RSA patches major vulnerability

By

RSA has issued an unexpected patch to plug a hole in its web application tool.

A boundary error in the RSA Authentication Agent for Web affects IIS version 5.x.


Security and vulnerability group Secunia has released an advisory suggesting hackers could create a heap-based buffer overflow.

Alongside the RSA vulnerability equally dangerous, executable vulnerabilities has been found in Ethereal, a packet sniffing program. Both vulnerabilities, as well as one within Smail, a minor MTA, are rated critical.

The news come two days after Microsoft released a single patch in its monthly patch cycle. The script injection vulnerability was rated as "important" and affects Windows 98, 2000 and ME users only.

In March SC reported Microsoft released eight security patches, at least half of which were rated critical.

In the same month SC reported Microsoft's major OS update, SP2 for Windows XP, was being rejected by over half of companies.

www.rsa.com
www.microsoft.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

Accenture to buy Australian cyber security firm CyberCX

Accenture to buy Australian cyber security firm CyberCX

TPG Telecom reveals iiNet order management system breached

TPG Telecom reveals iiNet order management system breached

Log In

  |  Forgot your password?