* Patches from Microsoft, Novell, Red Hat, others * Beware Windows virus spreading via e-mail pretending to be an e-card or tech support update * Meetinghouse updates WLAN security for Windows, and other interesting reading Today’s bug patches and security alerts:DirectX flaws put Windows systems at risk, Microsoft warnsTwo security bugs in DirectX, a part of the Windows operating system that provides multimedia support, could allow an attacker to gain control over computers running it, Microsoft warned Wednesday. IDG News Service, 07/24/03.https://www.nwfusion.com/news/2003/0724direcflaws.html Microsoft advisory:https://www.microsoft.com/technet/security/bulletin/MS03-030.asp Microsoft patches NT 4.0 flawA memory leak in the Windows NT 4.0 file management system could be exploited in a denial-of-service attack against the server. This vulnerability only affected Windows NT 4.0. For more, go to:https://www.microsoft.com/technet/security/bulletin/MS03-029.aspRelated @Stake advisory:https://www.atstake.com/research/advisories/2003/a072303-1.txtCumulative SQL patch from Microsoft A new cumulative patch for Microsoft SQL Server 7.0, SQL Server 2000, MSDE 1.0, and MSDE 2000 is now available. This patch includes all previous patches for SQL as well as fixes for a couple of newly found security vulnerabilities. For more, go to:https://www.microsoft.com/technet/security/bulletin/MS03-031.aspRelated @Stake advisory:https://www.atstake.com/research/advisories/2003/a072303-2.txt **********Novell patches Perl handlerA buffer overflow in Netware’s Perl handler may cause an ABEND. This could result in degraded server performance or a complete crash. For more, go to:https://support.novell.com/servlet/tidfinder/2966549**********New Mac security update from AppleApple has released a new security update to fix a couple flaws in Workgroup Manager that ships with Mac OS X Server 10.2. More information on the update can be found here:https://docs.info.apple.com/article.html?artnum=61798**********Red Hat, Conectiva patch kernelA number of vulnerabilities have been fixed in the Red Hat Linux kernel 2.4. The flaws could be exploited to steal passwords, cause a system crash or potentially read files on the affected machine. The same issues have been found and patched in the Conectiva kernel as well. For more, go to:Red Hat:https://rhn.redhat.com/errata/RHSA-2003-238.htmlConectiva:https://www.nwfusion.com/go2/0721bug2a.html**********Conectiva patches nfs-utilsA buffer overflow vulnerability has been found in the nfs-utils package, which provides a daemon for the kernel NFS server. An attacker could exploit the flaw in a denial-of-service attack, though it does not appear as if code could be executed. For more, go to:https://www.nwfusion.com/go2/0721bug2b.htmlConectiva releases Apache updateA number of vulnerabilities in the Apache Webserver code have been fixed in this latest release. Most of the flaws could be exploited in a denial-of-service attack against the affected server. For more, go to:https://www.nwfusion.com/go2/0721bug2c.htmlConectiva releases cups fixNumerous overflows have been patched in the Conectiva version of cups (Common UNIX Printing System). Some of the overflows could be exploited to execute arbitrary commands on the affected machine. For more, go to:https://www.nwfusion.com/go2/0721bug2d.html**********Today’s roundup of virus alerts:Troj/DownLdr-DI – A Trojan horse that downloads malicious codes from a remote Web site. No word on what damage can be caused to an infected machine. (Sophos)W32/Mofei-C – A virus that can slow the infected machine down and spreads via network shares with weak or no password protection. It also opens a backdoor to listen for remote instructions. (Sophos)W32/Jantic-B – This Windows virus spreads via e-mail pretending to be an e-card or tech support update. The virus e-mails itself to everyone in the infected machine’s address book. (Sophos)**********From the interesting reading department:Cracking Windows passwords in secondsIf your passwords consist of letters and numbers, beware. Swiss researchers Tuesday released a paper outlining a way to speed the cracking of alphanumeric Windows passwords, reducing the time to break such codes to an average of 13.6 seconds from 1 minute 41 seconds. Boston.com, 07/22/03.https://www.nwfusion.com/go2/0721bug2e.htmlMeetinghouse updates WLAN security for WindowsA new release of client software for Windows computers adds tougher 802.11 wireless LAN security and some features designed for easier deployment in large-scale nets. Network World Fusion, 07/22/03.https://www.nwfusion.com/news/2003/0722meetinghouse.htmlSophos boosts reporting capabilitiesSophos has released an antivirus tool that the company claims will boost the reporting capabilities of its management software suite. IDG News Service, 07/21/03.https://www.nwfusion.com/news/2003/0721sophounvei.htmlGuilty Plea in Kinko’s Keystroke CaperIf you used a computer at a Kinko’s in New York last year, or the year before, there’s a good chance that JuJu Jiang was watching. SecurityFocus, 07/18/03.https://www.securityfocus.com/news/6447Hacker cleans out bank accountsA hacker is targeting clients of South Africa’s largest bank and has managed to steal hundreds of thousands of rands by breaching their accounts over the Internet. Sunday Times, 07/20/03.https://www.sundaytimes.co.za/2003/07/20/news/news01.asp Related content news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center news AWS and Nvidia partner on Project Ceiba, a GPU-powered AI supercomputer The companies are extending their AI partnership, and one key initiative is a supercomputer that will be integrated with AWS services and used by Nvidia’s own R&D teams. By Andy Patrizio Nov 30, 2023 3 mins CPUs and Processors Generative AI Supercomputers news VMware stung by defections and layoffs after Broadcom close Layoffs and executive departures are expected after an acquisition, but there's also concern about VMware customer retention. By Andy Patrizio Nov 30, 2023 3 mins Virtualization Data Center Industry Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe