Cisco ACS Server EAP-TLS authentication flaw

Opinion
Nov 4, 20045 mins

* Patches from Sun, Debian, Conectiva, others * Beware ever more Rbot variants * Symantec pushing into mobile space, and other interesting reading

Today’s bug patches and security alerts:

Cisco reports flaw in Secure Access Control Server EAP-TLS Authentication

A flaw in Version 3.3.1 of the Cisco Secure ACS for Windows and Cisco Secure ACS Solution Engine could provide authentication to any “cryptographically correct” certificate. This means any certificate with the right fields in place, regardless of the fact that it’s expired or comes from an untrusted certificate authority, could be used to gain access to a network protected by this Cisco system. For more, go to:

https://www.nwfusion.com/go2/1101bug2a.html

**********

Sun patches Java System Web Proxy Server 3.6

Sun reports that its Java System Web Proxy Server 3.6 does not properly handled “connect” requests and has a number of buffer overflow issues. A remote attacker could exploit these vulnerabilities to crash the affected system or potentially run their code of choice on it. For more, go to:

https://wwws.sun.com/software/download/products/4149bc42.html

**********

Debian patches xpdf

A flaw in various implementations of a PDF viewer application could be exploited to crash the affected application or potentially run arbitrary code on the affected machine. For more, go to:

https://www.debian.org/security/2004/dsa-581

**********

Conectiva patches squid

A denial-of-service vulnerability has been found in Squid’s ASN1 parser. It could be exploited to crash the system. For more, go

to:

https://www.nwfusion.com/go2/1101bug2b.html

**********

Conectiva, Mandrake Linux update gaim

A buffer overflow in Gaim, an open source instant messaging client, could be exploited in a denial-of-service attack against the application or to potentially run any code on the affected machine. For more, go to:

Conectiva:

https://www.nwfusion.com/go2/1101bug2c.html

Mandrake Linux:

https://www.nwfusion.com/go2/1101bug2d.html

**********

Debian, Gentoo patch libxml

A number of buffer overflows have been found in the libxml and libxml2 code, the XML C parser and toolkits for GNOME. These flaws could be exploited to run an attacker’s code of choice on the affected machine. For more, go to:

Debian:

https://www.debian.org/security/2004/dsa-582

Gentoo:

https://security.gentoo.org/glsa/glsa-200411-05.xml

**********

Security update for TiVo Desktop

This may not be an “enterprise” issue, but I am guessing a number of our readers have TiVo running at home. If you do and you’re running TiVo Desktop (for picture/music sharing), there’s a new version available that fixes a security vulnerability found in previous releases. Users should upgrade to Version 1.3. For more, go to:

https://www.tivo.com/4.9.4.1.asp

**********

Today’s roundup of virus alerts:

W32/Rbot-NT – What would a newsletter be without an Rbot variant? This one installs itself as “winvc32.exe” in the Windows System directory after infiltrating the machine via network shares. It opens a backdoor through an IRC channel. (Sophos)

W32/Rbot-NU – Another Rbot variant. This one tries to exploit the WebDav, LSASS or RPC-DCOM vulnerabilities in Windows (all of which have long had patches available.) It installs itself as “winservice.exe”. (Sophos)

W32/Rbot-NY – The trifecta for Rbot. This variant uses the filename “crsss64.exe” and can be used for keystroke logging, DDoS attacks and video capture. (Sophos)

W32/Rbot-NZ – Grand Slam! Our fourth Rbot variant copies itself into the file “sysmsvc.exe” and can be used to send e-mail, start an FTP session, download/execute files, capture keystrokes and start a port scan. (Sophos)

W32/Rbot-NV – This Rbot variant can be used for a number of malicious purposes. It tries to exploit what looks like every known Windows vulnerability as it spreads between network shares using the filename “BLING.EXE”. When it infects a system, it installs itself in the system directory as “svchcst.exe”. (Sophos)

W32/Rbot-OB – Similar to the other variants of Rbot already mentioned. This one installs itself as “winxpini.exe”, though it’s a hidden/read-only file. (Sophos)

W32/MyDoom-AG – A new MyDoom variant that spreads via e-mail with varying attributes. One common theme in the infected message is the word “WORLDXXXPASS.COM” and the attached file will have an extension of zip, exe, scr, pif, bat, or cmd. (Sophos)

W32/Agobot-NS – A bot that tries to block access to popular security related Web sites. It spreads via network shares, installing itself as “SVCHOSTT.EXE” in the Windows System directory. (Sophos)

**********

From the interesting reading department:

Symantec pushing into mobile space

Symantec is making a major push to get its security products into more mobile phones as 3G services and smart phone use spreads internationally, company executives said in Tokyo on Thursday. IDG News Service, 11/04/04.

https://www.nwfusion.com/news/2004/1104symanpushi.html?nl

Hackers reopen stolen code store with Cisco wares

An anonymous group of malicious hackers reopened an online store that sells the stolen source code of prominent software products and is offering the code for Cisco’s PIX firewall software to interested parties for $24,000, according to messages posted in online discussion groups. IDG News Service, 11/03/04.

https://www.nwfusion.com/news/2004/1103hackers.html?nl

AOL joins industry anti-spam, anti-virus group

Internet service provider America Online Monday said it has joined the Messaging Anti-Abuse Working Group, which was formed last December by a group of communications and technology companies to fight spam, viruses and other online attacks and nuisances. Computerworld, 11/01/04.

https://www.nwfusion.com/news/2004/1101aoljoins.html?nl