Search This Blog

Friday, July 29, 2005

[SECURITY] [DSA 770-1] New gopher packages fix insecure temporary file creation

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 770-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
July 29th, 2005 http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : gopher
Vulnerability : insecure tmpfile creating
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2005-1853

John Goerzen discovered that gopher, a client for the Gopher
Distributed Hypertext protocol, creates temporary files in an insecure
fashion.

For the old stable distribution (woody) this problem has been fixed in
version 3.0.3woody3.

For the stable distribution (sarge) this problem has been fixed in
version 3.0.7sarge1.

For the unstable distribution (sid) this problem has been fixed in
version 3.0.9.

We recommend that you upgrade your gopher package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3.dsc
Size/MD5 checksum: 552 c36368a87e599721ce6faf7f6f2b43af
http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3.tar.gz
Size/MD5 checksum: 508858 9fafa9c495dc402c68e16b1d98578622

Alpha architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_alpha.deb
Size/MD5 checksum: 151672 43a15f4646faee119f5691500e78e8aa
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_alpha.deb
Size/MD5 checksum: 120288 cbee60712b9c3bc4ef7df144aa2c16f5

ARM architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_arm.deb
Size/MD5 checksum: 114782 5d02e52bcdb1e9682e5b338e88d3b1d6
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_arm.deb
Size/MD5 checksum: 98766 adb1f0e3eefea5578fafad6faf305d3e

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_i386.deb
Size/MD5 checksum: 112728 b2b16c3f5cfa2df5aa3a26361adba13f
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_i386.deb
Size/MD5 checksum: 96958 ad5d261eb022846bb9099e27e1c0faea

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_ia64.deb
Size/MD5 checksum: 173840 1a9b23617bb59a99de29c77f9438f266
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_ia64.deb
Size/MD5 checksum: 139924 92daf67a685a0a1d7092477037fc6883

HP Precision architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_hppa.deb
Size/MD5 checksum: 129958 662dcf6bc361150a7edab41fd8ace48d
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_hppa.deb
Size/MD5 checksum: 109924 e27effcad026aa923fa6cd069abc2353

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_m68k.deb
Size/MD5 checksum: 105804 9adb09f5a9705f668ef3f6c678beb738
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_m68k.deb
Size/MD5 checksum: 92012 0a99b4b07a6e7f5cdfab672ecaa0c24c

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_mips.deb
Size/MD5 checksum: 131172 321d042012f31e63989901fb0a799905
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_mips.deb
Size/MD5 checksum: 109634 9f52a094c0c3c4751ba759697b1a8a51

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_mipsel.deb
Size/MD5 checksum: 131172 09507006f76bad2f36a7ef1b845f895e
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_mipsel.deb
Size/MD5 checksum: 109522 0b3ee016c1135a1d7e6d9883d101f52c

PowerPC architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_powerpc.deb
Size/MD5 checksum: 121388 f1e8c648dfd1a9be38c8c595c1a10d3b
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_powerpc.deb
Size/MD5 checksum: 102924 6cacbf8097a31dac9d93ccb887294f83

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_s390.deb
Size/MD5 checksum: 116412 4026e77e65aa9029e59191085f37d76e
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_s390.deb
Size/MD5 checksum: 99978 00b9bfc610eb7583b1dc35757b017d87

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.3woody3_sparc.deb
Size/MD5 checksum: 122096 0f85aa93d4e54b4a8ecc658f7e5caa78
http://security.debian.org/pool/updates/main/g/gopher/gopherd_3.0.3woody3_sparc.deb
Size/MD5 checksum: 102280 f78c3fb64a500acc9a9b3ff714d16b34

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1.dsc
Size/MD5 checksum: 547 31eead81f6846deabd19e34c620e368f
http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1.tar.gz
Size/MD5 checksum: 678218 8f159dcfc9ed25335e8bc0b87fb3e3d8

Alpha architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_alpha.deb
Size/MD5 checksum: 148342 adcd570d5fc2baf7ab4bb43d54727444

ARM architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_arm.deb
Size/MD5 checksum: 116832 ef4570961aac6e3f6e3a9b8ef640e43a

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_i386.deb
Size/MD5 checksum: 120802 a9b89709899d3c9380219887d5a89573

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_ia64.deb
Size/MD5 checksum: 168676 3ec0be402bd6057a56a094d7baf5b0cd

HP Precision architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_hppa.deb
Size/MD5 checksum: 132718 088fc0a402a26fded33bcc374810a354

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_m68k.deb
Size/MD5 checksum: 110014 c2155dd93f6d6c0cecf27d026a107766

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_mips.deb
Size/MD5 checksum: 133724 42237ccac6bd4dd4c3b8a16f6fc60c8d

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_mipsel.deb
Size/MD5 checksum: 133830 a0e6f0436a1068dd86bdac1dedf51978

PowerPC architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_powerpc.deb
Size/MD5 checksum: 129276 5c2d33e24f528e9f55d7537acc960c4e

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_s390.deb
Size/MD5 checksum: 129252 462cdf9e475ef667550c419d1d5537ca

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarge1_sparc.deb
Size/MD5 checksum: 117344 ebcfe7c3898b6015f0b5a893145746ed

These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFC6kbxW5ql+IAeqTIRAhcQAJ9U5FcISrXnrxe9qIGm/+f4s5U2AwCfY/vt
jEptBrB5UncMKRk90NHPZvE=
=CuER
-----END PGP SIGNATURE-----

--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

[SECURITY] [DSA 769-1] New gaim packages fix denial of service

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 769-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
July 29th, 2005 http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : gaim
Vulnerability : memory alignment bug
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2005-2370

Szymon Zygmunt and Michal Bartoszkiewicz discovered a memory alignment
error in libgadu (from ekg, console Gadu Gadu client, an instant
messaging program) which is included in gaim, a multi-protocol instant
messaging client, as well. This can not be exploited on the x86
architecture but on others, e.g. on Sparc and lead to a bus error,
in other words a denial of service.

The old stable distribution (woody) does not seem to be affected by
this problem.

For the stable distribution (sarge) this problem has been fixed in
version 1.2.1-1.4.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your gaim package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4.dsc
Size/MD5 checksum: 915 3bee538026c525a384cbe0865d110c78
http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4.diff.gz
Size/MD5 checksum: 31681 382649de95e8cf1417c5170d1a8a372e
http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1.orig.tar.gz
Size/MD5 checksum: 5215565 866598947a30005c9d2a4466c7182e2a

Architecture independent components:

http://security.debian.org/pool/updates/main/g/gaim/gaim-data_1.2.1-1.4_all.deb
Size/MD5 checksum: 2838720 d1b16e84e0141e8030485e36339f4faa

Alpha architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_alpha.deb
Size/MD5 checksum: 1068846 ebb2a8902f38292e34b6dc08c28a1fcd
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_alpha.deb
Size/MD5 checksum: 102374 fb9bcb085067d216f57d39a332f2820d

ARM architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_arm.deb
Size/MD5 checksum: 817860 23f78add9104cf3e5f79b7cd304fb3f7
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_arm.deb
Size/MD5 checksum: 102410 b2df8a242b943aa0d1a9b6e8148169a2

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_i386.deb
Size/MD5 checksum: 879294 d2716bd687b657f2208ad0585c13d691
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_i386.deb
Size/MD5 checksum: 102360 4120bc2abace13ca4374651db973f448

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_ia64.deb
Size/MD5 checksum: 1264312 5204cd503aed191f1cba6cfa6705f5c1
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_ia64.deb
Size/MD5 checksum: 102360 69787fd4685f53e21c4bf7c2df0ecdc6

HP Precision architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_hppa.deb
Size/MD5 checksum: 1007084 92d7692ec48a6311177f752049ced338
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_hppa.deb
Size/MD5 checksum: 102412 d11aa9dca9554e751f15e2345e724b43

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_m68k.deb
Size/MD5 checksum: 815858 ccb750c04cffe4026096da9bc1d322bd
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_m68k.deb
Size/MD5 checksum: 102480 3dc4d6008736ff7ef71960587ef349ec

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_mips.deb
Size/MD5 checksum: 855152 23092ea32cdc78dd67e50723444c38d5
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_mips.deb
Size/MD5 checksum: 102382 d6d1c8c62c8ebc2eeb4a6cb5e2ab52f1

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_mipsel.deb
Size/MD5 checksum: 846462 14cc63bc73903ffd3b391d8d3be0c326
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_mipsel.deb
Size/MD5 checksum: 102378 f0e724ffce6ce9d80c75c4f77a341a67

PowerPC architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_powerpc.deb
Size/MD5 checksum: 913460 baa3230e8857033cb9e480ecda99b01d
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_powerpc.deb
Size/MD5 checksum: 102384 fb572b59ed02992ba80dc8c6aab6db91

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_s390.deb
Size/MD5 checksum: 946240 f431a8a8595dbe5c5b26148f9504bda0
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_s390.deb
Size/MD5 checksum: 102380 d7bb41baeb1391be34b1c9642ecb22a5

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/g/gaim/gaim_1.2.1-1.4_sparc.deb
Size/MD5 checksum: 850810 73b4bdb1206ba5b0f2a5bda0cf061470
http://security.debian.org/pool/updates/main/g/gaim/gaim-dev_1.2.1-1.4_sparc.deb
Size/MD5 checksum: 102380 7d112554def1191e36f50755ca21c7f8

These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFC6dvqW5ql+IAeqTIRAiYMAJ9tbYHKcEgLovyXhZ/+5w4BRWP8awCggJOR
TqUQ0OtKA45RTSOzIrKmTAg=
=9WEt
-----END PGP SIGNATURE-----

--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Thursday, July 28, 2005

INVESTMENT ENQUIRY

HELLO,
INVESTMENT ENQUIRY ON ESTATE PROPERTIES.
It is with heartfelt hope that I write to seek your
co-operation and assistance in my desire to invest into
Estate properties in your country.
Briefly, I am an oldman and due for retirement at any
moment from now after putting many years in civil service
as Secretary Ministerial Contract Evaluation
and Implementation, in the presidency. And during this past
years in the office I was able to secure huge amount of
money from over-invoiced Government Contract Bills, through
the advantage of my position in the office. I have
been deliberating on how to invest this fund abroad in a
confidential manner untill I came to a conclusion to use it
to buy Estate Properties and lease to people while part of
it will be used for non ? speculative investments
in your country as part of measures to secure the
betterment of my retirement future, till I come over to
meet with you.
In view of this therefore, I am soliciting your confidence,
support and assistance as my partner to claim this fund for
the investment project with your name and support from the
Security Vault where I deposited it for safe keeping. This
is because we civil servants are not allowed to own and
operate Dollar Accounts, especially outside the country. As
a matter of fact, to claim this fund remains the vital
issue for now which after the successful claim of the fund
we can then invest immediately
into any Estate Property or any other areas you
may consider lucrative in your country or else where.
However, I will be happy to disclose to you the amount to
be claimed and invested as soon as I received your reply,
as I expect you to be trustworthy and kind enough to
respond positively to my ENQUIRY.
Thanks.
Dr.Kay Williams

VoFi Gets a Boost

All newsletters are sent from the domain "internet.com." Please use this domain name (not the entire "from" address, which varies) when configuring e-mail or spam filter rules, if you use them.


Search
Search internet.com
News Reviews Insights Tutorials WiMax VoIP HotSpots Forums Events Research Products Glossary About




Subscribe Now!
Wi-Fi Planet.com's Daily Newsletter
html * text
More Free Newsletters


Wi-Fi Glossary
Find a Wi-Fi Term


Find a Hotspot
by city
by State

Wi-Fi® is a registered certification mark of the Wi-Fi Alliance

internet.com
wireless channel
internet.com wireless channel
Wi-Fi Planet
HotSpotList.com
Palm Boulevard
PDAStreet
PocketPCcity
PocketPCWire
PracticallyNetworked.com
Psion Place
RIM Road
Ultrawideband Planet
Visor Village
WirelessAdWatch
Events
Research


internet.com
Developer
Downloads
International
Internet Lists
Internet News
Internet Resources
IT
Linux/Open Source
Personal Technology
Small Business
Windows Technology
xSP Resources

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers




Wi-FiPlanet News

VoFi Gets a Boost
[July 27, 2005] New technology from Meru Networks addresses call quality issues for voice over wireless IP networks.

Network Chemistry Offers Open Agent
[July 27, 2005] The security provider is putting its software into third-party access points, so existing APs can become WLAN sensors.

Netgear Builds In Security
[July 26, 2005] The infrastructure vendor has a new initiative to provide advanced (and affordable) security for home and small business PCs from the router.

10,000-Seat wVoIP Deployment in Japan
[July 25, 2005] Meru Networks today announced a deal to build a network that will bring wireless voice and data to Osaka Gas's 50 offices.

More News >>


Win a FREE Nokia 9300 smartphone.
The most anticipated device of 2005 could be yours--absolutely free. With the launch of the stylish and powerful Nokia 9300 just weeks away, we are holding a prize draw giveaway. Could you be one of the lucky winners? Enter now to find out. http://ad.doubleclick.net/clk;18792604;11637406;i?http://www.nokiaforbusiness.com/amer/9300

Interested in placing your TEXT AD HERE? Click Here

Receive news via our XML/RSS feed

Wi-Fi Planet Insights
Celerus Courts SMBs Deploying Hotspots
[July 27, 2005] With "free" software (businesses pay only for maintenance) this company's plan is to provide management tools to spur on hotspots in new locations.

Sputnik's Temporary WLANs
[July 26, 2005] Firm is working to support not just hotspots but also short-lived networks for everything from emergencies to big events, all without putting strain on the customer.

Wi-Fi at the War Office
[July 25, 2005] All Points Logistics is an integrator that is striking gold with military and government deployments after earning a certification from the Department of Defense, but it won't be alone for long.

Rio Rancho: Innovations for Voice
[July 22, 2005] Making VoWi-Fi work citywide takes some tricks and special deals.

More Insights >>

Wi-Fi Planet Insights
KoolSpan (Part 2: The Test)
[July 22, 2005] In Part 1 we described this secure access product's architecture, our test network configuration, and client installation. This week, we test the product in the office and on the road.

KoolSpan (Part 1: The Tools)
[July 15, 2005] KoolSpan's novel SecurEdge "Lock and Key" solution provides simple secure access over any kind of LAN, wired or wireless, local or remote.

HomeNet Manager 2.0
[July 14, 2005] This try-before-you-buy utility aims to simplify networking tasks by providing a single place from which to view and manage network devices, share resources and troubleshoot problems.

Lenovo ThinkPad X41 Laptop
[June 15, 2005] Renown for its quality, design and support, ThinkPad continues its track record with the X41. But with its hefty price, you'll have to part with some gold of your own.

More Reviews >>

BVS has released Yellowjacket(R) version 4.0 software for HP iPAQ PocketPC(R) 2003 platform. FREE for all Yellowjacket(R)802.11b users, the update includes new analysis screens likeSignal-to-Noise Ratio (includes per channel noise readings),Channel Frequency Response and WISP Antenna Alignment.Screen JPEG snapshots supported for all analysis screens,improved MAC listing and spectrum analysis screens. http://www.bvsystems.com

Interested in placing your TEXT AD HERE? Click Here

Wi-Fi Planet Tutorials
Mesh Networking a Viable Alternative
[July 14, 2005] Mesh networking is making its way into municipal Wi-Fi networks, but use within enterprises is questionable. Learn the ins and outs of mesh networking and see if it fits into your wireless deployment.

WEP, WPA and Wireless Security
[June 30, 2005] Wireless networking is relatively easy to setup, but it's also easy to forget the importance of protecting yourself. PracticallyNetworked dissect WEP and WPA and offers some commonsense advice.

WISPs: Pricing to Survive
[June 14, 2005] If you have only one price for your service, you're not offering enough. Premium pricing and services are essential to WISP survival.

Make a Wireless Peer-to-Peer Connection
[May 19, 2005] Tips and tricks for setting up a P2P wireless network with no access point, and with wireless cards from different vendors.

More Tutorials >>



JupiterWeb networks:

internet.comearthweb.comDevx.comClickZGraphics.com

Search JupiterWeb:

Jupitermedia Corporation has four divisions:
JupiterWeb, JupiterResearch, JupiterEvents and JupiterImages

Copyright 2005 Jupitermedia Corporation All Rights Reserved.
Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Jupitermedia Corporate Info | Newsletters | Tech Jobs | E-mail Offers

Business Resources From Business.com
» Computer Networking

» Fixed Wireless Network Equipment

» Access Points

» Wireless Telecommunications Equipment and Supplies

» Bluetooth Wireless Telecommunications

SonicWall eyes SMB market with upcoming SSL VPN gear

NETWORK WORLD NEWSLETTER: TIM GREENE ON VPNS
07/28/05
Today's focus: SonicWall eyes SMB market with upcoming SSL VPN
gear

Dear security.world@gmail.com,

In this issue:

* SonicWall SSL-VPN 200 and SSL-VPN 2000 out in Q3
* Links related to VPNs
* Featured reader resource
_______________________________________________________________
This newsletter is sponsored by Tacit Networks
Network World Executive Guide: Staying Focused on the Moving
Target that is Storage

Keeping pace with evolving storage strategies, architectures,
and trends is not unlike keeping pace with your organizations
underlying capacity needs. From ILM strategies to SAN management
to the threat of those USB memory sticks, this Network World
Executive Guide will help you stay focused on the moving target
that is Storage. Register now and get a free copy of Network
World's Storage Executive Guide.
http://www.fattail.com/redir/redirect.asp?CID=108909
_______________________________________________________________
SERVER BLADE BUYER'S GUIDE

Updated constantly, NW Fusion's Buyer's Guides give you the
latest information on product capabilities, features,
requirements, pricing and more. Not sure which server blade to
buy? Our server blade buyer's guide gives you the latest product
specs and let's you compare with our compare-o-matic. Click
here:
http://www.fattail.com/redir/redirect.asp?CID=108736
_______________________________________________________________

Today's focus: SonicWall eyes SMB market with upcoming SSL VPN
gear

By Tim Greene

SonicWall is coming out with SSL VPN gear later this year for
small and midsize businesses at prices it hopes will be a big
draw.

The two devices the company will have available in the third
quarter of this year are called the SSL-VPN 200 and the SSL-VPN
2000.

While some might say it's pretty late to get into the SSL game,
given the recent mergers and acquisitions among SSL vendors,
SonicWall may be in a good position because it is already
established as a security vendor and because it isn't trying to
compete for the largest customers. The latter keeps it out of
the sights of the biggest competitors such as F5, Aventail,
Cisco, Juniper and Nortel.

The 200 is a desktop appliance with five 10/100 Ethernet ports
and the 2000 is a rack-mounted device with four ports. The
company hasn't set prices for them yet, but expects the range
for the 200 to be somewhere between $500 and $1,500 and between
$1,500 and $5,000 for the 2000.

These prices put it in a category with the relatively young SSL
vendor enKoo, whose philosophy has been to sell pared back SSL
gear that is inexpensive enough for small organizations. Like
enKoo, SonicWall doesn't have a lot of bells and whistles such
as software to check that computers trying to establish SSL
connections to a SonicWall box meet security policies. But that
may be OK with the small businesses that SonicWall is targeting,
as they may not be aware of the capabilities of higher end SSL
VPN equipment.

SonicWall says it will have fewer tiers of license packages, so
they can go from a license for, say, five users to a license for
unlimited users with fewer steps in between. The limit of
concurrent users will be set by limitations of the hardware, but
the company says it hasn't tested for those limits yet.
SonicWall says it expects the 200 to support about 20 concurrent
users and the 2000 to support about 200. Low-end users will want
to take a look at these devices.

The top 5: Today's most-read stories

1. 2005 Salary Survey
<http://www.networkworld.com/nlvpn4036>

2. Cisco nixes conference session on hacking IOS router code
<http://www.networkworld.com/nlvpn4037>

3. Verizon joins managed security game
<http://www.networkworld.com/nlvpn3772>

4. Schools battle personal data hacks
<http://www.networkworld.com/nlvpn4038>

5. VoIP security threats: Fact or fiction?
<http://www.networkworld.com/nlvpn3773>

Today's most forwarded story:

The ROI of VoIP
<http://www.networkworld.com/research/2005/071105-voip.html>
_______________________________________________________________
To contact: Tim Greene

Tim Greene is a senior editor at Network World, covering virtual
private networking gear, remote access, core switching and local
phone companies. You can reach him at <mailto:tgreene@nww.com>.
_______________________________________________________________
This newsletter is sponsored by Tacit Networks
Network World Executive Guide: Staying Focused on the Moving
Target that is Storage

Keeping pace with evolving storage strategies, architectures,
and trends is not unlike keeping pace with your organizations
underlying capacity needs. From ILM strategies to SAN management
to the threat of those USB memory sticks, this Network World
Executive Guide will help you stay focused on the moving target
that is Storage. Register now and get a free copy of Network
World's Storage Executive Guide.
http://www.fattail.com/redir/redirect.asp?CID=108908
_______________________________________________________________
ARCHIVE LINKS

Breaking VPN news from Network World, updated daily:
http://www.networkworld.com/topics/firewalls.html

Archive of the VPN newsletter:
http://www.networkworld.com/newsletters/vpn/index.html
_______________________________________________________________
FEATURED READER RESOURCE
SIX TIPS FOR GETTING WHAT YOU DESERVE

Before you go in for your next annual review or promotion
interview, you would be wise to consider these tips for ensuring
you've got the right stuff to move ahead. Network executives
offer advice to help you gun for that next promotion and fatten
up your paycheck. Click here:
<http://www.networkworld.com/you/2005/072505-salary-side2.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

3Com patches wireless access point


NETWORK WORLD NEWSLETTER: JASON MESERVE'S VIRUS AND BUG PATCH
ALERT
07/28/05
Today's focus: 3Com patches wireless access point

Dear security.world@gmail.com,

In this issue:

* Patches from 3Com, FreeBSD, OpenPKG, others
* Beware latest Sdbot and Mytob variants
* Threat alert highlights vulnerabilities in backup software
* Links related to Virus and Bug Patch Alert
* Featured reader resource
_______________________________________________________________
This newsletter is sponsored by Tacit Networks
Network World Executive Guide: Staying Focused on the Moving
Target that is Storage

Keeping pace with evolving storage strategies, architectures,
and trends is not unlike keeping pace with your organizations
underlying capacity needs. From ILM strategies to SAN management
to the threat of those USB memory sticks, this Network World
Executive Guide will help you stay focused on the moving target
that is Storage. Register now and get a free copy of Network
World's Storage Executive Guide.
http://www.fattail.com/redir/redirect.asp?CID=108907
_______________________________________________________________
CYBERSLACKING - IT COSTS

To the tune of $178 billion annually, according to a recent
study. Employees, at work, are reading the news, checking
personal e-mail, conducting online banking, travel and shopping
more than you might realize. How much time? Click here for more:
http://www.fattail.com/redir/redirect.asp?CID=108714
_______________________________________________________________

Today's focus: 3Com patches wireless access point

By Jason Meserve

There's some wild goings on at this week's Black Hat gathering
in Las Vegas. Lawsuits are flying over what has been disclosed
in one of the conference sessions:

Furor over Cisco IOS router exploit erupts at Black Hat

Although Cisco and Internet Security Systems had abruptly
cancelled a planned technical talk and demo at the Black Hat
Conference to reveal how unpatched Cisco routers can be remotely
compromised, the researcher who had originally uncovered the
problem went ahead with the talk anyway, igniting a spate of
lawsuits against himself and the Black Hat Conference. Network
World, 07/28/05.
<http://www.networkworld.com/nlvirusbug4047>

We're hoping to have more on this legal tussle with Test
Alliance member Rodney Thayer in Monday's Network World Radio
program.

Today's bug patches and security alerts:

3Com patches wireless access point

3Com has released an update for its Office Connect Wireless 11g
Access Point that fixes a flaw in the Web-based administrative
interface. An attacker could exploit the flaw to gather device
configuration information. For more, go to:
<http://webprd1.3com.com/swd/jsp/user/index.jsp?id=OCWAP15>
**********

FreeBSD, OpenPKG patch zlib

A flaw in the way zlib, a file compression/decompression
utility, handles compressed files could be exploited to crash
the application. For more, go to:

FreeBSD:
<http://www.networkworld.com/go2/0725bug2a.html>

OpenPKG:
<http://www.openpkg.org/security/OpenPKG-SA-2005.014-zlib.html>
**********

Linux vendors patch ClamAV

A number of integer overflows have been found in the ClamAV
anti-virus application. An attacker could exploit these flaws
using specially crafted files. The exploit could be used to run
malicious code on the affected machine. For more, go to:

Gentoo:
<http://security.gentoo.org/glsa/glsa-200507-25.xml>

Mandriva:
<http://www.mandriva.com/security/advisories?name=MDKSA-2005:125>
**********

More Mozilla Suite, Firefox fixes available

A number of Linux vendors have released update for the Mozilla
Suite and Firefox browser based on multiple flaws found in the
underlying code for both applications. Attackers could gain
elevated privileges by exploiting the flaws. For more, go to:

Gentoo (Mozilla Suite):
<http://security.gentoo.org/glsa/glsa-200507-24.xml>

Ubuntu (Firefox):
<https://www.ubuntulinux.org/support/documentation/usn/usn-149-3>

Ubuntu (Mozilla Suite):
<https://www.ubuntulinux.org/support/documentation/usn/usn-155-1>
**********

Gentoo, Mandriva release Shorewall packages

According to the Gentoo advisory, "A vulnerability in Shorewall
allows clients authenticated by MAC address filtering to bypass
all other security rules." For more, go to:

Gentoo:
<http://security.gentoo.org/glsa/glsa-200507-20.xml>

Mandriva:
<http://www.mandriva.com/security/advisories?name=MDKSA-2005:123>
**********

Debian patches heartbeat

Heartbeat, a sub-system for High-Availability Linux, does not
create temporary files in a secure fashion. An attacker could
exploit this using a symlink attack. For more, go to:
<http://www.debian.org/security/2005/dsa-761>

Debian releases fix for affix

According to an alert from Debian, "Kevin Finisterre discovered
two problems in the Bluetooth FTP client from affix, user space
utilities for the Affix Bluetooth protocol stack." For more, go
to:
<http://www.debian.org/security/2005/dsa-762>
**********

Fedora issues krb5 patch

Two flaws in the MIT Kerberos 5 system (krb5) could be exploited
to run arbitrary code on the affected machine. For more, go to:
<http://www.securityfocus.com/archive/1/406384/30/30/threaded>
**********

Gentoo, Ubuntu release fetchmail fixes

A buffer overflow in the popular fetchmail e-mail client could
be exploited in a denial-of-service attack or to potentially
execute arbitrary code. For more, go to:

Gentoo:
<http://security.gentoo.org/glsa/glsa-200507-21.xml>

Ubuntu:
<https://www.ubuntulinux.org/support/documentation/usn/usn-153-1>
**********

Today's roundup of virus alerts:

W32/Sdbot-AAY -- A new Sdbot variant that spreads through
network shares and allows backdoor access via IRC. It drops
"edit.exe" and "RDRIV.SYS" on the infected host. (Sophos)

W32/Sdbot-ZO -- Our second Sdbot worm of the day drops
"burndl32.exe" in the infected machine's Windows System folder.
It too allows backdoor access via IRC. (Sophos)

W32/Sdbot-ABI -- Sdbot number three for today has similar
capabilities to its predecessors. Its main differentiating
characteristic is the file it drops: "clipserv.exe". (Sophos)

W32/Mytob-HM -- This new Mytob e-mail worm can allow backdoor
access through IRC. It drops "yahooicons.exe" on the target host
when a recipient opens the infected attachment, which is usually
a double extension file. (Sophos)

W32/Mytob-DW -- Another Mytob e-mail worm variant. This one
tries to exploit the Windows LSASS vulnerability in its attempt
to penetrate a host. It installs itself as "taskgmr.exe" in the
Windows System directory. (Sophos)

W32/Mytob-BV -- Yet another Mytob variant. This one spreads
through e-mails that look like some sort of account warning from
a system administrator. The attached file usually has a double
extension to fool users. When executed, Mytob-BV drops
"TimeManager.exe" in the Windows System folder. (Sophos)

W32/Mytob-DX -- The fourth Mytob variant of the day drops two
files in the Windows System folder: "taskgmr32.exe" and
"winnet32.exe". It too allows backdoor access through IRC and
limits access to security Web sites by modifying the Windows
HOSTS file. (Sophos)

Troj/Mdrop-F -- A Trojan that drops "veja_fotos.exe" in a
temporary folder. No word on how it spreads. (Sophos)

Troj/Myftu-H -- A password-stealing Trojan that sends its bounty
via HTTP. The key file that it drops on the infected host is
"cMovie.exe" in the Program Files folder. (Sophos)

W32/Rbot-AJA -- An Rbot variant designed to steal information
from the infected host and participate in Internet-based
denial-of-service attacks. It spreads through network shares by
exploiting a number of known Windows vulnerabilities, all of
which have patches available. (Sophos)

Riot Immort-51 -- An old-school DOS virus that infects COM
files. It may display the message "iMMoRTaL.510 Encrypted!!}"
(Sophos)

W32/Randon-AO -- A Trojant that tries to exploit the Windows
LSASS vulnerability as it spreads through network shares. It
drops a number of files on its host and can provide backdoor
access via IRC channels. (Sophos)

Troj/Bancban-DY -- Another worm that targets the username and
password data for Brazilian banking sites. It sends the
collected data to a predefined Web site. (Sophos)
**********

From the interesting reading department:

Threat alert highlights vulnerabilities in backup software

The SANS Institute Monday reported 422 new Internet security
vulnerabilities discovered during the second quarter, up nearly
11% from the first quarter, with weaknesses in popular backup
software highlighting the report. NetworkWorld.com, 07/25/05.
<http://www.networkworld.com/news/2005/072505-backup.html?nl>

The top 5: Today's most-read stories

1. 2005 Salary Survey
<http://www.networkworld.com/nlvirusbug4048>

2. Cisco nixes conference session on hacking IOS router code
<http://www.networkworld.com/nlvirusbug4049>

3. Verizon joins managed security game
<http://www.networkworld.com/nlvirusbug4050>

4. Schools battle personal data hacks
<http://www.networkworld.com/nlvirusbug4051>

5. VoIP security threats: Fact or fiction?
<http://www.networkworld.com/nlvirusbug4052>

Today's most forwarded story:

The ROI of VoIP
<http://www.networkworld.com/research/2005/071105-voip.html>
_______________________________________________________________
To contact: Jason Meserve

Jason Meserve is the Multimedia Editor at Network World and
writes about streaming media, search engines and IP Multicast.
Jason can be reached at <mailto:jmeserve@nww.com>. Check out his
Multimedia Exchange weblog at:
<http://www.networkworld.com/weblogs/multimedia/>

Check out our weekly Network World Radio program at:
<http://www.networkworld.com/radio/>
_______________________________________________________________
This newsletter is sponsored by Tacit Networks
Network World Executive Guide: Staying Focused on the Moving
Target that is Storage

Keeping pace with evolving storage strategies, architectures,
and trends is not unlike keeping pace with your organizations
underlying capacity needs. From ILM strategies to SAN management
to the threat of those USB memory sticks, this Network World
Executive Guide will help you stay focused on the moving target
that is Storage. Register now and get a free copy of Network
World's Storage Executive Guide.
http://www.fattail.com/redir/redirect.asp?CID=108906
_______________________________________________________________
ARCHIVE LINKS

Virus and Bug Patch Alert archive:
http://www.networkworld.com/newsletters/bug/index.html

Breaking security news, updated daily
http://www.networkworld.com/topics/security.html
_______________________________________________________________
FEATURED READER RESOURCE

SIX TIPS FOR GETTING WHAT YOU DESERVE

Before you go in for your next annual review or promotion
interview, you would be wise to consider these tips for ensuring
you've got the right stuff to move ahead. Network executives
offer advice to help you gun for that next promotion and fatten
up your paycheck. Click here:

<http://www.networkworld.com/you/2005/072505-salary-side2.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005