* Patches from Apple, Slackware, others * Beware Sober virus * Developers get hands on Microsoft's NGSCB, and other interesting reading Today’s bug patches and security alerts:@Stake reports Mac vulnerabilitiesA file overwrite vulnerability has been found in the Apple Mac OS X 10.3 operating system. An attacker could exploit this to gain shell privileges to overwrite and read files on the affected machine. For more, go to:https://www.atstake.com/research/advisories/2003/a102803-1.txt For the latest Apple Updates (including a fix for this problem):https://docs.info.apple.com/article.html?artnum=61798 **********Apple patches QuickTime Java implementationA flaw in the QuickTime Java implementation for Mac OS X 10.3 and X Server 10.3 could be exploited to gain unauthorized system access. For more, go to:https://www.info.apple.com/kbnum/n120266**********Slackware issues gdm patch A flaw in GDM could be exploited by an attacker to cause the application to crash. For more, go to:https://www.nwfusion.com/go2/1027bug2a.htmlSlackware patches fetchmailA buffer overflow flaw in the popular fetchmail program could be exploited to cause the application to crash. A fix is available. For more, go to: https://www.nwfusion.com/go2/1027bug2b.html**********SGI issues three service packsSGI has released three new “environment updates” that fix a number of vulnerabilities in its IRIX operating system. For more, go to:https://www.nwfusion.com/go2/1027bug2c.htmlhttps://www.nwfusion.com/go2/1027bug2d.htmlhttps://www.nwfusion.com/go2/1027bug2e.html**********Debian patches thttpdTwo vulnerabilities have been found in Debian’s thttpd code. One flaw could be exploited to browse the entire disk contents. Another flaw could be exploited by an attacker to run arbitrary code. For more, go to:https://www.debian.org/security/2003/dsa-396**********DoS flaw in apache2 fixedMandrake Linux, OpenPKG and Immunix have released a fix for their implementations of the apache2 code. A flaw in the way certain scripts are handled could result in a denial-of-service against the http process. For more, go to:Mandrake Linux:https://www.nwfusion.com/go2/1027bug2f.htmlOpenPKG:https://www.openpkg.org/security/OpenPKG-SA-2003.046-apache.htmlImmunix (source code):https://www.nwfusion.com/go2/1027bug2g.html**********Today’s roundup of virus alerts:Sober virus in the wild but slow-movingAn e-mail-borne virus that apparently originated in Germany is in the wild but has not yet spread widely or affected many users, an anti-virus researcher said Monday. IDG News Service, 10/28/03.https://www.nwfusion.com/news/2003/1028sobervirus.html?nlW32/Holar-I – A worm that spreads via e-mail and peer-to-peer networks and causes the infected machine to stop responding after the virus has run 30 times. (Sophos)W32/Marq-A – This virus spreads via e-mail and requires the recipient to click on a link. The Web page the link directs users to contains the viral code. (Sophos)W32/Agobot-AF – Another variant of the Agobot worm family. This one too exploits Windows RPC DCOM vulnerability. (Sophos)**********From the interesting reading department:Developers get hands on Microsoft’s NGSCBIn addition to showing off its next-generation Longhorn operating system this week, Microsoft for the first time handed out code that underlies its closely watched Next-Generation Secure Computing Base security technology. IDG News Service, 10/30/03.https://www.nwfusion.com/news/2003/1030pdcdev.html?nlIntel steps up security on motherboardsIntel will begin offering motherboards with a new security option this week. The motherboards come with a chip called a Trusted Platform Module (TPM) that allows documents to be encrypted and safely stored on the fly using an RSA accelerator to generate up to 2048-bit RSA encryption and decryption. Geek.com, 10/27/03.https://www.geek.com/news/geeknews/2003Oct/bch20031027022394.htm Related content news analysis Western Digital keeps HDDs relevant with major capacity boost Western Digital and rival Seagate are finding new ways to pack data onto disk platters, keeping them relevant in the age of solid-state drives (SSD). By Andy Patrizio Dec 06, 2023 4 mins Enterprise Storage Data Center news analysis Global network outage report and internet health check Cisco subsidiary ThousandEyes, which tracks internet and cloud traffic, provides Network World with weekly updates on the performance of ISPs, cloud service providers, and UCaaS providers. By Ann Bednarz and Tim Greene Dec 06, 2023 286 mins Networking news analysis Cisco uncorks AI-based security assistant to streamline enterprise protection With Cisco AI Assistant for Security, enterprises can use natural language to discover policies and get rule recommendations, identify misconfigured policies, and simplify complex workflows. By Michael Cooney Dec 06, 2023 3 mins Firewalls Generative AI Network Security news Nvidia’s new chips for China to be compliant with US curbs: Jensen Huang Nvidia’s AI-focused H20 GPUs bypass US restrictions on China’s silicon access, including limits on-chip performance and density. By Anirban Ghoshal Dec 06, 2023 3 mins CPUs and Processors Technology Industry Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe