Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Servers

    SuSE Fixes Bugs, Defends New Update Policy

    Written by

    Steven J. Vaughan-Nichols
    Published February 8, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Novell Inc. released to its SuSE Linux line on Friday numerous fixes to bugs that could enable a number of types of attacks, including DoS.

      The new set of patches fixes a variety of problems that can be exploited to cause denial-of-service, spoofing and cross-site scripting attacks, as well as to disclose sensitive information or compromise unpatched systems. The programs affected by the fixes include older versions of SuSE Linux, Desktop and SuSE Server Linux and the newest server operating system, SuSE Enterprise Linux 9.

      Most of the flaws are not problems with SuSEs operating system per se, but with bundled programs, like CUPS (Common Unix Printing System), the Sun Java Plug-in and the KDE windows manager.

      With this release, Novells SuSE Linux division has started a new approach to releasing bug fixes. According to Marcus Meissner, a member of the SuSE Security Team, “To avoid spamming lists with advisories for every small incident, we will release weekly summary advisories for issues where we have released updates without a full advisory.”

      The fixes are currently available from SuSEs FTP servers and via the YaST Online Update program.

      According to reports, however, security firm Secunia is taking exception to this new weekly announcement policy. “SuSE started a new policy of bundling their updates, so that creates some confusion over what is highly critical and needs to be addressed first,” said Thomas Kristensen, Secunias chief technology officer.

      The difference, he explained, between SuSEs patch policy and that of Microsoft—which issues patches on a monthly schedule—is that Microsoft issues patches for only one main program, whereas SuSEs patches are for multiple programs.

      Novell/SuSE doesnt see it that way.

      “We are not aware of any customer confusion in the way our patches are released,” said Jasmin Ul-Haque, Novells corporate spokesperson. “Patches continue to be released without delay as soon as they have been approved by our quality assurance team, and our customers receive a timely notice of this via e-mail; this process has not changed at all.”

      What has changed, Ul-Haque said, “is the method of how we advise our customers of which patches have been released.”

      “We still send out advisory e-mails for all important issues as soon as the patches have been approved and released. But for all noncritical issues, these patches are now collected in an e-mail, which is released once a week in order to streamline the volume of messages that our customers get and to help them differentiate between important and noncritical issues,” Ul-Haque said.

      Check out eWEEK.coms for the latest open-source news, reviews and analysis.

      Steven J. Vaughan-Nichols
      Steven J. Vaughan-Nichols
      I'm editor-at-large for Ziff Davis Enterprise. That's a fancy title that means I write about whatever topic strikes my fancy or needs written about across the Ziff Davis Enterprise family of publications. You'll find most of my stories in Linux-Watch, DesktopLinux and eWEEK. Prior to becoming a technology journalist, I worked at NASA and the Department of Defense on numerous major technological projects.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×