|
Network SecurityWelcome to our security bulletin for October 2005; TippingPoint, a division of 3Com, has recently discovered a Veritas NetBackup vulnerability which has the potential to allow remote users to execute malicious code. Affected versions are NetBackup 3.4, 4.5, 5.0, 5.1 and 6.0. More details, and patches available here http://seer.support.veritas.com/docs/279085.htm Serious new MS Windows problem has been uncovered, currently being tracked by Internet Security Systems. This could allow complete compromise of Windows 2000 systems. Also, a further issue has been found with DirectShow, which could render the system vulnerable through use of a malicious video file. Versions affected: Microsoft Windows NT 4.0 up to Service Pack 6a inclusive,Microsoft Windows 2000 up to Service Pack 4 inclusive, Microsoft Windows XP up to Service Pack 2 inclusive, Microsoft Windows Server 2003 up to Service Pack 1 inclusive. Further details and patches from ISS at http://xforce.iss.net/xforce/alerts/id/206 The US Federal Trade Commission has launched Operation Spam Zombies, a campaign to make Internet service providers aware of what they can do about the large number of "zombies" (compromised computers working on behalf of third parties) on their networks. Also from theregister.co.uk, a new security threat has emerged for the PlayStation Portable. One of the download tools used to downgrade the embedded software from version 2.0 to 1.50 is actually a Trojan which deletes system files and renders the PSP unusable. More details at http://www.theregister.co.uk/2005/10/07/psp_trojanMajor Security Threat - Web Browsers These Gecko based browsers are vulnerable as they support Internation
Domain Names (web addresses containing non-standard characters such as
accents or non-Latin alphabets). A web page could be created with a
hyperlink containing a long string of such non-standard characters which
would cause an overflow in the dynamic memory allocation of the system.
This could result in either denial of service or even allow malicious
code to be executed.
Mozilla has issued a patch Other New Vulnerabilities NOD32 AntiVirus System - download latest version at http://www.nod32.com/home/home.htm. Cisco Content Server Switches (CSS11500 & CSS11501) More details and patch available at http://www.cisco.com/warp/public/707/cisco-sn-20050908-css.shtmlOld security bulletins are stored in our archive If you have a security issue or are looking for Internet security services, contact us to see what we can do for you. |
|
|||||||||||||||||||||||||||||||||||||||
| © 2009 Cambridge Computer Support - The computer networks & data recovery experts |
| Cambridge Computer Support Contact Us Networks Services Products Support |