Please wait while the page is being loaded Skip this advertisement >
Saturday | 30 August, 2008
ARN
Ahead of rootkit talk, Cisco patches router flaw
Cisco has issued patches for several products including the SSH server software used by its routers
Robert McMillan (IDG News Service) 23 May, 2008 10:38:26

Related Stories
  • +

    Cisco IDs flaw in its Catalyst switches, 7600 Series routers 21 December, 2007 08:56:28

    Fixes and workarounds have been released
    Cisco is warning that a flaw in its Firewall Services Module could result in a reload of the module, or if exploited repeatedly, could result in a sustained denial-of-service attack.
  • +

    Cisco warns of Unified Communications Manager flaw 18 January, 2008 07:24:18

    Cisco has made available a free software fix for affected customers
    Cisco Wednesday released its first new security alert of the year: a warning that its Cisco Unified Communications Manager - formerly CallManager - contains a heap overflow vulnerability in the Certificate Trust List that could allow a hacker to cause a denial-of-service attack or execute arbitrary code.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

Cisco has issued three security patches, fixing bugs that could crash its products and drawing a warning from the SANS Internet Storm Center.

The updates, issued Wednesday, fix denial of service bugs in the SSH (Secure Shell) software in Cisco's Internetwork Operating System (IOS), used to power its routers, and in the Cisco Service Control Engine, which is provides carrier-grade networking services.

Cisco has also patched a privilege escalation vulnerability in its Voice Portal automated telephone customer service software.

In its security advisories Cisco said that all of the bugs had been discovered by its own researchers, but SANS warned that researchers are likely reverse-engineering the patches and may release exploit code publicly.

These particular updates are getting extra attention from the security community, which is now closely investigating how malicious software might work on IOS, an operating system that has largely evaded serious scrutiny. On Thursday, for example, Core Security's Sebastian Muniz is slated to give a widely anticipated presentation on a Cisco rootkit he calls the DIK (Da Ios rootKit) at the EuSecWestconference in London.

Cisco recently changed its software update policy, saying it will now only issue IOS patches in March and September each year, unless forced to rush out a fix for serious bugs that were publicly disclosed or which were being actively exploited. On Wednesday, a Cisco spokesman couldn't immediately say whether his company considered the IOS patch, which fixes a flaw in the SSH server, an out-of-cycle update.

But Core Security Chief Technology Officer Ivan Arce said that Cisco's SSH bug-fix was not connected to his company's rootkit presentation. "It is more likely that this is related to an ongoing distributed SSH brute forcing attack that a few people reported in the incidents mailing list last week," he said in an e-mail interview.

The SSH server is used by administers to remotely log into a router using encryption. Bugs in the software could let an attacker repeatedly reload the device or access "spurious" parts of the router's memory and could be used to disable the hardware in a Denial of Service (DoS) attack, Cisco said in its advisory.

"While the 'Exploitation and Public Announcements' portion of all three advisories states that the vulns were discovered in-house, it's a pretty safe bet that a fair number of security researchers are feverishly reverse engineering the updates to develop exploits," wrote SANS Internet Storm Center contributor George Bakos in a blog posting.

"Anytime we see a 'spurious memory access' leading to a denial of service, thoughts immediately go to arbitrary code execution. There is no evidence that this is possible, but in light of the recent work in IOS rootkits, vulns in Cisco devices should not be taken lightly," he wrote.

Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
  • IFA: LG's newest TV includes Bluetooth

    Bluetooth will be installed in models in LG's PG7000-series plasma sets and LG7000-series LCD sets, which are due on sale across Europe before the end of September.

Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Microsoft® takes legal action against software pirates

Recently Microsoft took legal action against individuals and resellers for distributing and selling unauthorised Microsoft software.

Sponsored Links