* Patches from Debian, SCO, Red Hat, others * Beware P2P virus SpyBot * Paper finds new wireless standard less secure, and other interesting reading Today’s bug patches and security alerts:Linux CUPS vulnerability fixedA flaw in versions of Common Unix Printing System prior to 1.1.19 could be exploited via the Internet Printing Protocol (IPP) to cause CUPS to enter a busy loop, resulting in a denial of service. For more, go to:Red Hat: https://rhn.redhat.com/errata/RHSA-2003-275.htmlMandrake Linux: https://www.nwfusion.com/go2/1110bug1a.htmlConectiva:https://www.nwfusion.com/go2/1110bug1b.html**********Debian patches postgresqlTwo bugs found in the postgresql database code could be exploited to trigger a buffer overflow, which could be used to run malicious code on the affected server. For more, go to: https://www.debian.org/security/2003/dsa-397**********Conectiva releases fix for thttpdA flaw in the tiny http server (thttpd) for Conectiva’s Linux implementation could be exploited to by pass the virtual-hosting mechanism to read arbitrary files on the affected machine. For more, go to: https://www.nwfusion.com/go2/1110bug1c.html**********Conectiva, SCO patch net-snmpA flaw in earlier versions of net-snmp, an implementation of the Simple Network Management Protocol (SNMP) for network monitoring, could be exploited to allow users access to MIB objects that normally would be excluded from their view. For more, go to:Conectiva:https://www.nwfusion.com/go2/1110bug1d.htmlSCO OpenLinux:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-029.0.txt**********SCO, Conectiva release ethereal patchA number of flaws have been found in ethereal, a free network monitoring tool for Linux/Unix. The vulnerabilities could be exploited in a denial-of-service attack or to potentially execute the attacker’s code of choice. For more, go to:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt**********SCO releases Apache update for OpenServerVersion 2.0.48 of the Apache Web server is primarily a bug fix release, according to an alert from SCO. In addition to some minor bugs, this release also fixes a CGI path redirect flaw and a buffer overflow in the mod_alias and mod_rewrite. For more, go to:ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.28SCO issues fix for CDE libDtHelpAccording to an alert from SCO, “The Common Desktop Environment (CDE) is a standard desktop environment for UNIX based systems. CDE libDTHelp contains a buffer overflow that can be exploited by a local user using specially crafted environment variables. An authenticated local user may be able to execute arbitrary code with root privileges.” For more, go to:ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.31**********Red Hat patches fileutilsA buffer overflow vulnerability has been found in Red Hat Linux’s “ls” directory listing command found the fileutils package. The flaw could be exploited in a denial-of-service attack. The fix can be downloaded here:https://rhn.redhat.com/errata/RHSA-2003-309.html**********Today’s roundup of virus alerts:W32/SpyBot-W, V – A peer-to-peer virus that disables certain utilities and waits for commands sent via IRC. (Sophos)**********From the interesting reading department:Virus writers dismiss Microsoft’s bounty fundThough cyberspace outlaws may look over their shoulder one extra time before launching a computer virus or worm, they won’t be deterred by the $5 million bounty fund established by Microsoft to help capture and convict them, two virus writers said. IDG News Service, 11/07/03.https://www.nwfusion.com/news/2003/1107viruswrite.htmlPaper finds new wireless standard less secureA new paper by a leading security expert says that the new Wi-Fi Protected Access (WPA) security standard may be less secure, in certain scenarios, than WEP, the wireless standard it was designed to replace. IDG News Service, 11/07/03.https://www.nwfusion.com/news/2003/1107paperfinds.html Related content news Broadcom to lay off over 1,200 VMware employees as deal closes The closing of VMware’s $69 billion acquisition by Broadcom will lead to layoffs, with 1,267 VMware workers set to lose their jobs at the start of the new year. By Jon Gold Dec 01, 2023 3 mins Technology Industry Technology Industry Markets news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Network Management Software Network Management Software news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Mainframes Mainframes Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe