* Patches from NetBSD, Debian and Mandrake * Advertising-related Trojan Horses and e-mail worms * SANS top vulnerabilities include Outlook, P2P; and other interesting reading Today’s bug patches and security alerts:NetBSD, Debian patch sendmailA bug in the sendmail implementations from NetBSD and Debian could be exploited to gain elevated privileges on the affected machine. For more, go to:NetBSD: https://www.nwfusion.com/go2/1013bug1a.htmlDebian: https://www.debian.org/security/2003/dsa-394**********NetBSD issues OpenSSL fixA stack-overrun vulnerability in NetBSD’s implementation of OpenSSL could be exploited to crash the affected system. A second vulnerability could be exploited to run malicious commands on the machine. For more, go to:https://www.nwfusion.com/go2/1013bug1b.htmlNetBSD releases update for XFree86 According to an alert from NetBSD, “There is an integer overflow in the XFree86 font libraries, which could lead to potential privilege escalation and/or remote code execution.” For more, go to:https://www.nwfusion.com/go2/1013bug1c.html**********Mandrake Linux patches sane packages A number of bugs and potential security vulnerabilities were found in sane, a package used with document scanners. Most of these are pretty minor. For more, go to:https://www.nwfusion.com/go2/1013bug1d.html**********Today’s roundup of virus alerts:W32/Inmotecd-A — A worm that spreads via MAPI-based e-mail systems such as Outlook and comes with an infected .pif file. No word on any permanent damage caused by this virus. (Sophos)IRCBot.D — This worm spreads in a message claiming to be an update from an anti-virus vendor. The message in entitled “Last Update” and an attachment called “NAV32.EXE”. The virus logs on to an IRC server to get commands from a remote user. (Panda Software)Ruledor.A — A Trojan Horse that redirects URL requests to a list of advertiser sites. It also displays pop-up adds on the infected machine. (Panda Software)Pup.A — Another advertising-related Trojan Horse. This virus displays random ads in the Internet Explorer window. (Panda Software)**********From the interesting reading department:SANS top vulnerabilities include Outlook, P2PMicrosoft’s Outlook e-mail program and peer-to-peer software have been included for the first time on the SANS Institute’s annual list of the 20 security vulnerabilities most exploited by attackers on the Internet. IDG News Service, 10/09/03.https://www.nwfusion.com/news/2003/1009sanstopv.htmlSEC busts hacker for securities fraud, ID theftThe U.S. Securities and Exchange Commission (SEC) has filed civil charges against a Pennsylvania man for computer hacking and identity theft in a scheme last July to dump worthless options for Cisco stock. IDG News Service, 10/09/03.https://www.nwfusion.com/news/2003/1009updatsec.htmlMicrosoft unveils security initiativesMicrosoft CEO Steve Ballmer announced a gaggle of security initiatives Thursday that he said would shore up the security of its customers’ systems against what he said in a statement was a “wave of criminal attacks.” IDG News Service, 10/09/03.https://www.nwfusion.com/news/2003/1009mssec.htmlSSL gear makers prep mgmt., security updatesNow that SSL remote access is gaining acceptance among business networking executives, vendors of the gear are in the thick of adding peripheral features to make management simpler and to beef up security. Network World Fusion, 10/09/03.https://www.nwfusion.com/net.worker/news/2003/1009sslvens.html Related content news analysis IBM cloud service aims to deliver secure, multicloud connectivity IBM Hybrid Cloud Mesh is a multicloud networking service that includes IT discovery, security, monitoring and traffic-engineering capabilities. By Michael Cooney Dec 07, 2023 3 mins Network Security Cloud Computing Networking news Gartner: Just 12% of IT infrastructure pros outpace CIO expectations Budget constraints, security concerns, and lack of talent can hamstring infrastructure and operations (I&O) professionals. By Denise Dubie Dec 07, 2023 4 mins Network Security Data Center Industry feature Data centers unprepared for new European energy efficiency regulations Regulatory pressure is driving IT teams to invest in more efficient servers and storage and improve their data-center reporting capabilities. By Maria Korolov Dec 07, 2023 7 mins Enterprise Storage Enterprise Storage Enterprise Storage news analysis AMD launches Instinct AI accelerator to compete with Nvidia AMD enters the AI acceleration game with broad industry support. First shipping product is the Dell PowerEdge XE9680 with AMD Instinct MI300X. By Andy Patrizio Dec 07, 2023 6 mins CPUs and Processors Generative AI Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe