* Apache Tomcat fix releases * Gentoo patches slocate * Next 'Slammer' could be worse, and other interesting reading Patch and virus news from Apache, Gentoo, Red Hat and moreGot an e-mail from a reader about my statement in the last newsletter that I don’t buy the excuse that people don’t apply patches because of the testing. My explanation made the reader think I don’t believe in testing patches before installing them on production systems. I do believe people should test first. Some Microsoft systems were hit while testing was being done. If you’re working on applying the patch and get hit in the process, I feel badly for you.What I meant is that it’s a lame excuse when people don’t apply a patch because they think the testing is too much. Test, test and test again, then patch. If you want to keep your systems safe it’s the only way.Today’s bug patches and security alerts: Flaw found in SpamAssassinA buffer overflow vulnerability in the spam utility SpamAssassin could be exploited by an attacker to run arbitrary code on the affected machine, according to a report on SecurityTracker. For more, go to: https://www.securitytracker.com/alerts/2003/Jan/1005989.htmlRelated advisories/patches:Gentoo:https://forums.gentoo.org/viewtopic.php?t=33319**********Apache Tomcat fix releases Three major flaws have been found in the Apache Tomcat server software. The flaws could be exploited to get a directory listing, read XML data or use a cross-scripting attack to execute arbitrary commands on affected systems. Users should update to Version 3.3.1a. For more, go to:https://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/**********Red Hat updates Kerberos to fix FTP flaw A flaw in the Kerberos FTP client could be exploited to write files outside the current directory and potentially to execute arbitrary code on the affected machine. Red Hat users can download the update from:https://rhn.redhat.com/errata/RHSA-2003-020.html**********SCO patches CVS vulnerabilityA vulnerability in the popular Concurrent Version System (CVS) server could allow a malicious user to run arbitrary code on the affected machine. SCO is urging users to upgrade to the latest version to ensure systems are not vulnerable. For more, go to:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-006.0.txt**********Gentoo patches slocateA buffer overflow vulnerability has been found in Gentoo’s implementation of slocate. A patch is available to fix this flaw. For more, go to:https://forums.gentoo.org/viewtopic.php?t=33321**********Today’s roundup of virus alerts:Winpao — A Trojan horse that steals system information and mails it to the virus’ author. The virus can also mess with the Windows Registry in a way that will prevent a majority of files from running correctly. (Panda Software)**********From the interesting reading department:Next ‘Slammer’ could be worseAs cleanup of the MS-SQL Slammer worm continued last week, talk among security experts centered on two facets of the attack that might portend greater trouble: the remarkable speed with which Slammer spread, and the idea that future versions might carry a nefarious payload. Network World, 02/03/03.https://www.nwfusion.com/news/2003/0203slammer.htmlExpert weighs code release after SlammerSaturday’s Slammer worm was based on sample code published to help explain the threat posed by the security vulnerability that Slammer exploited, according to David Litchfield, the security expert who discovered the vulnerability. IDG News Service, 01/30/03.https://www.nwfusion.com/news/2003/0130expertslam.htmlSSL: The secret handshake of the ‘NetSecure Sockets Layer has become the de facto standard for secure communications between end users and Internet sites, and today, SSL support is built into virtually every browser. Network World, 02/03/03.https://www.nwfusion.com/news/tech/2003/0203techupdate.htmlSana Security claims cure for server intrusionStart-up Sana Security says its software can learn normal server activity and detect or block abnormal behavior, such as buffer-overflow attempts, which aim to subvert the server’s security. Network World, 02/03/03.https://www.nwfusion.com/news/2003/0203sana.htmlSecurity tool offers to rein in at-work IM useAt-work instant messaging addicts beware: Web security firm Blue Coat Systems is planning to release an application that can monitor, log and manage employees’ consumer instant messaging use. IDG News Service, 01/31/03.https://www.nwfusion.com/news/2003/0131securtool.htmlBIOS maker to unveil ‘bunker environment’ for PCsPhoenix Technologies, the maker of BIOS software for most of the world’s PCs, plans to unveil next month a software environment for PCs and other devices that creates a “bunker” in which critical utilities can be stored. IDG News Service, 01/30/03.https://www.nwfusion.com/news/2003/0130biosmaker.html**********Archives online:As a service to our faithful readers, we’ve got an online archive of this newsletter for your reference:https://www.nwfusion.com/newsletters/bug/ Related content feature Data centers unprepared for new European energy efficiency regulations Regulatory pressure is driving IT teams to invest in more efficient servers and storage and improve their data-center reporting capabilities. By Maria Korolov Dec 07, 2023 7 mins Enterprise Storage Enterprise Storage Enterprise Storage news analysis AMD launches Instinct AI accelerator to compete with Nvidia AMD enters the AI acceleration game with broad industry support. First shipping product is the Dell PowerEdge XE9680 with AMD Instinct MI300X. By Andy Patrizio Dec 07, 2023 6 mins CPUs and Processors Generative AI Data Center news Netskope extends SASE localization capabilities Expanded localization options in Netskope's NewEdge security private cloud can help enterprises meet data residency requirements and boost user experience. By Denise Dubie Dec 07, 2023 4 mins SASE SD-WAN Cloud Access Security Broker news analysis Western Digital keeps HDDs relevant with major capacity boost Western Digital and rival Seagate are finding new ways to pack data onto disk platters, keeping them relevant in the age of solid-state drives (SSD). By Andy Patrizio Dec 06, 2023 4 mins Enterprise Storage Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe