January 2003
Welcome to January's edition of Internet Security News, the monthly risks bulletin detailing the
latest Internet software and system vulnerabilities from NTA Monitor, a leading IT security testing
company. It provides a convenient way to keep up to date with the fast changing world of IT security;
this month's edition includes a total of 6 risk issues:
4 High, 1 Medium and 1 Low .
RealNetworks Helix Server in a bounds checking twist
(
High risk)
Malicious request by a client can inject code to be executed by server
30th January 2003
Read More
Netscape mail fails to delete properly
(
Low risk)
Netscape's mail client does not delete mail properly, even when eliminated from the trash folder.
30th January 2003
Read More
Five reasons to upgrade MySQL
(
Medium risk)
A variety of flaws from crashing the SQL server, to executing arbitrary commands and impersonating other database users. Two flaws are client side.
30th January 2003
Read More
Sun Cobalt RaQ 4 Server Security Hardening Package failure
(
High risk)
A bug in a .cgi script allows execution of commands with super user privilegesre
30th January 2003
Read More
Windows XP Shell buffer overflow bug
(
High risk)
A bug allows specifically crafted sound files to contain code to be executed when a user rests the mouse pointer on them
30th January 2003
Read More
BitKeeper remote command execution vulnerability
(
High risk)
A flaw allows anonymous attackers to execute arbitrary code on the BitKeeper software
15th January 2003
Read More
This bulletin is produced as a by-product of ongoing research carried out to develop NTA Monitor's Internet security
testing service, Regular Monitor. NTA are a full-service Internet security testing company with a comprehensive range of
testing services including: