* Patches from SuSE, Conectiva, Debian, others * Beware Trojan spreading via e-mail entitled "Fraudulent escrow service" * Organizations scramble to patch Microsoft flaws, and other interesting reading Here’s another suggested patch management solution. Reader Frank Kistner writes:Get Microsoft to enter into a partnership agreement with AOL (Geez, what am I saying…) such that AOL includes all Microsoft patches on the CDs that AOL mails to ‘x’ million households every year. This could actually be a valuable service to those people who would otherwise simply throw the CDs away, and to those people who have only dial-up internet access.Another option would be for Microsoft to enter into a partnership agreement with major computer stores (Best Buy, CompUSA, etc) whereby the computer stores would operate a ‘patch kiosk’. Microsoft could make a machine that looks and works much like an ATM – you put in a blank CD, pay a few dollars, answer a few questions (e.g. what operating system do you have?) and get all of the latest Microsoft patches.I like some of Frank’s ideas. Expanding his second suggestion, a store such as Best Buy, CompUSA or even Walmart could sell those handy little USB drives that a user takes home, plugs into his machine and has all his system information downloaded to it. The drive is brought back into the store, plugged into the kiosk, where the system information is analyzed. All the necessary patches and updates could then be downloaded back to the USB drive and taken home for installation. Granted, if you’ve got a high-speed line, this a moot point. But there are still a lot of dial up users out there. Today’s bug patches and security alerts:Conectiva, Engarde, SuSE patch pine As we reported last week, iDefense has found a couple of buffer problems in the pine e-mail client. Both of the flaws could be exploited to take control of the affected machine and run any application of the attacker’s choosing. Pine Version 4.58 fixes the problem. For more, go to:Conectiva:https://www.nwfusion.com/go2/0915bug1a.htmlEnGarde:https://www.linuxsecurity.com/advisories/engarde_advisory-3607.htmlSuSE: https://www.suse.com/de/security/2003_037_pine.html**********Conectiva patches flaw in GtkHTMLConectiva has released a fix for a flaw in GtkHTML, the HTML rendering engine for the Evolution e-mail reader. A user could get the application to point to a null pointer, causing the system to crash. For more, go to: https://www.nwfusion.com/go2/0915bug1b.html**********Mandrake Linux, Debian release patch for xfree86A flaw in the xterm package that comes with xfree86 could be exploited by an attacker to send arbitrary commands to the command line. The commands would not execute until the user press enter on the affected machine. If a funky command pops up on your command line that you didn’t enter, delete it. For more, go to:Mandrake Linux:https://www.nwfusion.com/go2/0915bug1c.htmlDebian:https://www.debian.org/security/2003/dsa-380**********Debian releases new sane-backendsA number of vulnerabilities were found in sane API set, used for interfacing with various scanners. An attacker could exploit this to cause a segfault or cosume large amounts of memory, causing the machine to crash. For more, go to:https://www.debian.org/security/2003/dsa-379**********Today’s roundup of virus alerts:Troj/Backsm-A – A backdoor Trojan horse program that connects to a third-party IRC server to give an attacker access to the affected machine. (Sophos)Mimail.B – Another Trojan horse. This one spreads via e-mail entitled “Fraudulent escrow service” with an attachment called “INFO.ZIP”. The virus logs keystrokes on the infected machine. (Panda Software)Gaobot.L – Another backdoor program that spreads similar to Blaster by exploiting the RPC DCOM vulnerability in Windows. The virus uses port 9900 to connect to an IRC server and waits for commands. (Panda Software)Vote.K – An e-mail virus that attempts to overwrite a number of popular file types on the infected machine. (Panda Software)**********From the interesting reading department:White paper: Defeating the Stack Based Buffer Overflow Prevention Mechanism of Microsoft Windows 2003 ServerDavid Litchfield of NGSSoftware Ltd presents several methods of bypassing the protection mechanism built into Microsoft’s Windows 2003 Server that attempts to prevent the exploitation of stack based buffer overflows. Recommendations about how to thwart these attacks are made where appropriate. NGSSoftware, 09/08/03. (PDF file)https://www.nwfusion.com/go2/0915bug1d.htmlOrganizations scramble to patch Microsoft flawsOrganizations that use Microsoft’s Windows software were scrambling Thursday to patch vulnerable systems after the companysent word on Wednesday of three more critical Windows software vulnerabilities. IDG News Service, 09/11/03.https://www.nwfusion.com/news/2003/0911scramble.htmlViruses salute 9/11Two viruses currently spreading on the ‘Net use references to the September 11, 2001 terrorist attacks in the U.S. as lead-ins to unwittingly unleash their vengeance. Geek.com, 09/12/03.https://www.geek.com/news/geeknews/2003Sep/gee20030912021732.htmSymantec pumps up security appliance familySymantec this week announced a family of all-in-one security appliances that will give customers a variety of ways to beef up securitywithout adding multiple devices to their networks. Network World, 09/12/03.https://www.nwfusion.com/news/2003/0915symantec.htmlSobig-F worm finally self-terminatesYour worm has expired; but don’t worry – there’s sure to be another one soon. Geek.com, 09/11/03.https://www.geek.com/news/geeknews/2003Sep/gee20030911021721.htmHacker Lamo free on bail after court appearanceAccused computer hacker Adrian Lamo has been released on bail after being charged Friday in federal court with breaking into the computer network of The New York Times Co. IDG News Service, 09/12/03.https://www.nwfusion.com/news/2003/0912hackerlamo.html Related content news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center news AWS and Nvidia partner on Project Ceiba, a GPU-powered AI supercomputer The companies are extending their AI partnership, and one key initiative is a supercomputer that will be integrated with AWS services and used by Nvidia’s own R&D teams. By Andy Patrizio Nov 30, 2023 3 mins CPUs and Processors Generative AI Supercomputers news VMware stung by defections and layoffs after Broadcom close Layoffs and executive departures are expected after an acquisition, but there's also concern about VMware customer retention. By Andy Patrizio Nov 30, 2023 3 mins Virtualization Data Center Industry Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe