OpenBSD patches IPv6 flaw

Opinion
Mar 19, 20072 mins

* Patches from rPath, Mandriva, Gentoo, others * RSA to offer Trojan take-down service * Microsoft concedes: OneCare AV software 'not stellar', and other interesting reading

Today’s bug patches and security alerts:

Core Security discovers IPv6-related flaw in OpenBSD

Core Security Technologies says it’s discovered an IPv6-related buffer-overflow vulnerability in several versions of the OpenBSD operating system that would allow an attacker to knock a server offline or take control at the kernel level. The OpenBSD project, the group which makes the free operating system available, has issued a software patch to plug the hole. Network World, 03/15/07.

OpenBSD advisory can be found here

***********

Two new updates from rPath

gnupg (message forgery)

libwpd (code execution)

***********

Three new fixes from Debian:

libwpd (code execution)

webcalendar (remote file inclusion)

gnupg (message forgery)

***********

Two new patches from Mandriva:

openoffice.org (multiple heap overflows)

libwpd (code execution)

***********

Four new updates from Gentoo:

Apache JK Tomcat Connector (buffer overflow, code execution)

PostgreSQL (multiple flaws)

Asterisk (denial of service)

SSH Secure Shell Server SFTP (privilege escalation)

***********

Virus and malware news of the day:

RSA to offer Trojan take-down service

EMC’s RSA division plans to launch a new service next month that will help financial institutions take down Web sites associated with malicious Trojan horse software. IDG News Service, 03/15/07.

***********

From the interesting reading department:

Microsoft concedes: OneCare AV software ‘not stellar’

Microsoft Thursday acknowledged poor test results of its OneCare antivirus software, but promised it would do better by paying more attention to malware actually in the wild. Computerworld, 03/16/07.

Hackers promise month of MySpace bugs

They won’t divulge their real names, they call their project a “whiny, attention-seeking ploy,” and they appear to take their fashion cues from Beastie Boys music videos. IDG News Service, 03/16/07.

Firefox takes new tack on testing bug fixes

Mozilla is changing the way it publishes security fixes for its Firefox browser. Over the next day, the open-source company plans to begin delivering bug fixes to a select group of beta testers who will try out the upcoming Firefox 2.0.0.3 version before it is released to all Firefox users. IDG News Service, 03/16/07.

Intel cracks down harder on desktop security with Weybridge

Intel is readying the second version of its chip-based vPro security technology for the desktop. The initial version debuted in September amid support from partners Symantec, Altiris and others. Network World, 03/16/07.

Sophos details NAC security plans

By this time next year, Sophos says it will have its desktop security software fully integrated with the network access control technology it acquired when it bought Endforce in January. NetworkWorld.com, 03/16/07.