Feeds

SANS revises Top 20 security vulns list

The SANS of time

  • alert
  • submit to reddit

Next gen security for virtualised datacentres

Bugs in anti-virus scanners and various media players joined flaws in Microsoft and Oracle software products in a list of the 20 most serious vulnerabilities discovered the first quarter of 2005.

The list - compiled by the SANS Institute in co-operation with security vendors such as TippingPoint and Qualys - highlights the 20 most critical vulnerabilities among 600 new Internet security bugs discovered in Q1 2005. Vulnerabilities that are easy to exploit and where a large number of unpatched systems existed were highlighted in the report. "Individuals and organisations that do not correct these problems face a heightened threat that remote, unauthorized hackers will take control of their computers and use them for identity theft, for industrial espionage, or for distributing spam or pornography," the SANS Institute warns.

Various flaws in Internet Explorer and Microsoft Windows subsystems (such as a recent Server Message Block bug) make the top 20 list. These are joined by DNS caching flaws affecting a number of products from Symantec and Microsoft, media player bugs (RealPlayer, iTunes, WinAmp and Windows Media Players) and anti-virus product glitches (buffer overflow bugs in apps from Symantec, F-Secure, Trend Micro and McAfee). Vulnerabilities to Oracle database and application software products fixed with a January patch release also make the SANS Top 20 list.

The flaws are all well-documented. The idea of the Top 20 is to draw people's attention towards particularly serious problems that might have been overlooked. The SANS Institute has moved from an annual to quarterly update of the list starting with its Q1 2005 report. The change reflects the faster evolution of Internet threats, it said. ®

Related stories

DNS cache poisoning bugs hits Symantec shops
Vendors agree vulnerability scoring system
The IT security vuln league table of fear (SANS Top 20, October 2004)

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?