Feeds

Cisco breaks cycle with IOS patch

Preemptive defence against rootkit exploits?

Intelligent flash storage arrays

Cisco released a trio of updates on Wednesday. The advisories cover denial of service vulnerabilities in IOS Secure Shell and its Secure Control Engine software. The escalation update involves Cisco's voice engine portal software.

The network giant states that it discovered all three vulnerabilities itself but the timing of the releases, on the day before Sebastian Muniz of CORE Security demoed proof of concept router rootkit software, may be more than simply coincidental. As researchers at the SANS Institute's Internet Storm Centre note, the IOS Secure Shell bug allows "spurious memory access".

"Anytime we see a 'spurious memory access' leading to a denial of service, thoughts immediately go to arbitrary code execution. There is no evidence that this is possible, but in light of the recent work in IOS rootkits, vulns in Cisco devices should not be taken lightly," writes ISC staffer George Bakos.

Cisco launched a twice-yearly patching cycle for IOS vulnerabilities back in March. The IOS Secure Shell falls outside this cycle, providing further fuel for conspiracy theorists.

Cisco's advisories can be found here, here and here. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
The cloud that goes puff: Seagate Central home NAS woes
4TB of home storage is great, until you wake up to a dead device
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
Intel offers ingenious piece of 10TB 3D NAND chippery
The race for next generation flash capacity now on
Want to STUFF Facebook with blatant ADVERTISING? Fine! But you must PAY
Pony up or push off, Zuck tells social marketeers
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
SAVE ME, NASA system builder, from my DEAD WORKSTATION
Anal-retentive hardware nerd in paws-on workstation crisis
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.