Red Hat releases three fixes

Opinion
May 22, 20033 mins

* Patches from Conectiva, others * Beware virus spreading via e-mail entitled: "Alert! SARS Is being Spread!" * Cisco tightens security in hardware, software, and other interesting reading

Today’s bug patches and security alerts:

Red Hat releases kernel fix

A bug has been found in the Red Hat kernel code that handles translation lookaside buffer flushing. The bug could cause multithreaded processes running via Red Hat Linux 7.2 to fail. For more, go to:

https://rhn.redhat.com/errata/RHBA-2003-144.html

Updated modutils package available for Red Hat Linux

A bug in the way modutils handled PLT relocations during module loading could result in a crash. A fix is available. For more, go to:

https://rhn.redhat.com/errata/RHBA-2003-144.html

Red Hat updates gnupg

A flaw in the way keys held my multiple users is validated could allow certain users greater access than they’re intended to recieve. For more, go to:

https://rhn.redhat.com/errata/RHSA-2003-175.html

**********

Debian releases BitchX client update

A flaw in BitchX, an IRC client, could be exploited by an attacker to write outside the buffer boundaries causing a denial-of-service. The vulnerability could also be exploited to run arbitrary code on the affected machine. For more, go to:

https://www.debian.org/security/2003/dsa-306

**********

SGI warns of vulnerability in Kassena MediaBase

SGI is warning its customers that Kassena’s MediaBase product for IRIX uses insecure versions of Apache and PHP. IRIX users running MediaBase should download the appropriate patch to ensure system security. For more, go to:

https://www.networkworld.com/ftp://patches.sgi.com/support/free/security/advisories/20030502-01-I

**********

Conectiva patches Bugzilla

A number of bugs and two security vulnerabilities have been patched in the latest Bugzilla release for Conectiva. The two vulnerabilities could be exploited via cross scripting or symlink attack. For more, go to:

https://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653

**********

Today’s roundup of virus alerts:

W32/Melare-A – A virus that spreads via an e-mail message entitled “Alert! SARS Is being Spread!”. On certain days of the month, the virus attempts to delete DLL, NLS and OCX files on the infected machine. (Sophos)

Troj/IRCBot-C – A Trojan horse virus that spreads via e-mail and gives an attacker access to the infected machine via IRC. (Sophos)

W32/Lovgate-L – Another variant in the Lovegate family of worms. This is also a Trojan horse that can provide backdoor access to an infected machine. (Sophos)

**********

From the interesting reading department:

Cisco tightens security in hardware, software 

Cisco is wheeling out a smorgasbord of hardware and software security upgrades to boost performance of VPNs and add more security features such as intrusion detection. Network World, 05/20/03.

https://www.nwfusion.com/news/2003/0520cissec.html

 Microsoft, antivirus vendors team on virus info site 

Microsoft has allied with antivirus vendors Network Associates and Trend Micro to form the Virus Information Alliance, an initiative to keep users better informed about virus threats to Microsoft products. Network World, 05/20/03.

https://www.nwfusion.com/news/2003/0520microantiv.html

 Network Associates updates Sniffer technology 

Network Associates released a hardware appliance and updated software on Tuesday that will extend the reach of that company’s Sniffer network traffic management technology from remote users into data centers at the network core. Network World, 05/20/03.

https://www.nwfusion.com/news/2003/0520sniffer.html