* Patches from Red Hat, OpenPKG, others * Beware Sober-B e-mail worm * Win 98's demise leaves questions on security, and other interesting reading This is the last newsletter of 2003. We’ll be taking the next two weeks off to celebrate the holidays with our family and friends. Hope you all have a great holiday season and prosperous 2004!Today’s bug patches and security alerts:Cisco warns of holes in PIX firewallsNetwork equipment maker Cisco is warning customers about security holes in its PIX firewall product and firewall software that runs on the Catalyst 6500 Series and 7600 Series switches. IDG News Service, 12/16/03. https://www.nwfusion.com/news/2003/1216ciscowarns.html?nlCisco advisory: https://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtmlRelated Cisco FWSM vulnerabilities advisory:https://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml**********Opera vulnerability patchedA flaw in Opera’s download dialog box could be exploited by a remote user to delete arbitrary files on the affected machine. For more, go to: https://www.securitytracker.com/alerts/2003/Dec/1008460.html**********Linux vendors patch lftpA buffer overflow vulnerability has been found in the lftp FTP client. The flaw could be exploited when the “ls” or “rels” command is executed on a “specially prepared directory.” An attacker could use this to run arbitrary code on the affected client. For more, go to: Mandrake Linux:https://www.nwfusion.com/go2/1215bug2a.htmlOpenPKG:https://www.openpkg.org/security/OpenPKG-SA-2003.053-lftp.htmlRed Hat:https://rhn.redhat.com/errata/RHSA-2003-403.htmlSlackware:https://www.nwfusion.com/go2/1215bug2b.htmlSuSE:https://www.suse.com/de/security/2003_051_lftp.html**********Red Hat issues two Apache-related advisoriesA couple of vulnerabilities have been found in Red Hat’s implementation of the open source Apache Web server application. Fixes are available:Updated httpd packages fix Apache security vulnerabilities:https://rhn.redhat.com/errata/RHSA-2003-320.htmlUpdated apache packages fix minor security vulnerability:https://rhn.redhat.com/errata/RHSA-2003-405.html**********OpenPKG patches cvsA flaw in versions of the cvs server prior to 1.11.10 could be exploited to create directories and files at the root level of the affected machine. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2003.052-cvs.html**********NetBSD issues BIND DNS patchA programming error in the BIND 8 DNS server could “result in a DNS message being incorrectly cached as a negative response.” This could lead to a denial of service against legitimate domain names. For more, go to:https://www.nwfusion.com/go2/1215bug2c.html**********Today’s roundup of virus alerts:W32/Sober-B – This worm spreads via e-mail, peer-to-peer networks and network shares. The virus seeks out e-mail address in a number of file types and overwrites files shared folders of popular peer-to-peer applications with copies of itself. The infected message could be written in German or English. (Sophos)**********From the interesting reading department:Win 98’s demise leaves questions on securityDays after software giant Microsoft announced it would stop distributing the Windows 98 operating system, and weeks ahead of the scheduled end of support, industry experts warn that the operating system, though long in the tooth, is still widely used within organizations. IDG News Service, 12/16/03.https://www.nwfusion.com/news/2003/1216win98.htmlCheck Point buys Zone to bolster endpoint securityCheck Point Software is to buy Zone Labs, which makes software that can tell whether a remote machine meets security policies before allowing it to access a corporate VPN. The $205 million cash-and-stock deal is expected to close in the spring. IDG News Service, 12/15/03.https://www.nwfusion.com/go2/1215bug2d.html Related content how-to Doing tricks on the Linux command line Linux tricks can make even the more complicated Linux commands easier, more fun and more rewarding. By Sandra Henry-Stocker Dec 08, 2023 5 mins Linux news TSMC bets on AI chips for revival of growth in semiconductor demand Executives at the chip manufacturer are still optimistic about the revenue potential of AI, as Nvidia and its partners say new GPUs have a lead time of up to 52 weeks. By Sam Reynolds Dec 08, 2023 3 mins CPUs and Processors Technology Industry news End of road for VMware’s end-user computing and security units: Broadcom Broadcom is refocusing VMWare on creating private and hybrid cloud environments for large enterprises and divesting its non-core assets. By Sam Reynolds Dec 08, 2023 3 mins Mergers and Acquisitions news analysis IBM cloud service aims to deliver secure, multicloud connectivity IBM Hybrid Cloud Mesh is a multicloud networking service that includes IT discovery, security, monitoring and traffic-engineering capabilities. By Michael Cooney Dec 07, 2023 3 mins Network Security Network Security Network Security Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe