* Patches from Debian, Slackware, Gentoo, others * Beware NetSky worm variant * Microsoft offers security update CDs, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
New Linux kernel updates
A driver in the kernel used by many Linux implementations has a flaw that could be exploited to by a local user to gain root privileges on the affected machine. For more, go to:
Debian patches:
Kernel 2.4.18 (alpha, i386, powerpc):
https://www.debian.org/security/2004/dsa-438
Kernel 2.4.16 (arm):
https://www.debian.org/security/2004/dsa-439
Kernel 2.4.17 (powerpc, apus):
https://www.debian.org/security/2004/dsa-440
Kernel 2.4.17 (mips, mipsel):
https://www.debian.org/security/2004/dsa-441
Kernel 2.4.17 (s390):
https://www.debian.org/security/2004/dsa-442
Gentoo (AMD 64):
https://forums.gentoo.org/viewtopic.php?t=137979
Red Hat:
https://rhn.redhat.com/errata/RHSA-2004-065.html
Trustix:
https://www.nwfusion.com/go2/0216bug2a.html
Slackware:
https://www.nwfusion.com/go2/0216bug2b.html
**********
Slackware patches Metamail
Four vulnerabilities have been found in Metamail for Slackware. These flaws could be exploited to run arbitrary code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0216bug2c.html
**********
iDefense warns of flaw in Ipswitch IMAIL Server
A buffer overflow in the LDAP daemon used by the Ipswitch IMAIL Server could be exploited to run arbitrary code on the affected machine with administrator privileges. For more, go to:
https://www.idefense.com/application/poi/display?id=74
**********
Gentoo releases patch for Clamav
A vulnerability in Clamav, an anti-virus application used with SMPT systems, could be exploited in a denial-of-service attack against the affected machine. For more, go to:
https://forums.gentoo.org/viewtopic.php?t=138395
Gentoo warns of flaw in phpMyAdmin
Improper authentication verification in phpMyAdmin for Gentoo could be exploited in a director traversal attack. For more, go to:
https://forums.gentoo.org/viewtopic.php?t=137978
Gentoo patche DoS flaw in Monkeyd
The Monkey Daemon (monkeyd), an HTTP server, contains a flaw in its get_real_string() function that could be exploited in a denial-of-service attack against the server. For more, go to:
https://forums.gentoo.org/viewtopic.php?t=135483
Gentoo issues patch for Gallery
A flaw in the way certain global variables are handled by Gallery, a PHP-based image handling application, could be exploited to gain remote access to the Web server. For more, go to:
https://forums.gentoo.org/viewtopic.php?t=135484
**********
Today’s roundup of virus alerts:
Experts warn of NetSky worm variant
Anti-virus software companies are warning that a new version of the NetSky e-mail worm is circulating on the Internet, only a day after the appearance of a new variant of the Beagle or “Bagle” worm prompted similar warnings. IDG News Service, 02/18/04.
https://www.nwfusion.com/news/2004/0218netsky.html?nl
Troj/DDosSmal-B – A Trojan horse that is used to launch denial-of-service attacks against specific Web sites. (Sophos)
W32/Tanx-A – An e-mail worm that is scheduled to stop spreading on February 25th. The worm harvests e-mail address from its infected target. Backdoor functionality in the worm may be used to upgrade its “features”. (Sophos)
**********
From the interesting reading department:
Hackers take advantage of Microsoft ASN flaw
Hackers have already found a way to take advantage of a critical security hole disclosed by Microsoft last week. IDG News Service, 02/17/04.
https://www.nwfusion.com/news/2004/0217hackers.html?nl
Microsoft offers security update CDs
Microsoft has started taking orders for the Windows Security Update CD, a disc with all critical updates released through October 2003 for various Windows versions. IDG News Service, 02/19/04.
https://www.nwfusion.com/news/2004/0219microoffer.html?nl
Snyder: Time to wise up about worms
I’m tired of having an in-box filled with worms. In the last 26 days, infected PCs have sent me 3,787 copies of MyDoom. I know I’m supposed to be an understanding, gentle kind of advice giver, but frankly, I’m sick of it. I’m sick of having my time wasted, and I’m sick of having to help people clean up messes because they can’t control their own mice. Network World, 02/16/04.
https://www.nwfusion.com/columnists/2004/0216snyder.html?nl
Nutter’s Help Desk: Passwords vs. biometric login
Management just funded an IS audit of the company. One of the things it picked apart was our password policy (or lack of one). With some of the projects we work with, auditors suggested we look to implement biometric login devices that would replace the use of a user-entered password. What should we look to do? Network World, 02/16/04.




