* Patches from Cisco, Microsoft, Gentoo, others * Top 10 viruses for December, according to Sophos * A new SSL certificate is on the way, and other interesting reading
Today’s bug patches and security alerts:
Cisco warns of flaw in Secure Access Control Server
According to a Cisco advisory, “Certain versions of Cisco Secure Access Control Server (ACS) for Windows and the Cisco Secure ACS Solution Engine (here after both referred to as purely Cisco Secure ACS) are affected by multiple vulnerabilities that cause specific Cisco Secure services to crash. Two of the vulnerabilities may permit arbitrary code execution after exploitation of the specified vulnerability.” A patch is available.
**********
Microsoft pulls four planned security patches
Microsoft has eliminated four of eight previously announced security patches scheduled to be available to system administrators next Tuesday. IDG News Service, 01/05/07.
**********
Patch issued for OpenOffice.org WMF vulnerability
A patch has been widely released for a vulnerability in the OpenOffice.org productivity suite, a problem rated as “highly critical” by one security vendor. The flaw could be exploited by creating a malicious file in the Windows Metafile (WMF) or Enhanced Metafile (EMF) formats. If the file was opened by a user, it could start running unauthorized code on a computer, according to an advisory by Linux distribution vendor Red Hat, which offers the OpenOffice suite with several of its products. IDG News Service, 01/04/07.
**********
Adobe calls for upgrades to mitigate vulnerability
Adobe Systems Inc. is urging users to update to the latest versions of Adobe Reader and Acrobat to avoid being affected by a recently discovered cross-site scripting flaw in its software that allows attackers to run malicious JavaScript on a user’s PC. Computerworld, 01/05/07.
**********
Latest “Month of Apple Bugs” advisories:
1/4: iLife iPhoto Photocast XML title Format String Vulnerability
1/5: Apple DiskManagement BOM Local Privilege Escalation Vulnerability
1/6: Multiple Vendor PDF Document Catalog Handling Vulnerability
**********
Two new fixes for Drupal CMS:
Two flaws have been found in the core code of the Drupal open source content management system. Flaw one could be exploited to run malicious code and again administrator privileges on an affected server. Flaw two could be used in a denial-of-service attack against a system.
**********
Three new patches from Gentoo:
Mozilla Firefox (multiple flaws)
Mozilla Thunderbird (multiple flaws)
**********
Four new updates from OpenPKG:
WordPress (privilege escalation, code execution)
**********
Four new updates from Ubuntu:
D-Bus (local denial of service, data loss)
**********
Top 10 viruses for December, according to Sophos:
1. Dref (35.2%)
5. Bagle (5.2%)
6. Zafi (4.8%)
9. Nyxem (1.3%)
10. StraDl (0.9%)
**********
From the interesting reading department:
A new SSL certificate is on the way
Web-based businesses face a crisis in consumer confidence because of phishing scams. But because of a new kind of SSL certificate, Web sites will be able to definitively demonstrate their identity, and customers will be able to confirm the identity of trusted sites. Network World, 01/04/07.
Study: IPSec fades; SSL grows for remote access security
Remote access IPSec VPNs are no longer on the radar screen of companies that seek the advice of consultants at Gartner, according to a new report. Network World, 01/04/07.
Happy New Year worm unmasked as stock scam
The Happy New Year worm that caused mild alarm towards the end of last year now appears to be nothing more than a high-profile stock manipulation scam. TechWorld, 01/03/07.




