* Patches from Red Hat, others * Beware worm that spreads via P2P networks * Sobig's success prompts calls for secure e-mail, and other interesting reading It wouldn’t be a Thursday without a security release from Microsoft.On a more serious note, my thoughts and prayers to everyone on this second anniversary of the 9/11 terrorist attacks.Today’s bug patches and security alerts:Blaster II? Microsoft warns of new security holes Only weeks after the appearance of the Blaster worm, Microsoft released a software patch for still more holes similar to those Blaster exploited. The three new vulnerabilities are all rated “critical” and could be used by a remote attacker to take control of vulnerable systems, installing programs or changing data stored on a hard drive, Microsoft said on Wednesday. IDG News Service, 09/10/03.https://www.nwfusion.com/news/2003/0910blastii.html Microsoft advisory: Buffer overrun in RPCSS service could allow code execution:https://www.microsoft.com/technet/security/bulletin/MS03-039.aspCERT advisory:https://www.cert.org/advisories/CA-2003-23.html**********WinAmp flaw found A buffer overflow has been found in the midi module for WinAmp 2.91 and 3.0. The flaw could be exploited to run arbitrary code on machine running WinAmp 2.91 or to crash machines running version 3.0. No patch is available yet from NullSoft, so users are advised to play midi files with another application until one is available. For more, go to:https://www.nwfusion.com/go2/0908bug2a.html**********Buffer overflow vulnerability in pine iDefense has found a couple of buffer problems in the pine e-mail client. Both of the flaws could be exploited to run arbitrary code on the affected machine. Pine Version 4.58 fixes the problem. For more, go to:iDefense advisory:https://www.idefense.com/advisory/09.10.03.txtHow to obtain Pine updates:https://www.washington.edu/pine/getpine/Red Hat update:https://rhn.redhat.com/errata/RHSA-2003-273.htmlSlackware update:https://www.nwfusion.com/go2/0908bug2b.html**********Red Hat patches flaw in GtkHTMLRed Hat is reporting a flaw in GtkHTML, the HTML rendering engine for the Evolution e-mail reader. A user could get the application to point to a null pointer, causing the system to crash. For more, go to:https://rhn.redhat.com/errata/RHSA-2003-264.html**********SCO releases Samba update for OpenServerA flaw in SCO’s Samba implementation for OpenServer could be exploited by a remote user to gain root access to the affected machine. The updated binaries can be found here:ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.13**********Today’s roundup of virus alerts:W32/Blaxe-A – A worm that spreads via peer-to-peer networks using a number of different filenames. Looks like the most damage it causes is to overwrite the .exe files in the directory of the P2P application. (Sophos)**********From the interesting reading department:Hackers jump through holes in Microsoft patchSecurity experts are warning Microsoft customers about silent Internet attacks that exploit a security flaw in the Internet Explorer Web browser, potentially allowing remote attackers to run malicious code on vulnerable machines. IDG News Service, 09/08/03.https://www.nwfusion.com/news/2003/0908hackejump.htmlStudy: ISPs should block ‘Net attack portsInternet service providers should take security matters into their own hands by blocking access to communications ports on their customers’ computers which are commonly exploited by Internet worms and other malicious programs, according to a SANS Institute report. IDG News Service, 09/08/03.https://www.nwfusion.com/edge/news/2003/0908studyisps.htmlSobig’s success prompts calls for secure e-mailEven seasoned antivirus experts hadn’t seen anything like the Sobig-F e-mail worm: Within hours of its release on Aug. 19,it created a million copies of itself and was spreading worldwide, shattering speed records set by earlier viruses. IDG News Service, 09/09/03.https://www.nwfusion.com/news/2003/0909sobigs.htmlSobig’s wake is SobigAlthough the Sobig virus is still worming its way around the network, causing headaches for IT organizations, already thoughts are turning to the lessons learned. And at some companies that may mean a separation of church and state or rather: work and home. Network World Web Business Newsletter, 09/04/03.https://www.nwfusion.com/newsletters/ecomm/2003/0901ecom2.htmlRomanian man to be charged in Blaster releaseA Romanian man will be charged with violating that country’s cybercrime laws by releasing a version of the W32.Blaster Internet worm, according to a source involved in the investigation. IDG News Service, 09/10/03.https://www.nwfusion.com/news/2003/0910romanian.html‘Homeless hacker’ Lamo surrenders to fedsComputer hacker Adrian Lamo surrendered Tuesday morning to U.S. Marshals at the federal courthouse in Sacramento, Calif., according to an FBI spokeswoman. IDG News Service, 09/09/03.https://www.nwfusion.com/news/2003/0909homeless.htmlIn computer security, a bigger reason to squirmDespite the brochures and educational Web sites that the antivirus industry churns out, some experts fear that many users will never alter their surfing habits. New York Times, 09/07/03.https://www.nytimes.com/2003/09/07/technology/07WORM.html Related content news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Industry Networking news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Network Security Networking news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center news AWS and Nvidia partner on Project Ceiba, a GPU-powered AI supercomputer The companies are extending their AI partnership, and one key initiative is a supercomputer that will be integrated with AWS services and used by Nvidia’s own R&D teams. By Andy Patrizio Nov 30, 2023 3 mins CPUs and Processors Generative AI Supercomputers Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe