On mySimon: Star Wars Mimobot Flashdrives
BNET Business Network:
BNET
TechRepublic
ZDNet

February 16th, 2007

Think 'Patch Tuesday' is just for Microsoft? Think again!

Posted by George Ou @ 11:34 pm

Categories: Browsers, Desktop, Hardware, Mobile/Wireless, Networking, Security, Vista, VoIP

Tags:

Multiple Cisco vulnerabilities affecting IPS functionality in routers, PIX/ASA/FWSM firewalls, Switches.  Multiple Cisco vulnerabilities affecting SIP/FTP/HTTP inspection in PIX/ASA products.  While the patches are available, most Cisco devices are rarely if ever patched.  For example, here is a long list of issues within the last three months that many people are unaware of.  The common assumption for too many people is that network devices are plumbing and that you don't really have to think about them.  This list should scare you enough to patch every Cisco device on your network to the latest stable software release.  You should get in to a permanent monthly "patch Tuesday" frame of mind for your Cisco equipment.

Cisco Firewall Services Module SIP DoS and ACL Corruption
Cisco IOS IPS Security Bypass and Denial of Service
Cisco IOS SIP Packet Handling Reload Denial of Service
Cisco IOS VTP Denial of Service Vulnerability
Cisco IOS Multiple Vulnerabilities
Cisco Products SSL/TLS and SSH Validation Security Issue
Cisco IOS DLSw Denial Of Service Vulnerability
Cisco Multiple Products JTapi Gateway Denial Of Service
Cisco Secure ACS Multiple Vulnerabilities
Cisco Clean Access Predictable Snapshots Filename
Cisco Clean Access Unchangeable Secret Security Issue
Cisco Secure Desktop Multiple Vulnerabilities
Cisco Products OpenSSL Vulnerabilities
Cisco Products OpenSSL Vulnerabilities
Cisco Security Agent LDAP Authentication Bypass

Microsoft had a relatively large batch of patches for the month of February to clear out a backlog of zero-day Microsoft Office exploits (Office 2007 exempt).  The first Vista remote exploit is ironically in the software that's suppose to be scanning for Malware.

If you're running Trend Micro, you have two critical flaws to worry about so far this month.  There's a critical flaw in an ActiveX component from today and a critical UPX parsing flaw from last week.

Apple patches multiple critical vulnerabilities.  Many of these issues were zero-day exploits released during the MoAB (Month of Apple Bugs).

Firefox had a moderately critical flaw from today for this month though it isn't nearly as bad as the nine highly critical flaws last month.

There was a critical zero-day exploit for the Solaris Telnet Daemon for those who are unfortunately still using Telnet.  Sun did a great job and released an emergency patch within a day though I wish the patch would simply delete the Telnet Daemon

uTorrent (a superb BitTorrent Client) suffered its first security vulnerability when opening .Torrent files and it's a critical issue.  The stable version of 1.6.1 which has been patched for this vulnerability is available for download on the uTorrent website.

Aruba which makes Wireless Switch controllers and light weight access points suffered its first two critical vulnerabilities it its controller.  Patches are available on Aruba's support site.

Avaya VoIP products had two critical vulnerabilities this month.  There were several other less critical to moderately critical vulnerabilities in Avaya products this months and flaws of every severity level in every previous month.  Get use to the idea of doing a monthly "patch Tuesday" for Avaya products if you don't want your phone system to go down or worse, get hacked.

So what's the moral of the story?  The hardware and software industry needs to start doing some serious code auditing and patch Tuesday isn't just for Microsoft.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 44 Talkback(s)
Ladies and Gentlemen, this is what a zealot looks like
And his name is George Ou. (Read the rest)
Posted by: nomorems Posted on: 02/21/07 You are currently: a Guest | | Terms of Use
Patch Tuesday' is just for Microsoft  deaf_e_kate | 02/17/07
For Apple, Cisco, Avaya, Mozilla, it IS regular  georgeou | 02/17/07
Let see if it lasts for the non-MS systems  deaf_e_kate | 02/17/07
Firefox patched faster, but they had a LOT more bugs  georgeou | 02/17/07
Firefox doesn't cost $200+  Robert Crocker | 02/19/07
True issue  frgough | 02/19/07
And I've criticized them for this over and over again  georgeou | 02/19/07
I've also point out the DRM patches  georgeou | 02/19/07
and IE6 and iE5 and ie4  deaf_e_kate | 02/19/07
Firefox bundles minor patches  Greenknight_z | 02/21/07
How did 9 firefox 2 remote code execution exploits get bundled in to one?  georgeou | 02/21/07
I See you got your Check, from MS!  Rick_K | 02/19/07
5GB? Who's the liar?  georgeou | 02/19/07
L A W L  xxn1927 | 02/20/07
Nice!  xxn1927 | 02/20/07
in logic  frgough | 02/19/07
So what do you call it when...  NonZealot | 02/19/07
????  Rick_K | 02/19/07
The same thing  frgough | 02/19/07
What the hell are you talking about?  georgeou | 02/19/07
And the fun never stops!  D. T. Schmitz | 02/17/07
Complete and Utter FALLACY  Arthas | 02/18/07
Ladies and Gentlemen, this is what a zealot looks like  georgeou | 02/18/07
but George...  ImUpAbvIt | 02/18/07
Zealotry  frgough | 02/19/07
I saw the picture  Rick_K | 02/19/07
Did you miss these blogs?  georgeou | 02/19/07
Take a good look in the mirror  dragosani | 02/19/07
And look at all of his brethren!!  NonZealot | 02/19/07
Speaking of Zealots  Rick_K | 02/19/07
No, no, no!  frgough | 02/19/07
Au contraire  MacCanuck | 02/20/07
Ladies and Gentlemen, this is what a zealot looks like  nomorems | 02/21/07
Take a break, people!  NetArch. | 02/19/07
I've been slamming Microsoft for not patching things  georgeou | 02/19/07
I know, I know...  NetArch. | 02/20/07
I get pretty good support from Microsoft and Cisco  georgeou | 02/20/07
Example  puppadave | 02/20/07
........  xxn1927 | 02/20/07
Why Microsoft has Patch Tuesday  Sxooter_z | 02/20/07
Nine Firefox flaws last month ?  mhenriday | 02/20/07
I THINK I UNDERSTAND YOU  BALTHOR | 02/20/07
Mozilla doesn't wait a month  Greenknight_z | 02/21/07
Explain 9 firefox 2 remote code execution exploits get bundled in to one?  georgeou | 02/21/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
    • More from IBM
    • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
    • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
    Click Here