Flaw in Symantec NetBackup

Opinion
Dec 18, 20062 mins

* Patches from Symantec, Ubuntu, Mandriva, others * Today's big virus and malware new * The ISECOM Top 10 Real Computer Crimes for 2007 and Beyond

Today’s bug patches and security alerts:

Symantec NetBackup users urged to update software

Users of Symantec Veritas NetBackup software are being advised to immediately update their systems with newly-created patches that repair several serious security vulnerabilities that could allow remote intruders to gain access to affected systems and execute arbitrary code. Computerworld, 12/14/06.

Symantec advisory

**********

Two new patches from Ubuntu:

gdm (format string, code execution)

avahi (regression error)

**********

Four new updates from Mandriva:

Mozilla Thunderbird (multiple flaws)

Evince (buffer overflow, code execution)

ClamAV (multiple flaws)

gdm (format string, code execution)

**********

Three new fixes from Gentoo:

Gnu Radius (format string, code execution)

Links (arbitrary command execution)

McAfee VirusScan (remote code execution)

**********

Today’s big virus and malware news:

‘Big Yellow’ malware exploits Symantec desktop products

Endpoint security firm eEye Digital Security says it has discovered malware that exploits Symantec desktop security products by spreading through an unpatched vulnerability in Symantec’s antivirus software. The malware, called “Big Yellow” due to the distinct color of Symantec’s brand, is a combined worm and botnet that is controlled through Internet Relay Chat channels, according to Marc Maiffret, eEye’s founder and CTO. The worm/botnet malware appears to have originated in China, Maiffret says. Network World, 12/15/06.

eEye advisory

**********

From the interesting reading department:

The ISECOM Top 10 Real Computer Crimes for 2007 and Beyond

A tongue-in-cheek predictions list for 2007, including #1: Your computer will probably crash a lot or at least reboot for no apparent reason but most likely due to some patch you got through an automated update which you are told to do for security reasons because apparently security and stability are incompatible.