom (3.3%)

8. Sality (2.8%)

9. Nyxem (1.3%)

10. StraDl (0.9%)

**********

From the interesting reading department:

A new SSL certificate is on the way

Web-based businesses face a crisis in consumer confidence because of phishing scams. But because of a new kind of SSL certificate, Web sites will be able to definitively demonstrate their identity, and customers will be able to confirm the identity of trusted sites. Network World, 01/04/07.

Study: IPSec fades; SSL grows for remote access security

Remote access IPSec VPNs are no longer on the radar screen of companies that seek the advice of consultants at Gartner, according to a new report. Network World, 01/04/07.

Happy New Year worm unmasked as stock scam

The Happy New Year worm that caused mild alarm towards the end of last year now appears to be nothing more than a high-profile stock manipulation scam. TechWorld, 01/03/07.