Version: 2008

July 15, 2005 10:00 AM PDT

This week in software flaws

  • Post a comment
It wasn't a pretty week in software security.

Hackers are actively exploiting two serious security vulnerabilities in Windows, Microsoft warned as it released "critical" alerts about the flaws. One of the problems affects the Microsoft Color Management Module, a component of Windows that handles colors. The other relates to the JView Profiler, part of Microsoft's Java Virtual Machine.

The vulnerabilities could be used to commandeer a PC. An intruder could take advantage of the JView Profiler flaw by crafting a malicious Web page and persuading a user to visit the site. As for the Color Management Module vulnerability, people could fall victim to an attack by viewing a malicious image.

Meanwhile, two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned. The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult." Several software makers have already released updates to their products to address the problem.

Several vulnerabilities were identified in Cisco Systems' products this week that could lead to denial-of-service attacks. The most noteworthy flaw was reported Tuesday when Cisco warned that hackers could cripple its IP telephony networks by exploiting flaws in its CallManager software, an essential component of Cisco's IP telephony technology, which is used for call signaling and call routing.

By exploiting the discovered vulnerabilities, an attacker can trigger an overflow in memory within a critical CallManager process. This can result in a denial-of-service condition, which will cause the CallManager server to shut down and reboot. Cisco has issued a patch for the vulnerability.

See more CNET content tagged:
Cisco Systems Inc., flaw, Kerberos, IP telephony, vulnerability

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (0.00%) 0.00 23.94
Microsoft (0.00%) 0.00 30.48
Dow Jones Industrials (0.00%) 0.00 10,428.05
S&P 500 (0.00%) 0.00 1,115.10
NASDAQ (0.00%) 0.00 2,269.15
CNET TECH (0.00%) 0.00 1,646.41
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right