* Patches from Gentoo, Connectiva, Slackware, others * Beware Lovegate variant * Gartner: Phishing attacks up against U.S. consumers, and other interesting reading Today’s bug patches and security alerts:FreeBSD patches heimdal and kadmindAccording to an alert from FreeBSD, “A remote attacker may send a specially formatted message to k5admind, causing it to crash or possibly resulting in arbitrary code execution.” For more, go to:heimdal: https://www.nwfusion.com/go2/0510bug1a.htmlkadmind: https://www.nwfusion.com/go2/0510bug1b.html**********ASP cookied vulnerabilityA flaw in the way ASP server pages handle certain cookie requests could expose sensitive server information, according to a post on the BugTraq mailing list. Users should build a custom error page to help protect against server information leaks. For more, go to:https://support.microsoft.com/?id=834452********** Gentoo patches flaws in LCDprocThere are two buffer overflow and one format string vulnerability in Gentoo’s LCDproc package. A fix is available. For more, go to:https://forums.gentoo.org/viewtopic.php?t=166300Gentoo patches Samba A flaw in Samba could be exploited by a remote user to gain root privileges on the affected machine. For more, go to:https://forums.gentoo.org/viewtopic.php?t=168290**********Gentoo, Slackware issue patches for xineA temporary file vulnerability has been found in xine, which could be exploited by a local user to overwrite arbitrary files. For more, go to:Gentoo:https://forums.gentoo.org/viewtopic.php?t=166301Slackware:https://www.nwfusion.com/go2/0510bug1c.html**********Gentoo, OpenPKG release patches for ssmtpThe ssmtp mail transfer agent contains a format string vulnerability, which could be exploited by an attacker to run arbitrary code on the affected machine. For more, go to:Gentoo:https://forums.gentoo.org/viewtopic.php?t=166298OpenPKG:https://www.openpkg.org/security/OpenPKG-SA-2004.020-ssmtp.html**********Connectiva, Slackware patch lhaA buffer overflow and directory transversal vulnerability in lha could be exploited to run arbitrary code on the affected machine. Fixes are available. For more, go to:Conectiva:https://www.nwfusion.com/go2/0510bug1d.htmlSlackware:https://www.nwfusion.com/go2/0510bug1e.html**********Debian releases patch for eximTwo stack-based buffer overflows have been found in Debian’s Exim package. Fortunately, the flaws cannot be exploited in the default Debian configuration. For more, go to:https://www.debian.org/security/2004/dsa-501**********SCO releases update for ApacheA new update for SCO’s Apache implementation fixes two vulnerabilities in the popular Web server software. One flaw fixes a weak encryption cipher. The other fixes a buffer overflow that could be exploited in a denial-of-service attack. For more, go to:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6**********OpenPKG patches kolabIt’s been found that OpenPKG’s kolab stores OpenLDAP passwords in plaintext. Download the update to fix the problem. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2004.019-kolab.html**********SuSE patches Live CD 9.1A flaw in the default configuration of SuSE Live CD 9.1, which allows a user to boot SuSE Linux from a CD, could allow a remote user to gain root privileges by logging in via ssh without need for a password. Download the update from:ftp://ftp.suse.com/pub/suse/i386/live-cd-9.1/LiveCD-9.1-01.iso**********Today’s roundup of virus alerts:W32/Lovgate-V – Another variant of the Lovegate worm, which spreads via e-mail, network shares and file sharing networks. The virus drops a backdoor Trojan on the infected machine that allows an attacker to gain access. The infected file attachment is a ZIP with the name work, setup, important, bak, letter or pass . (Sophos)W32/Sdbot-JT – Another Sdbot variant that copies itself to the Windows system folder as nmsmtp32.exe. No word on how the infected spreads. (Sophos)W32/Sdbot-IH – Yet another Sdbot variant that spreads via weakly protected network shares and plants a backdoor Trojan Horse on the infected machine. It also logs the user’s keystrokes. (Sophos)Briss.A – A memory-resident Trojan horse that downloads malware to the infected machine. Spreads via infected downloads and files. (Sophos)**********From the interesting reading department:German Teen Admits Making The ‘Sasser’ Internet WormA teenager in Germany confessed to creating a computer worm that has crashed computers around the world in the past week, German authorities said Saturday. The suspect had been identified by acquaintances seeking a $250,000 reward. Washington Post, 05/09/04.https://www.nwfusion.com/go2/0510bug1f.htmlGartner: Phishing attacks up against U.S. consumersA new study by research firm Gartner found that the number of online scams known as “phishing attacks” have spiked in the slast year and that online consumers are frequently tricked into divulging sensitive information to criminals. IDG News Service, 05/06/04.https://www.nwfusion.com/news/2004/0506gartnphish.html?nlFTC settles with alleged ‘Married But Lonely’ spammersThe Federal Trade Commission has settled charges against two alleged spammers that used what the FTC called “deceptively bland subject lines,” false return addresses, and other methods to lure unsuspecting consumers, including children, to sexually explicit material. IDG News Service, 05/07/04.https://www.nwfusion.com/news/2004/0507ftcsettle.html?nl Related content news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Cloud Computing opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software brandpost Sponsored by HPE Aruba Networking SASE, security, and the future of enterprise networks By Adam Foss, VicePresident Pre-sales Consulting, HPE Aruba Networking Nov 28, 2023 4 mins SASE news AWS launches Cost Optimization Hub to help curb cloud expenses At its ongoing re:Invent 2023 conference, the cloud service provider introduced several new and free updates that are expected to help enterprises optimize their AWS costs. By Anirban Ghoshal Nov 28, 2023 3 mins Amazon re:Invent Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe