* Patches from Oracle, Cisco, Mandrake Linux, others * Beware e-mail with the subject line: "When It's Cold Outside She Gives Me Warm Inside" * No Christmas patches from Microsoft, and other interesting reading Network World needs your help. We’re looking for the weirdest, most wild, descriptive and/or silly network product name you’ve come across. Got one to share? Fill out this short form and you could win a fabulous Network World prize: http://www.nwfusion.com/survey/favprod2003.htmlNetwork World needs your help. We’re looking for the weirdest, most wild, descriptive and/or silly network product name you’ve come across. Got one to share? Fill out this short form and you could win a fabulous Network World prize:https://www.nwfusion.com/survey/favprod2003.htmlToday’s bug patches and security alerts: Oracle patches SSL server bugsOracle has issued a security alert and software patches for a set of serious vulnerabilities in the security protocols used by some of its server products. IDG News Service, 12/09/03. https://www.nwfusion.com/news/2003/1209oraclpatch.html?nlSGI patches OpenSSL flaw:https://www.nwfusion.com/go2/1208bug2a.html**********Cisco patches ACNS vulnerabilityAccording to an alert from Cisco, “By entering an overly long password, it may be possible to execute arbitrary code on a vulnerable device. This vulnerability affects all devices and hardware modules that are running ACNS software releases prior to 4.2.11 and 5.0.5. The workaround is to disable the CE GUI server.” For more, go to: https://www.nwfusion.com/go2/1208bug2b.htmlCisco warns of Unity vulnerabilities on IBM-based serversDefault installations of Cisco Unity running on IBM servers contain default user accounts and passwords that could be used to compromise the system. Only IBM servers running Unity are affected. For more, go to:https://www.nwfusion.com/go2/1208bug2c.html **********IE glitch gives spoofers powerful toolA newly discovered vulnerability in Microsoft’s Internet Explorer browser could be a powerful new tool for scammers, allowing them to convincingly mask the real origin of Web pages used to trick targets into revealing sensitive information. IDG News Service, 12/10/03.https://www.nwfusion.com/news/2003/1210ieglitc.htmlAn illustration of the problem can be found here:https://www.zapthedingbat.com/security/ex01/vun1.htm**********Yahoo fixes e-mail service security flawYahoo has fixed a flaw in its Web-based e-mail service that exposed Yahoo Mail users to serious attacks, including potential interception of personal data, security company Finjan Software said Wednesday. IDG News Service, 12/10/03.https://www.nwfusion.com/news/2003/1210yahoofix.html?nl**********New gnupg fixes availableA flaw in the way gnupg deals with type 20 ElGamal sign+encrypt keys could allow for an unauthorized user to recover private keys from a signature. For more, go to:Conectiva:https://www.nwfusion.com/go2/1208bug2d.htmlRed Hat:https://rhn.redhat.com/errata/RHSA-2003-390.htmlSuSE:https://www.suse.com/de/security/2003_048_gpg.txt**********SGI releases Advanced Linux Environment security update #6According to an advisory from SGI, “SGI has released Patch 10037: SGI Advanced Linux Environment security update #6, which includes updated RPMs for SGI ProPack v2.3 for the Altix family of systems.” For more, go to:https://www.nwfusion.com/go2/1208bug2e.html**********Mandrake Linux patches cvsA flaw in versions of the cvs server prior to 1.11.10 could be exploited to create directories and files at the root level of the affected machine. For more, go to:https://www.nwfusion.com/go2/1208bug2f.htmlMandrake Linux updates screenA buffer overflow has been found in Mandrake Linux’s Virtual Screen Manager GNU screen. Attackers could gain control of other users’ screens or potentially gain elevated privileges on the affected machine. For more, go to:https://www.nwfusion.com/go2/1208bug2g.htmlMandrake Linux fixes ethereal flawsA number of vulnerabilities in the ethereal network-monitoring tool could be exploited to crash the service or potentially run arbitrary code on the affected machine. For more, go to:https://www.nwfusion.com/go2/1208bug2h.html**********Immunix issues rsync patchA heap overflow vulnerability in the rsync application can be exploited with the recently discovered Linux kernel flaw to compromise Linux servers. Download the fix from:Precompiled binary packages for Immunix 7.3:https://www.nwfusion.com/go2/1208bug2i.htmlPrecompiled binary packages for Immunix 7+:https://www.nwfusion.com/go2/1208bug2j.html**********Today’s roundup of virus alerts:W32/Agobot-BD – A Trojan horse that spreads via shared network resources with weak passwords. The virus attempts to connect to an IRC channel to listen for commands from an attacker. It also disables certain security-related applications. (Sophos)Troj/Zana-A – This virus is a browser application that displays porn on the infected machine. It may also attempt to download a dialer application from a remote site. (Sophos)W32/Scold-A – An e-mail virus that comes with a subject line of “When It’s Cold Outside She Gives Me Warm Inside” and a similarly named attachment with a .scr extension purported to be a photo. The virus spreads to everyone listed in the infected machine’s Outlook address book. (Sophos)Troj/Dloader-F – A Trojan horse that attempts to download code from a remote Web site, which wasn’t available at the time of this writing. (Sophos)**********From the interesting reading department:No Christmas patches from MicrosoftMicrosoft has an early holiday gift for systems administrators: no monthly security patch release in December. IDG News Service, 12/09/03.https://www.nwfusion.com/news/2003/1209microsanta.html?nlIEEE: Chinese security standard could fracture Wi-FiThe implementation of a Chinese security standard for wireless networking could undermine efforts to develop a global standard for wireless LANs and drive up the cost of networking equipment for end users, warned a senior executive at the IEEE in a recent letter to Chinese government officials. IDG News Service, 12/09/03.https://www.nwfusion.com/news/2003/1209ieeechine.html?nlAgony for anti-virus vendor SophosUK anti-virus firm Sophos has signed a deal with The Sun’s agony aunt column ‘Dear Deidre’ to protect its virtual mailbag from viruses. Silicon.com, 12/08/03.https://www.nwfusion.com/go2/1208bug2k.htmlNew patch management mailing listThe PatchManagement.org mailing list is the industry’s first discussion list dedicated to discussing security patch management topics. This list discusses the how-to’s and why’s of security patch management across a broad spectrum of Operating Systems, Applications, and Network Devices. This list is meant as an aid to network and systems administrators and security professionals who are responsible for maintaining the security posture of their hosts and applications.https://www.patchmanagement.org/default.asp Related content feature 5 ways to boost server efficiency Right-sizing workloads, upgrading to newer servers, and managing power consumption can help enterprises reach their data center sustainability goals. By Maria Korolov Dec 04, 2023 9 mins Green IT Green IT Green IT news Omdia: AI boosts server spending but unit sales still plunge A rush to build AI capacity using expensive coprocessors is jacking up the prices of servers, says research firm Omdia. By Andy Patrizio Dec 04, 2023 4 mins CPUs and Processors Generative AI Data Center feature What is Ethernet? History, evolution and roadmap The Ethernet protocol connects LANs, WANs, Internet, cloud, IoT devices, Wi-Fi systems into one seamless global communications network. By John Breeden Dec 04, 2023 11 mins Networking news IBM unveils Heron quantum processor and new modular quantum computer IBM also shared its 10-year quantum computing roadmap, which prioritizes improvements in gate operations and error-correction capabilities. By Michael Cooney Dec 04, 2023 5 mins CPUs and Processors High-Performance Computing Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe