* Patches from Apple, FreeBSD,SCO, others * Beware e-mail worm disguised as Microsoft patch * Symantec adds anti-virus to early warning system, and other interesting reading Today’s bug patches and security alerts:Apple patches OpenSSH and sendmail flaws in Mac OS XA new Mac OS X update provides fixes for the recently discovered sendmail and OpenSSH flaws as well as a number of smaller bugs found in previous editions of the operating system. Users should download Version 10.2.8 to get all the latest fixes and updates. For more, go to:https://docs.info.apple.com/article.html?artnum=61798 **********FreeBSD fixes arp flaw A vulnerability in FreeBSD’s Address Resolution Protocol (ARP) implementation could be exploited by an attacker to crash the affected machine. The attacker could flood the system with bogus arp requests, causing a “system panic” and ultimately a crash. For more, go to:https://www.nwfusion.com/go2/0922bug2a.html**********SCO, Conectiva, Slackware patch Wu-ftpd flawAccording to the alert from SCO, “Wu-ftpd FTP server contains remotely exploitable off-by-one bug. A local or remote attacker could exploit this vulnerability to gain root privileges on a vulnerable system.” For more, go to:SCO OpenServer: ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.20Conectiva:https://www.nwfusion.com/go2/0922bug2b.htmlSlackware: https://www.nwfusion.com/go2/0922bug2c.html**********Slackware issues ProFTPD updateA bug in the way ProFTPD handles ASCII translations could be exploited by a remote user to gain root shell privileges. This could allow the attacker to have complete control over the affected machine. For more, go to:https://www.nwfusion.com/go2/0922bug2d.html**********NetBSD upgrades sysctl(2) securityThree potential denial-of-service vulnerabilities were found in NetBSD’s kernel sysctl(2) function. The various flaws could be exploited to cause a system panic. For more, go to:https://www.nwfusion.com/go2/0922bug2e.htmlNetBSD fixes ibcs2 bugA flaw in the way large parameters are handled by NetBSD’s ibcs2 function could be exploited to view sensitive system information that could be used in other attack scenarios against the affected machine. For more, go to:https://www.nwfusion.com/go2/0922bug2f.html**********Root vulnerability in Denian’s hztty fixedA buffer overflow in hztty, an application for translating Chinese characters in a terminal session, could be exploited to by an attacker to gain root access on the affected machine. A fix is available. For more, go to:https://www.debian.org/security/2003/dsa-385Debian plugs gopher buffer overflowsA number of buffer overflow vulnerabilities have been found in the Debian’s implementation of the gopher server. These flaws could be exploited to run an attacker’s code of choice on the machine with the privileges of “gopher”. For more, go to:https://www.debian.org/security/2003/dsa-387Debian patches libmailtools-perlPoor input checking in libmailtools-perl, a Perl application for passing mail to other applications, could result in malicious commands being run on the affected machine. For more, go to:https://www.debian.org/security/2003/dsa-386Debian issues new ipmasq packagesA flaw in ipmasq, a form of network address translation for Debian Linux, could be exploited to forward unauthorized traffic from the outside world to an internal client on the network. For more, go to:https://www.debian.org/security/2003/dsa-389**********Red Hat issues new Apache and mod_ssl packagesThis latest Apache update from Red Hat fixes a number of vulnerabilities found in previous versions of the popular Web server software. For more, go to:https://rhn.redhat.com/errata/RHSA-2003-243.htmlRed Hat releases Perl updateAccording to an alert from Red Hat, “Updated Perl packages that fix a security issue in Safe.pm and a cross-sitescripting (XSS) vulnerability in CGI.pm are now available.” For more, go to:https://rhn.redhat.com/errata/RHSA-2003-256.html**********Today’s roundup of virus alerts:W32/Dumaru-B – Another worm that spreads via an e-mail that claims to be a Microsoft patch. The infected message comes from “security@microsoft.com” with a subject line of “Use this patch immediately !” and an attachment called “patch.exe”. The virus drops a keystroke logger and attempts to disable security-related software running on the infected machine. (Sophos)W32/Lovgate-R – A worm that drops backdoor functionality on the infected machine, allowing an attacker to gain access to and control the system. The virus spreads via network shares and e-mail. (Sophos)**********From the interesting reading department:U.S. immigration system hit by virusThe U.S. Department of State struggled Tuesday to quell an outbreak of the W32.Welchia Internet worm on the department’s computer systems. IDG News Service, 09/24/03.https://www.nwfusion.com/news/2003/0924immigration.htmlAn inside look at tracing a network intrusionLawrence Baldwin traces the steps he took to investigate an intrusion into his network.https://www.nwfusion.com/go2/0922bug2g.htmlIf These Networks Get Hacked, BewareAmerica’s critical transportation, power, and communications systems remain quite vulnerable and lack funds to remedy that. BusinessWeek, 09/16/03.https://www.nwfusion.com/go2/0922bug2h.htmlGov’t agency uses buying power to encourage securityThe U.S. government has started to use its immense purchasing power to influence cybersecurity, beginning with a Department of Energy contract with Oracle that requires the software vendor to build in security configurations. IDG News Service, 09/23/03.https://www.nwfusion.com/news/2003/0923govt.htmlSophos buys anti-spam vendor ActiveState for $23 millionU.K. anti-virus company Sophos Wednesday said it bought the Canadian company ActiveState for $23 million in cash, adding ActiveState’s line of anti-spam products to Sophos’ enterprise anti-virus software. IDG News Service, 09/24/03.https://www.nwfusion.com/news/2003/0924sophobuys.htmlSymantec adds anti-virus to early warning systemChanges to Symantec’s DeepSight Threat Management System announced Monday will add data on computer viruses and worms to an Internet early warning system, providing enterprise customers with the ability to track the outbreaks on the Internet, Symantec said. IDG News Service, 09/23/03.https://www.nwfusion.com/news/2003/0923symanadds.htmlCalif. law protects all from security breachesNo matter where you live in the U.S., your identity theft protection is about to improve. And you can thank the California legislature for that. PC World, 09/23/03.https://www.nwfusion.com/news/2003/0923califlawp.htmlTruSecure tackles risk managementTruSecure, a managed security services company, waded into the crowded waters of security software applications Monday with the announcement of a new enterprise security management application called Risk Commander. IDG News Service, 09/22/03.https://www.nwfusion.com/news/2003/0922trusetackl.htmlRSA upgrades ClearTrust software for Web access controlRSA Security has upgraded its ClearTrust server software for policy-based access to Web applications, adding support for Security Assertions Markup Language (SAML) 1.1 and identity-management features licensed from Thor Technologies. Network World Fusion, 09/22/03.https://www.nwfusion.com/news/2003/0922rsa.html Related content news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Network Management Software Networking opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software brandpost Sponsored by HPE Aruba Networking SASE, security, and the future of enterprise networks By Adam Foss, VicePresident Pre-sales Consulting, HPE Aruba Networking Nov 28, 2023 4 mins SASE news AWS launches Cost Optimization Hub to help curb cloud expenses At its ongoing re:Invent 2023 conference, the cloud service provider introduced several new and free updates that are expected to help enterprises optimize their AWS costs. By Anirban Ghoshal Nov 28, 2023 3 mins Amazon re:Invent Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe