VERITAS Software Technical Advisory (fwd)

From: Dave Ahmad (daat_private)
Date: Tue Jan 28 2003 - 13:39:07 PST

  • Next message: Fozzy [Hackademy Audit]: "[Full-Disclosure] MIT Kerberos FTP client remote shell commands execution"

    David Mirza Ahmad
    Symantec
    
    0x26005712
    8D 9A B1 33 82 3D B3 D0 40 EB  AB F0 1E 67 C6 1A 26 00 57 12
    
    ---------- Forwarded message ----------
    Return-Path: <Technical_Servicesat_private>
    Delivered-To: daat_private
    Received: (qmail 1157 invoked by alias); 26 Jan 2003 04:53:18 -0000
    Received: (qmail 1154 invoked from network); 26 Jan 2003 04:53:18 -0000
    Received: from maillist.east.veritas.com (HELO nsmg.veritas.com)
        (207.30.27.51)
      by mail.securityfocus.com with SMTP; 26 Jan 2003 04:53:18 -0000
    X-Mailer: UnityMail
    Errors-To: <Technical_Servicesat_private>
    Originator: <Technical_Servicesat_private>
    X-UnityID:
        <20030125234152.AZECLBCXPACACGUhrolstsrv0.79869at_private
        >
    X-UnityUser: Veritas
    X-Mailer-Version: 4.0.425
    From: "Technical_Services" <Technical_Servicesat_private>
    To: "Technical_Services" <Technical_Servicesat_private>
    Subject: VERITAS Software Technical Advisory
    Date: Sat, 25 Jan 2003 23:41:52 -0500
    MIME-Version: 1.0
    Content-Type: text/plain;
    	charset="iso-8859-1"
    Content-Transfer-Encoding: 7bit
    Thread-Index: AcLE9T8raU1OGz7/Sy+uMUii6EjUZw==
    Content-Class: urn:content-classes:message
    X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
    
    Dear Valued VERITAS Software Customer,
    
    VERITAS Technical Support has recently discovered that Backup Exec 9.0
    servers may be susceptible to infection by the "W32.SQLExp.Worm" (also
    known as "SQL Slammer" discovered 1/24/2003). This TechAlert is to
    inform you of the circumstances and/or conditions under which this
    problem could occur and to provide the remedy for it. This alert was
    generated because product quality and customer responsiveness are
    consistent VERITAS Software hallmarks. While initial indications are
    that this worm is not likely to directly threaten your data, any issues
    that could potentially affect your data, no matter how rare, are viewed
    as extremely serious.
    
    This worm can affect any server running Microsoft SQL and/or Microsoft
    MSDE 2000 components. Backup Exec for Windows 9.0 servers may be
    susceptible as it includes MSDE 2000 components with the installation
    that are affected by this virus. This issue may be resolved by running
    the Microsoft patch identified in the link below. The Microsoft patch
    will work with the version of MSDE included with Backup Exec 9.0. SQL
    2000 and other installations of MSDE may require additional patches. For
    more information, refer to the documentation accompanying the Microsoft
    patch which can be downloaded from the following link:
    
    http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40602
    
    It will be necessary to reboot after this patch is installed.
    
    For more information, please visit:
    
    Microsoft security bulletin:
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-039.asp
    
    
    Symantec Security Response information:
    http://www.symantec.com/avcenter/venc/data/w32.sqlexp.worm.html
    
    VERITAS TechNote:
    http://support.veritas.com/docs/254244
    
     Sincerely,
    
     VERITAS Software Corporation
    
    
    ___________________________________________________________
    **************
    *PLEASE NOTE:*
    **************
    Email format restrictions may not allow a URL to fit on one line.  Thus,
    when you click the URL line in the email message, you may get a browser
    error (e.g., non-existent link). If the URL does not seem to work,
    please make certain you select, copy, and then paste the entire link
    address into your browser's target address field.
    ____________________________________________________________
    
    How to use this mailing list..
    
    You received this e-mail newsletter as a result of your registration on
    the VERITAS Email Notification System. To fully unsubscribe, send a
    blank email to mailto:@maillist.support.veritas.com (if the
    email address is not clickable, simply copy the text to the right of the
    'mailto:' command and paste it into your email application and hit
    send).
    
    To further define your communication preferences with VERITAS including
    subscriptions and removals from any Technical Support list, please
    visit:
    xxxxxxxxat_private">http://maillist.support.veritas.com/infotype_select.asp?EmailAddress=xxxxxxxxat_private
    
    
    THIS DOCUMENT IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY. The
    information contained in this document represents the current view of
    VERITAS Software Corporation on the issues discussed as of the date of
    publication. Because VERITAS must respond to change in market
    conditions, it should not be interpreted to be a commitment on the part
    of VERITAS and VERITAS cannot guarantee the accuracy of any information
    presented after the date of publication. INFORMATION PROVIDED IN THIS
    DOCUMENT IS PROVIDED 'AS IS' WITHOUT WARRANTY OF ANY KIND, EITHER
    EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES
    OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND FREEDOM FROM
    INFRINGEMENT. The user assumes the entire risk as to the accuracy and
    the use of this document. This document may be copied and distributed
    subject to the following conditions:
    1. All text must be copied without modification and all pages must be
    included.
    2. All copies must contain VERITAS Software Corporation's copyright
    notice and any other notices provided therein.
    3. This document may not be distributed for profit.
    
    Sincerely,
    VERITAS Software Corporation
    



    This archive was generated by hypermail 2b30 : Tue Jan 28 2003 - 14:44:55 PST