Americas

  • United States

New sendmail flaw fixed

Opinion
Aug 28, 20034 mins
NetworkingSecurity

* Patches from Debian, Red Hat * Beware network worm that spreads via weak or non-password protected network shares * Time Warner Telecom may be next Sobig.F target, and other interesting reading

Potential good news for all of you suffering from Windows 2000 Service Pack 4 issues pertaining to add/remove programs. Read Gautam Aggarwal shares this Microsoft Knowledgebase article that may hold provide a solution: http://support.microsoft.com/default.aspx?scid=KB;en-us;q266668

Potential good news for all of you suffering from Windows 2000 Service Pack 4 issues pertaining to add/remove programs. Read Gautam Aggarwal shares this Microsoft Knowledgebase article that may hold provide a solution:

https://support.microsoft.com/default.aspx?scid=KB;en-us;q266668

Hope that helps.

Today’s bug patches and security alerts:

Sendmail DNS map flaw patched

Sendmail 8.12.0 and greater could be subject to a denial-of-service vulnerability when the DNS map feature is turned on. In some cases the flaw could be exploited to run arbitrary code on the affected machine. Users should download Version 8.12.9 to fix the problem. For more, go to:

https://www.sendmail.org/dnsmap1.html

FreeBSD patch:

https://www.nwfusion.com/go2/0825bug2a.html

Mandrake Linux:

https://www.nwfusion.com/go2/0825bug2b.html

Red Hat:

https://rhn.redhat.com/errata/RHSA-2003-265.html

**********

Exploit for RealNetworks server hole

A flaw in almost every generation of RealNetworks streaming servers, including Helix Universal Server 9 and RealSystem Server Versions 7 and 8, could be exploited by an attacker to gain root access on the affected machine. The flaw has been know for some time, but reports of an exploit are just surfacing. A patch is not yet available from RealNetworks, but a workaround is: Remove the “View source plug-ins” from the “plug-ins” directory then restart the server. For more, go to:

https://www.nwfusion.com/go2/0825bug2c.html

RealOne Player flaw fixed

An attacker could use script code embedded in SMIL file to gain access to certain browser cache information on the target machine. A fix for this is available from RealNetworks. For more, go to:

https://www.nwfusion.com/go2/0825bug2d.html

**********

Debian patches unzip

A flaw in unzip that could allow arbitrary files to be overwritten has been patched by Debian. For more, go to:

https://www.nwfusion.com/go2/0825bug2e.html

**********

Slackware releases GDM update

A flaw in Slackware’s GDM package allows any local user to view any file on the affected system. For more, go to:

https://www.nwfusion.com/go2/0825bug2f.html

**********

Red Hat patches iptables package

A bug in iptables makes it incompatible with some of the new kernel code available from Red Hat. A fix is available. For more, go to:

https://rhn.redhat.com/errata/RHSA-2003-213.html

Red Hat issues fix for pam_smb

A vulnerability in the pam-pgsql module for Red Hat could be exploited by a malicious user to execute arbitrary code with the privileges of the application requesting PAM authentication. For more, go to:

https://rhn.redhat.com/errata/RHSA-2003-261.html

**********

Today’s round up of virus alerts:

W32/Tzet-A – A network worm that spreads via weak or non-password protected network shares. The virus drops a Trojan horse on the infected machine. (Sophos)

**********

From the interesting reading department:

NetGear routers blast University of Wisconsin

Starting in May and continuing until just recently, The University of Wisconsin at Madison has been the victim of an accidental denial-of-service attack from hundreds of thousands of Netgear routers. Geek.com, 08/27/03.

https://www.geek.com/news/geeknews/2003Aug/gee20030827021489.htm

Time Warner Telecom may be next Sobig.F target

Romanian researchers claim to have discovered a variant of the Sobig.F virus that looks to mail and domain name servers at Time Warner Telecom for information about how to modify its behavior. IDG News Service, 08/26/03.

https://www.nwfusion.com/news/2003/0826twsobig.html

Virus-related sites getting slammed

With the recent onslaught of computer worms, Web surfers have been looking for refuge in various virus-related sites. Geek.com, 08/26/03.

https://www.geek.com/news/geeknews/2003Aug/gee20030826021470.htm

SCO Web site hit by denial-of-service attack

The SCO Group’s Web site was accessible again Monday after being down for about three days, the victim of a denial-of-service attack launched by a “senior” member of the open source community, according to open source advocate Eric Raymond. IDG News Service, 08/25/03.

https://www.nwfusion.com/news/2003/0825scodds.html