* Patches from Veritas, Sun, Debian, others * Beware new Netsky variant * California discloses massive ID theft, and other interesting reading
endif; ?>Editor’s Note: GO RED SOX!
Today’s bug patches and security alerts:
Oracle warns of exploits for latest DB flaws
Oracle is warning customers to apply software patches it released in August, citing the availability of malicious code that can exploit unpatched vulnerabilities in its software. IDG News Service, 10/15/04,
https://www.nwfusion.com/news/2004/1015oraclwarns.html?nl
Original Oracle advisory:
https://www.nwfusion.com/go2/1018bug2a.html
**********
CERT issues advisory on IE
CERT is urging users to apply the cumulative patch for Internet Explorer that Microsoft released last week. Multiple vulnerabilities were found in the browser, the most serious of them could be used to run code on the affected system. For more, go to:
https://www.us-cert.gov/cas/techalerts/TA04-293A.html
Microsoft advisory:
https://www.microsoft.com/technet/security/Bulletin/MS04-038.mspx
**********
Veritas Cluster Server patch available
Veritas has released a patch for its Cluster Server for Unix that fixes an undisclosed vulnerability. The company did say an attacker could exploit the flaw to take control of the affected server. For more, go to:
https://seer.support.veritas.com/docs/271040.htm
**********
Solaris LDAP patch available
Sun has released a patch for Solaris systems that run LDAP with Role Based Access Control (RBAC). An attacker could excute commands on the affected machine with the higher privileges. For more, go to:
https://sunsolve.sun.com/search/document.do?assetkey=1-26-57657-1
**********
New Trustix “multi”
A new update from Trustix fixes problems in libtiff, mysql, squid and cyrus-sasl. For more, go to:
https://www.trustix.org/errata/2004/0054/
**********
Debian, SCO patch libpng
According to the SCO advisory, “Several vulnerabilities exist in the libpng library, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.” For more, go to:
Debian (libpng):
https://www.debian.org/security/2004/dsa-570
Debian (libpng3):
https://www.debian.org/security/2004/dsa-571
SCO UnixWare:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.16
**********
Vendors patch libtiff vulnerability
The libtiff image handling library used by many vendors contains heap and buffer overlfow vulnerabilities. One of the flaws could be exploited to affect memory allocation. For more, go to:
Debian:
https://www.debian.org/security/2004/dsa-567
Gentoo:
https://security.gentoo.org/glsa/glsa-200410-11.xml
Mandrake Linux:
https://www.nwfusion.com/go2/1018bug2b.html
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.043-tiff.txt
**********
Today’s roundup of virus alerts:
W32/Sdbot-QJ – An Sdbot variant that, like previous versions, spreads via network shares with weak or no password protection. It installs itself as “msgfix.exe” in the Windows System directory. It can be used to download files and launch denial-of-service attacks. (Sophos)
W32/Netsky.AG – A new Netsky variant that spreads via e-mail and peer-to-peer networks. It displays a “File corrupted” message when it infects the machine and has an icon that looks like the Brazilian Flag with a slash through it. (Panda Software)
W32/Traxg-B – A low risk worm that spreads via Outlook. It creates the directory “c:folder.htt” and may alter data. (Sophos)
W32/Forbot-BI – This worm installs itself as “systemproc.exe” after spreading via weakly protected network shares. It uses IRC to provide backdoor access and allows the infected machine to be used for a number of malicious purposes. (Sophos)
W32/Forbot-AZ – Another Forbot variant. This one uses the filename “syshelped.exe” as its infection point. (Sophos)
W32/Rbot-NC – A bot that attempts to run as a generic process, allowing backdoor access via IRC. It installs itself as “SCHOST.EXE” in the Windows System folder. It may delete network shares from the infected machine. (Sophos)
W32/Wort-B – A worm that spreads via network shares by exploiting the Windows LSASS vulnerability. It can download “SETTER.EXE” or “SETTROW.EXE” from a remote Web site. It may also report its status back to the remote site. (Sophos)
**********
From the interesting reading department:
California discloses massive ID theft
The state of California has warned residents that their personal data may have been stolen from computers at the University of California, Berkeley, after a database used by researchers there was compromised by hackers. IDG News Service, 10/20/04.
https://www.nwfusion.com/news/2004/1020califdisc.html?nl
Liberty Alliance holdout IBM ends resistance, joins
IBM has become the latest company to join the Liberty Alliance, a global consortium aimed at developing standards for managing user identities. IBM joins Oracle and Intel as a backer of the effort, which Sun leads. IDG News Service, 10/20/04.
https://www.nwfusion.com/news/2004/1020liberty.html?nl
Microsoft scales back Passport ambitions
Microsoft is recasting ambitions for its .Net Passport identification system, saying the service now will be limited to its own online offerings and those of close partners. Microsoft no longer sees Passport as a single sign-on system for the Web at large, a spokeswoman said. IDG News Service, 10/20/04.
https://www.nwfusion.com/news/2004/1020microscale.html?nl
Bradner: Core software as security vulnerabilities
The whole list comes across a little bit like telling someone to stop breathing in order to avoid getting cancer from air pollution – accurate but useless advice. I’ll focus on the Windows part of the list because many more people can relate to Windows vulnerabilities than Unix ones (including, I suppose, Mac OSX). Network World, 10/18/04.
https://www.nwfusion.com/columnists/2004/101804bradner.html?nl
Editorial: Stage set for VoIP, patch debates
All the parties that have been called on to participate in two upcoming Network World Showdowns are in, including six prominent VoIP vendors for a Showdown at the VON conference in Boston this week, and six patch-management players for an online debate Nov. 15. Network World, 10/18/04.




