1. /
  2. Security Response/
  3. Security Updates Detail

Symantec Enterprise Security Manager - Security Update 2009.09.01 (SU 38)

September 30, 2009

Description



The Symantec Enterprise Security Manager™ Security Update 2009.09.01 has been enhanced to support AIX VIOS Server 2.1 on AIX 6.1, Logical Partition (LPAR) on AIX 5.3 and  6.1, SUSE 11 on x86, Opteron and EM64T, Itanium, zLinux, and PPC e-Server, RHEL 5.2 and 5.3 on x86, Opteron and EM64T, Itanium, zLinux, and PPC e-Server, Oracle Enterprise Linux 5.2, 5.3 on x86, Opteron and EM64T, Hyper-V Server 2008, SUSE OES 2 SP1 on x86 and Opteron and EM64T, and ESX server 4.0 on x86 and Opteron and EM64T operating systems.

 

In addition, 13 new checks have been added across several modules.

 

Install Security Update 2009.09.01 to upgrade UNIX and Windows security modules on Symantec ESM 6.5.x and 9.0 agents. For detailed descriptions of new features and enhancements, download the Security Update 2009.09.01 Release Notes.

 

Enhancements

Security Update 2009.09.01 provides the following enhancements:
  • Support for the following operating systems on ESM 6.5.3 and later versions:
    • AIX VIOS Server 2.1 on AIX 6.1
    • Logical Partition (LPAR) on AIX 5.3 and 6.1
    • SUSE 11 on x86, Opteron and EM64T, Itanium, zLinux, and PPC e-Server
    • RHEL 5.2 and 5.3 on x86, Opteron and EM64T, Itanium, zLinux, and PPC e-Server
    • Oracle Enterprise Linux 5.2, 5.3 on x86, Opteron and EM64T
    • Hyper-V Server 2008
    • SUSE OES 2 SP1 on x86 and Opteron and EM64T
    • ESX server 4.0 on x86 and Opteron and EM64T
  • New Windows IIS Configuration module:
    The checks in the IIS Configuration module on Windows verify the various settings that are associated with the IIS server on the ESM agent computer.
    Seven checks in the Windows IIS Configuration module:
    • ASP.Net Configuration
    • Log directory
    • Metabase settings
    • Virtual directory
    • WAMUser
    • Web site
    • Web sites and Virtual directories

    Two templates in the Windows IIS Configuration module:
    • IIS Metabase template
    • IIS ASP.Net template
  • One new check in the Windows Active Directory module:
    • Domain Controller Information
  • One new check in the Windows and UNIX Agent Information module:
    • LiveUpdate status
  • One new check in the UNIX Login Parameters module:
    • Required PAM Configuration
  • One new check in the UNIX Network Integrity module:
    • Established TCP Connection
  • One new check in the AIX VOIS server OS Patches module:
    • VIOS level
  • One new check in the UNIX Password Strength module:
    • Required PAM Configuration
  • One new message in the Windows Symantec Product Information module:
    • Symantec Endpoint Protection (SEP) group
  • One new message in the UNIX Password Strength module:
    • Password age
  • One new template in the UNIX Object Integrity module:
    • Name to Major
  • One new template in the UNIX Login Parameters module:
    • PAM Conf for Login Parameters
  • One new template in the UNIX Password Strength module:
    • PAM Conf for Password Strength
  • One new template in the AIX OS Patches module:
    • VIOS level

Note: On the LiveUpdate wizard, the SU version is now visible in the following format: SU<YYYY>.<MM>.<Release_Version>. ... Where, YYYY is the year of release, MM is the month of release, and Release_Version is the release version of the SU. For example, SU 38 displays as SU 2009.09.01 on the LiveUpdate wizard.

Extended Support

The Extended Support TPK includes the following enhancements:
  • Large file support
  • Extended unprintable characters in filenames support (Solaris only)
  • Full promiscuous mode detection (Solaris only)

Note: The extended support installer (TPK) is only applicable on AIX, HP-UX, and Solaris operating systems.

Downloads


Download Security Update 2009.09.01 for AIX-PPC64
  • AIX 5.3 (64-bit only)
  • AIX 6.1 (64-bit)
    MD5:958e0771b28759bd1195e37356bc0fb0
Download Security Update 2009.09.01 for AIX RS/6000
  • AIX 5.2 (32-bit and 64- bit only)
  • AIX 5.3 (32-bit only)
    MD5: 85849dcb703f089341c0b27d2af02b5a

Download Security Update 2009.09.01 for Linux

MD5:  2eeabbb33bce5500237a88bbde98e44e

Linux Platforms include:

  • Red Hat Enterprise Server (x86, Opteron and EM64T)
  • SUSE Linux Enterprise Server (x86)
  • SUSE Linux Enterprise Server (Opteron and EM64T)
  • ESX Server (x86, Opteron)

For these platforms, continue to use Security Update 18:
For these platforms, continue to use Security Update 17:

Agent Installs

Refer to the ESM Agent Downloads section on the following Security Response Web site or information on downloading the ESM 6.5.x and later agents:

Documentation

The SU Release Notes contain the details of all module enhancements. Continue using your Security Update 17 User’s Guides until the updated guides are released.
Security Response Blog
The State of Spam