* Patches from Red Hat, Immunix, Trustix, others * Beware destructive virus spreading via an e-mail attachment called "VIRUS_BLOCK.EXE" Today’s bug patches and security alerts:Red Hat patches memory leak in xftA bug in the way xft-based applications render text on certain X servers could cause a memory leak. A fix is available. For more, go to:https://rhn.redhat.com/errata/RHBA-2002-305.html Red Hat updates up2dateA flaw in up2date, a tool that automatically looks for and installs Red Hat patches, does not properly check for a valid GPG signature. An attacker could exploit this to trick the machine into downloading and installing malicious code. For more, go to: https://rhn.redhat.com/errata/RHSA-2003-255.html**********Immunix patches wuftpdAn off-by-one bug has been found in the popular Washington University FTP Server daemon (wufptd). An attacker could exploit this flaw to gain root privileges on an affected server. For more, go to:https://www.nwfusion.com/go2/0811bug1a.html********** NetBSD warns of OSI network bugA flaw in the OSI networking kernel for NetBSD could be exploited to cause a denial-of-service against an affected machine. For more, go to:https://www.nwfusion.com/go2/0811bug1b.html********** Conectiva patches wgetA buffer overflow in wget, a tool for retrieving files via FTP and HTTP, could be exploit to run arbitrary code on the affected machine or cause erratic application behavior. For more, go to:https://www.nwfusion.com/go2/0811bug1c.html**********EnGarde, Trustix patch stunnelA flaw in stunnel, an application for tunneling an unencrypted network connection over a secure connection, does not properly start certain processes, which could be exploited in denial-of-service attack. For more, go to:EnGarde:https://www.nwfusion.com/go2/0811bug1d.htmlTrustix:https://www.nwfusion.com/go2/0811bug1e.html**********Trustix patches postfixA new version of postfix, a mail transfer agent, is available that fix two vulnerabilities in older versions of the software. One flaw could be exploited in a denial-of-service (DoS) attack against the affected machine. Another flaw could be exploited to use postfix as a distributed DoS tool for launching attacks against random IP addresses. For more, go to:https://www.nwfusion.com/go2/0811bug1f.html**********OpenPKG patches OpenSSHA flaw in the openssh PAM authentication module could be exploited to determine if an account name is valid or not. An attacker could use this information to narrow the focus of an attack against a target machine. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2003.035-openssh.htmlOpenPKG issues fix for perl-wwwA cross-scripting vulnerability has been found in the CGI.pm Perl module. A fix is available from OpenPKG. For more, go to:https://www.openpkg.org/security/OpenPKG-SA-2003.036-perl-www.html**********@Stake warns of flaws in IPNetSentryX and IPNetMonitorXIPNetSentryX and IPNetMonitorX, network monitoring tools from Sustworks, contain flaws that could allow an unauthorized local user to sniff the network or potentially gain root access to the affected machine. For more, go to:https://www.atstake.com/research/advisories/2003/a080703-1.txt**********Today’s roundup of virus alerts:Troj/SView-A – A backdoor Trojan horse program that allows third-parties to access the infected machine without authorization. (Sophos)Panol – A destructive virus that spreads via an e-mail attachment called “VIRUS_BLOCK.EXE”. Instead of doing what the name implies, it stop anti-virus processes and attempts to format the C-drive when the infected machine is restarted. (Panda Software) Related content how-to Doing tricks on the Linux command line Linux tricks can make even the more complicated Linux commands easier, more fun and more rewarding. By Sandra Henry-Stocker Dec 08, 2023 5 mins Linux news TSMC bets on AI chips for revival of growth in semiconductor demand Executives at the chip manufacturer are still optimistic about the revenue potential of AI, as Nvidia and its partners say new GPUs have a lead time of up to 52 weeks. By Sam Reynolds Dec 08, 2023 3 mins CPUs and Processors Technology Industry news End of road for VMware’s end-user computing and security units: Broadcom Broadcom is refocusing VMWare on creating private and hybrid cloud environments for large enterprises and divesting its non-core assets. By Sam Reynolds Dec 08, 2023 3 mins Mergers and Acquisitions news analysis IBM cloud service aims to deliver secure, multicloud connectivity IBM Hybrid Cloud Mesh is a multicloud networking service that includes IT discovery, security, monitoring and traffic-engineering capabilities. By Michael Cooney Dec 07, 2023 3 mins Network Security Cloud Computing Networking Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe