Security

Novell patch fixes password synch feature

Novell released a host of patches and updates this week. Exterminator takes a look at these fixes, along with Microsoft and Trend Micro updates and information.


Exterminator brings you weekly updates on bug fixes, virus recovery, service release announcements, and security notices for Windows, Novell, Linux, and other systems.

Microsoft Security Bulletin (MS01-033)
Regarding: Microsoft Index Server 2.0 and Indexing Service in Windows 2000
Date Posted: June 18, 2001
Patch URL:Click here to download the patch for NT 4.0.
Patch URL:Click here to download the patch for Windows 2000.
Information URL:Click here for more information.

One of the ISAPI extensions that’s installed with IIS is idq.dll, a part of Index Server that supports administrative scripts and Internet Data Queries. A security hole exists because idq.dll contains an unchecked buffer in code that deals with input URLs, which could allow an attacker to create a buffer overrun.

Novell issues
Regarding: Account Management 2.1
Date Posted: June 19, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

Novell has released a patch to make your Account Management for Windows 2000 Password Synchronization feature work correctly. You will need to upgrade both servers and workstations with this patch.

Regarding: GroupWise, GroupWise 6
Date Posted: June 19, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch provides a group of view files for use with GroupWise 6 on Macintosh.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This support pack updates all the components in NDS Authentication Services (NDS-AS) v3.0.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1, OnDemand, OnDemand 1.0, OnDemand 1.5, ZENworks 2
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch resolves an Abend issue that occurs when users install ZFD2SP1. You must install the STORER.JAR from ZFD2PT4 before using this patch.

Regarding: Novell Client 4.8 for Windows NT/2000, Novell Clients
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch for the 4.8 client install contains three fixes for the NWSETUP.DLL file.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This IBM WebSphere version 3.5.3 Application Server Standard Fixpack for NetWare replaces all the executables without destroying the configuration files. It also lets you uninstall the update and return the executables to their original state.

Virus updates from Trend Micro
Virus/Worm: TROJ_MADBOX.B
Posted: June 18, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Virus/Worm: JAVA_STORM.A
Posted: June 19, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Virus/Worm: W97M_GOGA.A
Posted: June 20, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Stay current on virus information
Are you keeping up with the latest virus information from Microsoft and Novell? If not, visit the Exterminator archive for past columns with information on bugs and patches you may have missed.

 

Exterminator brings you weekly updates on bug fixes, virus recovery, service release announcements, and security notices for Windows, Novell, Linux, and other systems.

Microsoft Security Bulletin (MS01-033)
Regarding: Microsoft Index Server 2.0 and Indexing Service in Windows 2000
Date Posted: June 18, 2001
Patch URL:Click here to download the patch for NT 4.0.
Patch URL:Click here to download the patch for Windows 2000.
Information URL:Click here for more information.

One of the ISAPI extensions that’s installed with IIS is idq.dll, a part of Index Server that supports administrative scripts and Internet Data Queries. A security hole exists because idq.dll contains an unchecked buffer in code that deals with input URLs, which could allow an attacker to create a buffer overrun.

Novell issues
Regarding: Account Management 2.1
Date Posted: June 19, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

Novell has released a patch to make your Account Management for Windows 2000 Password Synchronization feature work correctly. You will need to upgrade both servers and workstations with this patch.

Regarding: GroupWise, GroupWise 6
Date Posted: June 19, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch provides a group of view files for use with GroupWise 6 on Macintosh.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This support pack updates all the components in NDS Authentication Services (NDS-AS) v3.0.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1, OnDemand, OnDemand 1.0, OnDemand 1.5, ZENworks 2
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch resolves an Abend issue that occurs when users install ZFD2SP1. You must install the STORER.JAR from ZFD2PT4 before using this patch.

Regarding: Novell Client 4.8 for Windows NT/2000, Novell Clients
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This patch for the 4.8 client install contains three fixes for the NWSETUP.DLL file.

Regarding: NetWare 5.1, Novell Small Business Suite 5.1
Date Posted: June 20, 2001
Patch URL:Click here to download the patch.
Information URL:Click here for more information.

This IBM WebSphere version 3.5.3 Application Server Standard Fixpack for NetWare replaces all the executables without destroying the configuration files. It also lets you uninstall the update and return the executables to their original state.

Virus updates from Trend Micro
Virus/Worm: TROJ_MADBOX.B
Posted: June 18, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Virus/Worm: JAVA_STORM.A
Posted: June 19, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Virus/Worm: W97M_GOGA.A
Posted: June 20, 2001
Risk: Low
Information URL:Click here for more information on this virus.

Stay current on virus information
Are you keeping up with the latest virus information from Microsoft and Novell? If not, visit the Exterminator archive for past columns with information on bugs and patches you may have missed.

 

Editor's Picks

Free Newsletters, In your Inbox