* Patches from SGI, Debian, others * Beware worm that spreads via ADMIN$ and IPC$ network shares * Microsoft to kill popular Linux antivirus product, and other interesting reading Today’s bug patches and security alerts:Apple releases Mac OS X security updateTwo vulnerabilities have been fixed in Apple’s Mac OS X. One flaw in the Apple File Service could be exploited to overwrite arbitrary files. The second flaw involves passwords being sent in cleartext when logging on via Kerberos on an LDAPv3 server. For more, go to:https://docs.info.apple.com/article.html?artnum=120223 **********Vulnerability in Netware HTTP Stack patched The HTTP stack used in NetWare 6 is vulnerable to an “ABEND” (abnormal end) when it receives a modified TCP keep-live request. A patch is available. For more, go to:https://support.novell.com/servlet/tidfinder/2966181**********SGI patches webminA flaw in the IRIX Web setup package (webmin) from SGI could allow unauthorized remote access to the applications. A fix is available. For more, go to:https://www.networkworld.com/ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I **********Debian, Mandrake Linux update kernel packagesA number of vulnerabilities have been fixes in new kernel updates from Debian and Mandrake Linux. Users should update their kernel implementations as soon as possible. For more, go to:Debian: https://www.debian.org/security/2003/dsa-311https://www.debian.org/security/2003/dsa-312Mandrake Linux:https://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:066**********Debian patches xaosAccording to an alert from Debian, “XaoS, a program for displaying fractal images, is installed setuid root on certain architectures in order to use svgalib, which requires access to the video hardware. However, it is not designed for secure setuid execution, and can be exploited to gain root privileges. For more, go to:https://www.debian.org/security/2003/dsa-310**********OpenPKG patches gzipA flaw in the way GNU Zip’s (gzip) znew command creates temporary files could be exploited in a symlink attack against the affected machine. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html**********Immunix patches teTeXA number of potential vulnerabilities and bugs in teTeX have been patched by Immunix. Updates can be downloaded from:https://www.networkworld.com/ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/**********@Stake warns of flaw in Nokia GGSN (IP650 Based)According to an alert from @Stake, “There exists a vulnerability in the TCP stack that allows an attacker to cause the GGSN to kernel panic and shutdown. This potentially allows an attacker to crash all data connectivity within a GPRS based network.” For more, go to:https://www.atstake.com/research/advisories/2003/a060903-1.txt**********Today’s roundup of virus alerts:W32/Mapson-A – A virus that spreads via e-mail and peer-to-peer file-sharing networks. The virus sends itself to email addresses found in the infected machine’s MSN Messenger contact list. It also displays random messages on the infected machine’s screen. (Sophos)Win32.Mofei.B – This worm spreads via ADMIN$ and IPC$ network shares. The worm acts as a back door Trojan horse for attackers to exploit. (Computer Associates)W32/Backzat-K – A worm that spreads in the form a .scr file via mIRC, AIM95 and the KaZaA file-sharing network. No word on any permanent damage cause. (Sophos)W32/Jeefo-A – A worm that creates a couple registry entries to ensure it runs on a computer’s restart. No word on permanent damage caused. (Sophos)**********From the interesting reading department:Microsoft still certifying leaky drivers, firm saysMonths after promising to tighten up its procedures for certifying third-party software drivers, Microsoft is still giving the green light to network interface card (NIC) drivers that leak sensitive user information from machines running Windows Server 2003, according to a prominent security company. IDG News Service, 06/09/03.https://www.nwfusion.com/news/2003/0609microstill.htmlRelated NGSSoftware advisory:https://www.nextgenss.com/advisories/etherleak-2003.txtMicrosoft to buy Romanian antivirus companyMicrosoft Tuesday announced it is buying Bucharest, Romania-based antivirus software vendor GeCAD Software for an undisclosed price, triggering speculation from analysts that Microsoft has its eye on competing directly in the antivirus market. Network World Fusion, 06/10/03.https://www.nwfusion.com/news/2003/0610msav.htmlMicrosoft to kill popular Linux antivirus productThe RAV product line will be discontinued after Microsoft completes the acquisition of the technology, Microsoft said. GeCAD, which claims its products protect over 10 million users worldwide, will support current customers through the end of their contracts, Microsoft said. IDG News Service, 06/11/03.https://www.nwfusion.com/news/2003/0611microtoki.htmlQuantum leap for secret codesBritish researchers say they are close to producing an off-the-shelf system that exploits quantum physics to create a secure communications channel. BBC News, 06/05/03.https://news.bbc.co.uk/2/hi/technology/2963138.stmUnisys suite aims to detect criminal patternsA new family of products and services from Unisys is designed to make it possible for financial institutions to detect more complex kinds of fraud and spot identity theft and money laundering schemes earlier. IDG News Service, 06/10/03.https://www.nwfusion.com/news/2003/0610unisysuite.html Related content news Dell provides $150M to develop an AI compute cluster for Imbue Helping the startup build an independent system to create foundation models may help solidify Dell’s spot alongside cloud computing giants in the race to power AI. By Elizabeth Montalbano Nov 29, 2023 4 mins Generative AI Machine Learning Artificial Intelligence news DRAM prices slide as the semiconductor industry starts to decline TSMC is reported to be cutting production runs on its mature process nodes as a glut of older chips in the market is putting downward pricing pressure on DDR4. By Sam Reynolds Nov 29, 2023 3 mins Flash Storage Technology Industry news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Cloud Computing opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe