Debian, Gentoo Linux patches

Opinion
Mar 15, 20043 mins

* Patches from Debian, Gentoo, others * Beware Trojan LDPinch-G, H * NetScreen update expands reach of intrusion detection, and other interesting reading

Today’s bug patches and security alerts:

Debian patches samba

A flaw in Debian’s samba implementation, a LanManager-like package for Unix, could be exploited to run arbitrary code on the affected machine with root privileges. Attackers could also gain root privileges. For more, go to:

https://www.debian.org/security/2004/dsa-463

Debian issues fix for calife

A buffer overflow in the calife, a program that grants super user privileges, getpass function could be exploited by a local user to run arbitrary code with root privileges. For more, go to:

https://www.debian.org/security/2004/dsa-461

**********

Gentoo patches kernel do_mremap

A flaw in the Gentoo Linux kernel’s memory management system could be exploited by a local user to gain elevated privileges. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=145828

Gentoo issues fix for Libxml2

A flaw in the way libxml2 parses remote data retrieved using FTP or HTTP could be exploited to cause a buffer overflow. This in turn could be used to run arbitrary code on the affected machine. For more, go to:

https://forums.gentoo.org/viewtopic.php?t=145827

**********

SGI releases Advanced Linux Environment security update #14

A new update is available for SGI’s Advanced Linux Environment fixes a vulnerability is the sysstat application used in ProPack v2.3 and SGI ProPack v2.4 for the SGI Altix family of systems. For more, go to:

https://www.nwfusion.com/go2/0315bug1a.html

**********

OpenPKG patches uudeview

OpenPKG has released a patch for uudeview, which fixes problems with insecure temporary file handling and a buffer overflow. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.txt

**********

Today’s roundup of virus alerts:

Troj/LDPinch-G, H – A backdoor application that attempts to collect system information and sends it to a remote location. The Trojan runs in the background and can provide access to the infected machine via port 2050. (Sophos)

**********

From the interesting reading department:

Microsoft readies pitch on patches

Microsoft customers this week are hoping to finally evaluate the company’s new patch management tools and hear more about the wide-ranging systems management platform in which those tools will be a key component. Network World, 03/15/04.

https://www.nwfusion.com/news/2004/0315msmgmt.html?nl

Fix the patch update system

As the major operating system vendors, we throw our Tester’s Challenge gauntlet at the feet of Apple, Microsoft, Novell and Red Hat. We challenge you to create an effective, simplified means by which we can get our hands on pertinent patch information pertaining to your products. Network World, 03/15/04.

https://www.nwfusion.com/go2/0315bug1b.html

Craftier Web threats hit finance firms

The last six months of 2003 saw a fivefold increase in worms and other types of malicious code that attempt to steal personal data from Internet users, according to Symantec’s semiannual Internet Security Threat Report. Network World, 03/15/04.

https://www.nwfusion.com/news/2004/0315symantec.html?nl

Review: Newbury Networks’ WiFi Watchdog

An invisible fence to keep attack dogs away from your WLAN. Network World, 03/15/04.

https://www.nwfusion.com/go2/0315bug1c.html

Encryption restrictions

Regulations regarding the import and export of encryption products affect buying decisions worldwide. Network World, 03/15/04.

https://www.nwfusion.com/careers/2004/0315man.html?nl

NetScreen update expands reach of intrusion detection

NetScreen Technologies is upgrading its intrusion-detection software so it also gathers and parses data about network traffic to reduce false intrusion alarms and pin down sources of network attacks. Network World, 03/15/04.

https://www.nwfusion.com/news/2004/0315netscreen.html?nl

Cisco raises its security profile

Cisco last week announced enhancements to a number of its software products and hardware designed to make corporate networks more resilient to attacks. Network World, 03/15/04.

https://www.nwfusion.com/news/2004/0315csiso.html?nl