- Cool Yule Tools: 2008 Holiday Gift Guide
- 10 kitchen gadgets for the geek gourmet
- Google admits to violating iPhone development terms
- Smartphone smackdown: Storm vs. iPhone
- Google layoffs: 10,000 jobs being cut
Jason Meserve provides up-to-the-minute news on vendor security alerts and fixes.
Cisco patches flaws in ASA and PIX
According to to Cisco, "Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco
PIX Security Appliances that may result in a reload of the device or disclosure of confidential information." Updates are
available for affected systems.
Cisco fixes denial-of-service flaw in Secure ACS
A flaw in the way Cisco's Secure ACS system handles RADIUS EAP packets could be exploited in a denial-of-service attack against
an affected system. Cisco has released an update for this issue.
**********
Early security issues tarnish Google's Chrome
Security researchers have reported finding vulnerabilities in Google's new Web browser a day after it was released in beta.
IDG News Service, 09/03/2008.
Also:
Chrome gets first ding
Video: Chrome a good start, but has a ways to go
**********
Four new updates from Mandriva:
python-django (cross site scripting)
libtiff (denial of service, code execution)
opensc (authentication bypass)
wordnet (heap overflow, code execution)
**********
Three new fixes from FreeBSD:
icmp6 (denial of service)
nmount (buffer overflow, code execution)
amd64 swapgs (code execution)
**********
Two new patches from Ubuntu:
tiff (denial of service, code execution)
Yelp (format string, code execution)
**********
Two new fixes from Debian:
wordnet (heap overflow, code execution)
slash (SQL injection, cross scripting)
Jason Meserve is multimedia editor at Network World.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment