* Patches from Conectiva, Gentoo, Debian others * More Rbot viruses run amuck * Gates: We'll make security our forte, and other interesting reading Today’s bug patches and security alerts:Latest patch for IE holes released by MicrosoftMicrosoft Friday issued a much-anticipated patch for three vulnerabilities that have recently caused some havoc among users of its Internet Explorer browser. Network World Fusion, 07/30/04.https://www.nwfusion.com/news/2004/0730mspatch.html?nl Microsoft advisory:https://www.microsoft.com/technet/security/Bulletin/MS04-025.mspx Related alerts:ISS X-Force:https://xforce.iss.net/xforce/alerts/id/179CERT advisory:https://www.us-cert.gov/cas/techalerts/TA04-212A.html********** Debian patches courierAccording to an alert from Debian, “A cross-site scripting vulnerability was discovered in sqwebmail, a web mail application provided by the courier mail suite, whereby an attacker could cause web script to be executed within the security context of the sqwebmail application by injecting it via an e-mail message.” For more, go to:https://www.debian.org/security/2004/dsa-533Debian updates mailreader A directory traversal bug has been found in mailreader, which could be exploited to view files with the privileges of “www-data”. For more, go to:https://www.debian.org/security/2004/dsa-534**********Vendors release Sox patchesNothing to do with the Red Sox trading deadline moves. Sox is a sound file conversion utility. Two buffer overflow flaws have been found in the code, which could be exploited with a specially crafted WAV file. For more, go to:Conectiva:https://www.nwfusion.com/go2/0802bug1a.htmlGentoo:https://forums.gentoo.org/viewtopic.php?t=204383Mandrake Linux:https://www.nwfusion.com/go2/0802bug1b.html**********Conectiva, Gentoo patch SambaA buffer overflow has been found in SWAT, the Samba Web Administration Tool. This flaw could be exploited prior to a user being authenticated and could allow an attacker to take control of the affected machine. For more, go to:Conectiva:https://www.nwfusion.com/go2/0802bug1c.htmlGentoo:https://forums.gentoo.org/viewtopic.php?t=203872**********Conectiva patches kernelFive different flaws have been patched in the latest kernel release from Conectiva. Most of the flaws are relatively obscure, but users are urged to upgrade. For more, go to:https://www.nwfusion.com/go2/0802bug1d.html**********Today’s roundup of virus alerts:W32/Rbot-EW — Another bot Trojan that exploits network shares with weak passwords to spread between machines. It installs itself as “UPDATE_W.EXE” in the Windows System directory and allows backdoor access via IRC. (Sophos)W32/Rbot-FC — This Rbot variant is similar to EW above, except it uses the infected file of “WINSYST32.EXE” and adds the twist of a file logger and CD key stealer. (Sophos)W32/Rbot-DE — Another Rbot variant. It uses “WINSYS32.EXE” as its infection point and tries to kill certain network share connections. (Sophos)W32/Sdbot-KU — A bot that spreads by exploiting machines infected with MyDoom or without the Windows DCOM patch. It installs itself as “PEREMPTION.EXE” and allows backdoor access via IRC. It can be used to launch SYN flood attacks against remote sites and also attempts to steal CD keys for popular games. (Sophos)W32/Tompai-A — A backdoor Trojan that spreads via network shares and uses a variety of filename combinations to install itself in the Windows System folder. The virus has the text “phantompain” embedded in the code. (Sophos)W32/Agobot-KM — Yet another bot that uses weakly protected network shares to spread between machines. This infects “MSVSRV32.EXE” in the Windows System directory, allows backdoor access via IRC, and modifies the Windows HOSTS file to block access to anti-virus sites. (Sophos)**********From the interesting reading department:Gates: We’ll make security our forteSecurity will come to be seen as a Microsoft strength. So says Bill Gates, who raised the bar significantly last week when he told financial analysts that ongoing development projects will transform security “from a concern for us into something that’s a significant, unique asset as well as a business opportunity.” Network World, 08/02/04.https://www.nwfusion.com/news/2004/080204msfinancial.html?nlFeature: Practice safe chatUnprotected messaging can cause serious security and compliance problems. Network World, 08/02/04.https://www.nwfusion.com/research/2004/080204im.html?nlTechnology Update: ID management establishes trustAs businesses start deploying distributed federated models to solve identity management problems, the Liberty Alliance has developed the Liberty Identification Federation Framework 1.2 specification. Network World, 08/02/04.https://www.nwfusion.com/news/tech/2004/080204techupdate.html?nlNIST says DES encryption ‘inadequate’The National Institute of Standards and Technology is proposing that the Data Encryption Standard, a popular encryption algorithm, lose its certification for use in software products sold to the government. IDG News Service, 07/29/04.https://www.nwfusion.com/news/2004/0729nistsays2.html?nlGlitch locks out Money usersIt’s the end of the month – bill-paying time – and some Money 2004 users are wishing they’d kept their cash in an old mattress instead of relying on Microsoft’s financial software. A snafu with a couple of Microsoft servers has frozen users’ access to their own financial data, even though the encrypted files are on the hard drives of their own PCs. PC World, 07/30/04.https://www.nwfusion.com/news/2004/0730glitclocks.html?nl Related content feature 5 ways to boost server efficiency Right-sizing workloads, upgrading to newer servers, and managing power consumption can help enterprises reach their data center sustainability goals. By Maria Korolov Dec 04, 2023 9 mins Green IT Green IT Green IT news Omdia: AI boosts server spending but unit sales still plunge A rush to build AI capacity using expensive coprocessors is jacking up the prices of servers, says research firm Omdia. By Andy Patrizio Dec 04, 2023 4 mins CPUs and Processors Generative AI Data Center feature What is Ethernet? History, evolution and roadmap The Ethernet protocol connects LANs, WANs, Internet, cloud, IoT devices, Wi-Fi systems into one seamless global communications network. By John Breeden Dec 04, 2023 11 mins Networking news IBM unveils Heron quantum processor and new modular quantum computer IBM also shared its 10-year quantum computing roadmap, which prioritizes improvements in gate operations and error-correction capabilities. By Michael Cooney Dec 04, 2023 5 mins CPUs and Processors CPUs and Processors CPUs and Processors Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe