Video | Business Headlines | Internet | Science | Scientific Ethics | Technology | Search

 


New MS Vulnerabilities Information from Symantec

New MS Vulnerabilities Information from Symantec

Symantec currently provides system and network protection for three new vulnerabilities announced today by Microsoft: MS ASN.1 Integer Overflow, Cumulative Security Update for Internet Explorer and Windows Internet Naming Service (WINS) Buffer Overflow.

These vulnerabilities have been reviewed by Symantec Security Response, and Symantec recommends that users update the services affected, via the Microsoft windows update Website. Symantec also recommends that users implement best security practices such as restricting external access to all ports and services that are not explicitly intended to be accessible by remote parties. This action will limit exposure to these and other latent vulnerabilities. If appropriate, firewalls should also be deployed on individual systems to restrict access and network intrusion detection systems (NIDS) should be deployed to monitor network traffic for any suspicious or anomalous activity.

Microsoft Vulnerabilities Overview

· MS ASN.1 Integer Overflow (828028) -- Critical Rating The buffer overflow vulnerability in Microsoft ASN.1 could allow an attacker who successfully exploited this vulnerability to execute code with system privileges on an affected system. The attacker could then take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges.

· Cumulative Security Update for Internet Explorer (832894) -- Critical Rating For the Internet Explorer vulnerability, systems administrators should apply the security update immediately.

· Windows Internet Naming Service (WINS) Buffer Overflow (830352) -- Important Rating The vulnerability in Windows Internet Naming Service (WINS) could allow an attacker who sent a series of specially-crafted packets to a WINS server to cause the service to fail on Windows Server 2003. This could potentially cause a denial of service, and the service would have to be manually restarted to restore functionality. An attack on Windows 2000 and Windows NT 4.0 could cause a degradation in performance. WINS will then return to normal levels of functionality. A number of mitigating factors exist for this vulnerability. For example, the WINS service is not installed by default. In addition, when running on Windows Server 2003, WINS will automatically restart if attacked.

More information can be found at http://www.microsoft.com/security/security%5Fbulletins/.

Symantec Solutions Protecting Against New Microsoft Vulnerabilities Symantec Security Solutions

* Symantec DeepSight Threat Management System/Symantec DeepSight Alert Services - For Symantec DeepSight Threat Management System, the vulnerabilities have been summarized on the Daily Summary Reports sent to customers. Symantec is closely monitoring global activity for signs of attack and will deliver additional notifications as required. For Symantec DeepSight Alert Services, a notification has been distributed on the new vulnerabilities.

* Symantec Managed Security Services - MSS Managed Systems running Windows Operating Systems are not susceptible to the WINS vulnerability as those components & services are disabled as part of our standard baseline and system hardening process. MSS Managed Systems running Windows Operating Systems are vulnerable to the ASN.1 vulnerability. Due to the potential impact of this vulnerability, all affected systems are currently being updated via MSS emergency patch rollout procedures. MSS has contacted managed customers about this vulnerability and will continue to update customers on the status of this vulnerability via the MSS Secure Internet Interface.

* Symantec Gateway Security/Symantec Enterprise Firewall -- By default, Symantec's full application inspection firewall technology protects against the Microsoft ASN.1 and WINS vulnerabilities.

* Symantec Client Security/AntiVirus Solutions - Symantec has created heuristic detection for the Microsoft ASN.1 vulnerability.

* Symantec ManHunt - Symantec has released a signature to protect against the WINS vulnerability. ends


© Scoop Media

 
 
 
 
 
Business Headlines | Sci-Tech Headlines

 

Sky City : Auckland Convention Centre Cost Jumps By A Fifth

SkyCity Entertainment Group, the casino and hotel operator, is in talks with the government on how to fund the increased cost of as much as $130 million to build an international convention centre in downtown Auckland, with further gambling concessions ruled out. The Auckland-based company has increased its estimate to build the centre to between $470 million and $530 million as the construction boom across the country drives up building costs and design changes add to the bill.
More>>

ALSO:

RMTU: Mediation Between Lyttelton Port And Union Fails

The Rail and Maritime Union (RMTU) has opted to continue its overtime ban indefinitely after mediation with the Lyttelton Port of Christchurch (LPC) failed to progress collective bargaining. More>>

Earlier:

Science Policy: Callaghan, NSC Funding Knocked In Submissions

Callaghan Innovation, which was last year allocated a budget of $566 million over four years to dish out research and development grants, and the National Science Challenges attracted criticism in submissions on the government’s draft national statement of science investment, with science funding largely seen as too fragmented. More>>

ALSO:

Scoop Business: Spark, Voda And Telstra To Lay New Trans-Tasman Cable

Spark New Zealand and Vodafone, New Zealand’s two dominant telecommunications providers, in partnership with Australian provider Telstra, will spend US$70 million building a trans-Tasman submarine cable to bolster broadband traffic between the neighbouring countries and the rest of the world. More>>

ALSO:

More:

Statistics: Current Account Deficit Widens

New Zealand's annual current account deficit was $6.1 billion (2.6 percent of GDP) for the year ended September 2014. This compares with a deficit of $5.8 billion (2.5 percent of GDP) for the year ended June 2014. More>>

ALSO:

Still In The Red: NZ Govt Shunts Out Surplus To 2016

The New Zealand government has pushed out its targeted return to surplus for a year as falling dairy prices and a low inflation environment has kept a lid on its rising tax take, but is still dangling a possible tax cut in 2017, the next election year and promising to try and achieve the surplus pledge on which it campaigned for election in September. More>>

ALSO:

Job Insecurity: Time For Jobs That Count In The Meat Industry

“Meat Workers face it all”, says Graham Cooke, Meat Workers Union National Secretary. “Seasonal work, dangerous jobs, casual and zero hours contracts, and increasing pressure on workers to join non-union individual agreements. More>>

ALSO:

Get More From Scoop

 
 
Standards New Zealand

Standards New Zealand
 
 
 
 
 
 
 
 
Sci-Tech
Search Scoop  
 
 
Powered by Vodafone
NZ independent news