Home > Security News > Security Bytes: Cisco patches CS-MARS flaws
Security News:
EMAIL THIS

Security Bytes: Cisco patches CS-MARS flaws

By SearchSecurity.com Staff
20 Jul 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Cisco patches CS-MARS flaws
Attackers could exploit several security holes in Cisco's Security Monitoring, Analysis and Response System (CS-MARS) to take complete control of an affected system or gain knowledge of sensitive information. A fixed version of the program is now available.

The San Jose, Calif.-based networking giant said in an advisory that version 4.2.1 of CS-MARS -- a security system that receives and analyzes event logs from various network devices and reports any security issues -- fixes the following problems:

  • CS-MARS uses an Oracle database to store sensitive network event and configuration data. The information contained in the database potentially includes authentication credentials for network devices, such as firewalls, routers and IPS devices, and the details of network security events, Cisco said. By default, Oracle databases contain several built-in accounts with well-known passwords and, if access can be gained to the database, the accounts could potentially be used to compromise the information stored in the database.

  • CS-MARS contains an installation of the JBoss Web application server. It may be possible for a remote, unauthenticated user to create a specially-crafted HTTP request that executes arbitrary shell commands on the CS-MARS appliance with the privileges of the CS-MARS administrator via the optional JBoss JMX console. Cisco said.

  • The CS-MARS CLI -- a restricted shell environment that allows authenticated administrators to perform system maintenance tasks -- contains several privilege escalation vulnerabilities that may allow shell commands to be executed on the underlying appliance operating system with root privileges, Cisco said.

    Metasploit creator warns of serious IE flaw
    Metasploit Framework creator H.D. Moore has outlined a serious vulnerability in Microsoft Internet Explorer (IE) as part of his Month of Browser Bugs campaign.

    Moore has been posting at least one new browser flaw a day in his Browser Fun blog as part of the effort, which he has said will continue through the month of July. One of the latest postings for IE caught the attention of the French Security Incident Response Team (FrSIRT), which labeled the flaw critical in an advisory.

    Remote attackers could exploit the flaw to crash a vulnerable browser or potentially take complete control of an affected system, FrSIRT warned. "This flaw is due to an integer overflow error in the Common Controls library 'comctl32.dll' when processing a 'WebViewFolderIcon' object with a specially crafted 'setSlice()' method, which could be exploited by attackers to cause a denial of service or execute arbitrary commands by convincing a user to visit a specially crafted Web page," FrSIRT said.

    Cisco may get more unwanted attention at Black Hat
    Last year's Black Hat Briefings conference in Las Vegas was dominated by the controversy caused by researcher Michael Lynn's demonstration of a Cisco router exploit. Lynn isn't scheduled as a presenter at this year's Black Hat proceedings, which take place Aug. 2 and 3, but Cisco's products may be under the microscope again.

    Fifteen new exploits will be detailed at this year's conference and two of them target NAC (Network Admission Control) and VoIP vulnerabilities in products from Cisco and other vendors. Black Hat Director Jeff Moss told the IDG News Service that vulnerability researchers are shifting focus from Windows flaws to other areas like NAC and VoIP.

    Black Hat and Cisco settled a lawsuit over the Lynn affair after conference organizers promised not to proliferate Lynn's findings. The IDG News Service noted that a Cisco lawsuit regarding any potential disclosures at the upcoming conference is unlikely because the exploits are related to underlying technologies used in many products, not just those produced by Cisco.

    Tags: Security Event ManagementDatabase Security ManagementWeb Browser SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Event Management
    Network traffic collection, analysis helps prevent data breaches
    Best Security Information and Event Management Products
    Understanding PCI DSS compliance requirements for log management
    Data breach notification legislation: What info must be released?
    How to prevent a denial-of-service (DoS) attack
    Mature SIMs do more than log aggregation and correlation
    The top 5 network security practices
    SIMs tools and tactics for business intelligence
    SIEM: Not for small business, nor the faint of heart
    Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?

    Database Security Management
    What is the best database patch management process?
    Unpatched vulnerability discovered in Microsoft SQL Server
    SQL injection continues to trouble firms, lead to breaches
    Oracle issues quarterly patches, fixes database flaws
    Database monitoring, encryption vital in tight economy, Forrester says
    Oracle to buy Sun Microsystems for $7.4 billion
    Oracle issues 43 updates, fixes serious database flaws
    Imperva assigns security risk levels to databases
    How to create configuration management plans to install DLP
    Information security book excerpts and reviews
    Database Security Management Research

    Web Browser Security
    Microsoft fixes security update that breaks Internet Explorer
    Mozilla update repairs Firefox buffer overflow vulnerabilities
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Do Facebook URL security concerns justify blocking social networks?
    Phishing attacks to remain a major problem, say security experts
    Adrian Perrig: Improve SSL/TLS Security Through Education and Technology
    New Bahama botnet evades search engines, fuels click fraud
    SANS: Application threats, website flaws pose biggest security threats
    Mozilla helps Adobe push out faster patches
    Web Browser Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    security information management (SIM)  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts