* Patches from Conectiva, SCO, Mandrake Linux * Beware worms that give attacker access to infected machines via IRC channel * SSH boosts e-commerce security, and other interesting reading Today’s bug patches and security alerts:Buffer overflow in Oracle databaseSecurityTracker is reporting a buffer overflow vulnerability in the Oracle command line interface. An attacker could exploit this to run the code of choice or potentially gain elevated privileges. For more, go to:https://www.securitytracker.com/alerts/2003/Oct/1007956.html **********Opera browser flaw fixed A buffer overflow in the way HREFs are handled by the browser could be exploited in a denial-of-service attack or to potentially run code on the affected machine. Download Version 7.21 to fix this issue:https://www.opera.com/download/@Stake advisory:https://www.atstake.com/research/advisories/2003/a102003-1.txt**********Conectiva patches fileutils A buffer overflow vulnerability has been found in Conectiva’s “ls” directory listing command found the fileutils package. The flaw could be exploited in a denial-of-service attack. For more, go to:https://www.nwfusion.com/go2/1020bug2a.html**********SCO patches issue with /tmp SCO is warning that several scripts improperly use the /tmp directory. A malicious user could exploit this using a symlink attack. For more, go to:ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.27**********Mandrake Linux patches gdmTwo flaws in Mandrake Linux’s gdm package could be exploited to freeze or crash the application to freeze or crash. A fix is available. For more, go to:https://www.nwfusion.com/go2/1020bug2b.html**********Today’s roundup of virus alerts:Troj/IRCBot-P – Yet another Trojan horse application that spreads via IRC and allows an attacker to access the infected machine via an IRC channel. (Sophos)W32/Dafly-B – A virus that attaches itself to Windows Executable file. It changes a bunch of registry keys and displays a message on the infected machine. (Sophos)W32/Opaserv-R – A worm that spreads via network shares. It drops a couple of .dat file on the infected machine but no word on any permanent damage cause. (Sophos)Troj/CoreFloo-C – This virus arrives as an executable file with a random 7 character name. The virus gives an attacker access to the infected machine via an IRC channel and attempts to protect various virus-related processes. (Sophos)W32/Agobot-AA – Another worm that attempts to provide unauthorized access to the infected machine via an IRC channel. This virus spreads via network shares with weak or no password protection. (Sophos)**********From the interesting reading department:Aruba boosts Wi-Fi security, remote mgmt.Aruba Wireless Networks this week is scheduled to launch a fixed-configuration wireless LAN switch aimed at bringing advanced Wi-Fi management and security to branch offices, or expanding deployments throughout a larger company. Network World, 10/20/03.https://www.nwfusion.com/news/2003/1020aruba.htmlJuniper spearheads plan to fortify ‘NetJuniper last week disclosed an ambitious plan to unite the industry around a common vision for public networking that could make the Internet secure and reliable enough for full-fledged global commerce. Network World, 10/20/03.https://www.nwfusion.com/news/2003/1020juniper.htmlAuthentication upgrade on tap from FunkFunk Software is introducing upgraded software that lets Cisco gear users authenticate and gain access to wireless networks via Funk’s RADIUS servers, Network World, 10/20/03.https://www.nwfusion.com/news/2003/1020funk.htmlCheck Point gets into appliance businessCheck Point – formerly a software-only company – now offers two lines of low-end VPN-firewall appliances for branch offices and home offices. Network World, 10/20/03.https://www.nwfusion.com/news/2003/1020checkpoint.htmlSSH boosts e-commerce securitySSH Communications Security next month plans to release its Tectia product suite for securing access to proprietary e-commerce applications by making use of the IETF standard Secure Shell Protocol instead of the Web-based encryption standard Secure Sockets Layer. Network World, 10/20/03.https://www.nwfusion.com/news/2003/1020ssh.htmlNetScreen announces deep inspection firewallCiting an increase in attacks that take advantage of holes in existing firewall technology, NetScreen Technologies Mondaysaid that it will release new “deep packet inspection” features across its line of network firewall products. IDG News Service, 10/20/03.https://www.nwfusion.com/news/2003/1020netscannou.htmlSymantec adds patch management to Ghost softwareA new version of the Ghost computer cloning and restoration product from Symantec adds features that deploy software patches and reduce the network bandwidth used by the program, the company said Monday. IDG News Service, 10/20/03.https://www.nwfusion.com/news/2003/1020symanadds.htmlSymantec purchases SSL VPN maker SafeWebAnti-virus and computer security company Symantec Monday said that it purchased SafeWeb of Emeryville, Calif., for $26 million in cash. SafeWeb makes technology that givesworkers secure, remote access to network resources over the Internet. IDG News Service, 10/20/03.https://www.nwfusion.com/news/2003/1020symanpurch.html Related content news Dell provides $150M to develop an AI compute cluster for Imbue Helping the startup build an independent system to create foundation models may help solidify Dell’s spot alongside cloud computing giants in the race to power AI. By Elizabeth Montalbano Nov 29, 2023 4 mins Generative AI news DRAM prices slide as the semiconductor industry starts to decline TSMC is reported to be cutting production runs on its mature process nodes as a glut of older chips in the market is putting downward pricing pressure on DDR4. By Sam Reynolds Nov 29, 2023 3 mins Flash Storage Flash Storage Technology Industry news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Network Management Software Networking opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe