* Patches from Apple, Debian, Trustix, others * Beware latest Lovegate variants * Feds eyeing one access model for all, and other interesting reading Today’s bug patches and security alerts:CERT warns of Mozilla problemsLooks like that problem with Mozilla was more serious than we thought. CERT has issued a warning to users: “Several vulnerabilities exist in the Mozilla web browser and derived products, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.” Internet Explorer isn’t the only browser with problems.https://www.us-cert.gov/cas/techalerts/TA04-261A.html **********Apple patches iChat A flaw in iChat could allow an attacker to send a link that, when clicked, could launch local application on the affected machine. For more, go to:https://docs.info.apple.com/article.html?artnum=61798(scroll down to “Security Update 2004-09-16”)**********Debian, Mandrake Linux patch gdk-pixbufA flaw in one of the gdk-pixbuf code libraries could be exploited by a remote user to run any code on the affected machine. For more, go to: Debian:https://www.debian.org/security/2004/dsa-549Mandrake Linux:https://www.nwfusion.com/go2/0920bug1a.html **********Trustix releases two “service packs”Two new updates available from Trustix fix flaws in a number of applications. The first patches fix issues in kernel, samba and swup. The second fixes problems in apache, cups, foomatic-filters, iptables and squid. For more, go to:Patch set #1:https://www.trustix.org/errata/2004/0046/Patch set #2:https://www.trustix.org/errata/2004/0047/**********FreeBSD patches CVSA number of flaws in the FreeBSD implementation of the CVS version control system have been patched. The most serious of the vulnerabilities could be exploited by an attacker to run their code on the affected machine. For more, go to:https://www.nwfusion.com/go2/0920bug1b.html**********OpenPKG releases SpamAssassin fixA denial-of-service vulnerability has been found in SpamAssassin for OpenPKG. An attacker could send a malformed message through the system, causing it to crash. For more, go to:https://www.nwfusion.com/go2/0920bug1c.htmlOpenPKG patches aspellA buffer overflow in the aspell spell check’s word-list-compression utility could be exploited to run malicious code on the affected machine. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2004.042-aspell.html**********Today’s roundup of virus alerts:W32/Forbot-V – This Forbot variant installs itself as “wuaucls.exe” and allows backdoor access via IRC. The virus can act as a proxy server, spam relay and more. (Sophos)W32/Forbot-W – A simpler Forbot variant that installs itself as “WINXPINIT.EXE” in the Windows System folder and allows backdoor access via IRC. No word on any other applications it may handle. (Sophos)W32/Forbot-C – Another Forbot variant. This one uses the file “winitr32.exe” and can disable security-related applications running on the infected machine. (Sophos)W32/Myfip-A – A worm that seems to collect file names from an infected system and mail the results to the virus author. The virus spreads via network shares and installs itself as “worm.txt.exe” or “dfsvc.exe” in the Windows System directory. (Sophos)W32/Sdbot-PG – This Sdbot variant exploits the DCOM flaw in Windows as it tries to spread via network shares. It installs itself as “CASD.EXE” in th Windows System folder and can be used in denial-of-service attacks against third parties. (Sophos)W32/Lovgate-X – This Lovegate variant spreads via e-mail (with random message attributes) and peer-to-peer networks. It starts a service called “NetMeeting Remote Sharing” on the infected machine and tries to terminate certain applications. (Sophos)W32/Rbot-JR – One of those “fun” Rbot variants that can capture images from a Webcam attached to the infected machine. The virus spreads via networks shares, installing itself in the Windows System folder as “lshost.exe”. It provides backdoor access via IRC and terminates security-related applications. (Sophos)**********From the interesting reading department:Feds eyeing one access model for allA mandate from President Bush has required the entire federal government to adopt common technology to be used to identify employees and contractors accessing federally controlled networks and buildings. Network World, 09/20/04.https://www.nwfusion.com/news/2004/092004fedsmart.html?nlReview: Endpoint security products aid in client defenseWe test enterprise endpoint security products from nine vendors: eEye Digital Security, Finjan Software, F-Secure. InfoExpress, SecureWave, Sygate Technologies, Symantec, WholeSecurity and Zone Labs. Network World, 09/20/04.https://www.nwfusion.com/reviews/2004/0920rev.html?nlManagement Strategies: Security certification staplesDigest what some of the most popular IT credentials bring to the table. Network World, 09/20/04.https://www.nwfusion.com/careers/2004/0920man.html?nlNetilla SSL device guards one application at a timeNetilla is introducing a line of Secure Sockets Layer gear that protects only one application at a time as remote users access servers across the Internet. Network World Fusion, 09/16/04.https://www.nwfusion.com/news/2004/0916netilla.html?nlSymantec to acquire security consultants @StakeSymantec has agreed to acquire @Stake, a Cambridge, Mass.-based provider of IT security consulting services. IDG News Service, 09/16/04.https://www.nwfusion.com/news/2004/0916symantoac.html?nlIBM fits PCs with new hardware-based security chipIBM has begun using new security hardware from National Semiconductor in its desktop PCs in an effort to fend off viruses and hackers. IDG News Service, 09/16/04.https://www.nwfusion.com/news/2004/0916ibmfits.html?nl Related content news Nvidia races to fulfill AI demand with its first Vietnam semiconductor hub Vietnam has been a growing tech manufacturing destination for the past few years, and Nvidia said it is open to a new manufacturing partner in Vietnam. By Sam Reynolds Dec 11, 2023 3 mins CPUs and Processors Technology Industry how-to Doing tricks on the Linux command line Linux tricks can make even the more complicated Linux commands easier, more fun and more rewarding. By Sandra Henry-Stocker Dec 08, 2023 5 mins Linux news TSMC bets on AI chips for revival of growth in semiconductor demand Executives at the chip manufacturer are still optimistic about the revenue potential of AI, as Nvidia and its partners say new GPUs have a lead time of up to 52 weeks. By Sam Reynolds Dec 08, 2023 3 mins CPUs and Processors Technology Industry news End of road for VMware’s end-user computing and security units: Broadcom Broadcom is refocusing VMWare on creating private and hybrid cloud environments for large enterprises and divesting its non-core assets. By Sam Reynolds Dec 08, 2023 3 mins Mergers and Acquisitions Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe