* Patches from Opera, Debian, SuSE, others * Beware bogus financial site login screens * Cisco security plan eyed warily, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Opera browser vulnerability patched
A flaw in Opera’s auto-install function for skin and configuration files could be exploited by a malicious Web site to create arbitrary files in any location on the affected machine. These files could be used for Trojan horses or viruses. Download Opera 7.23 to fix this issue. For more, go to:
https://www.nwfusion.com/go2/1124bug1a.html
Opera download site:
https://www.opera.com/download/
**********
Debian warns of project server compromise
A few of Debian’s servers were compromised late last week. The group is in the process of verifying all content on the affected machines. For more, go to:
https://www.debian.org/News/2003/20031121
Debian GNU/Linux 3.0 updated (r2)
Despite the server compromise of last week, Debian has released a new update (code named “woody”) that contains a number of security-related fixes. For more, go to:
https://www.debian.org/News/2003/20031121a
**********
SuSE patches sane
A potential denial-of-service (DoS) vulnerability has been patched in sane, a driver that allows local or remote access to a scanner. A remote user could exploit this flaw in a DoS attack against the affected machine. For more, go to:
https://www.suse.com/de/security/2003_046_sane.html
**********
SGI releases update #5
SGI has released a new security update (#5) that contains a number of fixes for previously announced vulnerabilities in its IRIX operating system. For more, go to:
https://www.nwfusion.com/go2/1124bug1b.html
**********
Conectiva updates zebra
A DoS vulnerability has been found in zebra, “a multiserver routing software package which provides TCP/IP-based routing protocols also with IPv6 support such as RIP, OSPF and BGP.” For more, go to:
https://www.nwfusion.com/go2/1124bug1c.html
**********
Microsoft investigates possible Exchange 2003 flaw
Microsoft is investigating a potential security issue with Exchange Server 2003, which would be the first since the e-mail server was launched last month. IDG News Service, 11/21/03.
https://www.nwfusion.com/news/2003/1121microinves2.html?nl
**********
Today’s roundup of virus alerts:
W32/Mimail-K – Yet another version of the Mimail work. This one comes in an e-mail entitled “don’t be late!
JS/Flea-B – An e-mail virus that comes as an HTML signature to a message. The JavaScript code tries to access a remote site that is not available. (Sophos)
Banbra.B – A Trojan that displays a fake login page when the infected user visits specific financial institution Web sites in an attempt to steal account information. (Panda Software)
**********
From the interesting reading department:
Cisco’s security plan eyed warily
Cisco says its road map for tying leading anti-virus software to its network hardware promises to eventually transform every WAN, LAN and Wi-Fi port into a security checkpoint. But the technology – not available until the middle of next year – raises questions about management complexity and the issue of locking users into a single-vendor architecture, observers say. Network World, 11/24/03.
https://www.nwfusion.com/news/2003/1124ciscosec.html?nl
Security of handhelds far too lax, experts say
Network executives are starting to realize the scope and seriousness of this potential security problem. Network World, 11/24/03.
https://www.nwfusion.com/news/2003/1124comdex.html?nl
Frameworks coordinate security
Security management frameworks provide a coordinated component set that collects security data from the network, puts it in a common format, stores it in a database and executes a range of analysis, display, response and reporting tasks. Network World, 11/24/03.
https://www.nwfusion.com/news/tech/2003/1124techupdate.html?nl
Gear guards networks against infected laptops
InfoExpress is coming out with packages to protect LANs from infections brought in by laptops that have been used outside a network. Network World, 11/24/03.
https://www.nwfusion.com/news/2003/1124infoexpress.html?nl
Sourcefire releases an IDS helper
Sourcefire last week made available a network appliance that can identify the hosts, servers, wireless access points, routers and other devices on a subnet, plus many of the applications in use, to improve security monitoring. Network World, 11/24/03.
https://www.nwfusion.com/news/2003/1124sourcefire.html?nl
For security ask yourself…what would Microsoft do?
Despite taking a beating in the press and from customers for security holes in its products, decision makers at Microsoft appear to think the company still has something to teach the world about computer security. IDG News Service, 11/21/03.
https://www.nwfusion.com/news/2003/1121forsecur2.html?nl
CA offers free anti-virus, firewall software
Computer Associates Tuesday said it will give away its consumer anti-virus and firewall software product with a year’s subscription to virus signature updates. IDG News Service, 11/20/03.
https://www.nwfusion.com/news/2003/1120comdeca.html?nl
Sybari blocks IM viruses
Addressing the inevitable threat of viruses that piggyback on instant messages, Sybari has announced Antigen 7.5 for IM at Comdex in Las Vegas. PC World, 11/20/03.
https://www.nwfusion.com/net.worker/news/2003/1120comdesyb.html?nl
Check Point CEO elaborates on upcoming products
In an interview with Network World Senior Editor Tim Greene, Check Point’s Chairman and CEO Gil Shwed gave some flavor of what the new products would include. Network World Fusion, 11/21/03.
https://www.nwfusion.com/news/2003/1121shwedqa.html?nl
Related story:
https://www.nwfusion.com/news/2003/1120cpoint.html?nl
Group pushing e-voting security to launch
A group that draws heavily from the ranks of computer scientists and technology policy specialists who are concerned about inattention to IT security issues in voting systems will announce its debut on Friday in Washington, D.C. IDG News Service, 11/20/03.
https://www.nwfusion.com/news/2003/1120grouppushi.html?nl
Please note that there will be no newsletter on Thursday. Happy Thanksgiving!




