<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
<channel>
<title>IS Services Desk Announcements</title>
<link>http://www.infodiv.unimelb.edu.au/itsc/</link>
<description>IS Services Centre Announcements RSS feed</description>
<language>en-us</language>
<item>
	<title>[For Information] - Remedy - Planned Outage - 13 November 10:30pm - 15 November 6:00pm</title>
	<description><p>To Remedy Users, </p>Information Technology Services advise that Remedy will be unavailable from 10:30 p.m. on Friday, 13th November 2009 to 6.00 p.m. on Sunday, 15th November 2009.<br />
<br />
Access to Remedy will not be available during this period. Please note that users will still be able to log incident requests through the online forms at [<a href="http://servicedesk.unimelb.edu.au" target='_blank'>http://servicedesk.unimelb.edu.au</a>]<br />
<br />
Two changes are planned during this outage:<br />
<br />
1. Remedy Knowledge Management will be upgraded to version 7.2 - This version provides improved stability and performance without any major changes to the interface and functionality of Remedy Knowledge Management.<br />
<br />
2. SSL security will be implemented on the Remedy web interface and Remedy Knowledge Management web interface. Redirections are in place for the main pages, but if you have bookmarked the login page you may need to use the links from the following page to update your bookmarks:<br />
[<a href="http://www.infodiv.unimelb.edu.au/remedy" target='_blank'>http://www.infodiv.unimelb.edu.au/remedy</a>]<br />
<br />
If you have any feedback on these changes, please contact the Remedy Service Delivery Manager, Simon Abbott sjabbott@unimelb.edu.au</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=935</link>
	<pubDate>2009-11-06</pubDate>
	</item>
<item>
	<title>[For Information] - Software Vendor Roadshow 2009 - General Notification</title>
	<description><p>To IT Managers and Lites, </p>ADOBE, VMware, Symantec and Microsoft will presenting the latest updates at The University of Melbourne.<br />
<br />
Session details and times can be located:<br />
<br />
[<a href="http://www.infodiv.unimelb.edu.au/itpl/licensing/SoftwareVendor2009.html" target='_blank'>http://www.infodiv.unimelb.edu.au/itpl/licensing/SoftwareVendor2009.html</a>]<br />
<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=934</link>
	<pubDate>2009-11-05</pubDate>
	</item>
<item>
	<title>[Important] - IT Security Services - Email with malicious attachment received in the University</title>
	<description><p>To Email users, </p>ITSS-Advisory : Medium : Email with malicious file attached<br />
<br />
It would be appreciated if this information can be communicated<br />
to students and staff through appropriate means, such as notice<br />
boards or linked through web information services.<br />
The web address of this article is:<br />
[<a href="http://www.infodiv.unimelb.edu.au/it-security/05-11-2009.html" target='_blank'>http://www.infodiv.unimelb.edu.au/it-security/05-11-2009.html</a>]<br />
<br />
<br />
THREAT LEVEL<br />
============<br />
Medium.<br />
<br />
<br />
INFORMATION<br />
===========<br />
An email with a malicious file attached has been received in the University.<br />
The email has the following characteristics:<br />
<br />
From:     Comcover Gov<br />
Subject: Nonrefundable loan approved for your company!<br />
<br />
McAfee antivirus with DAT version 5791 (and later) is able to detect and <br />
delete the malicious file attachment.<br />
<br />
 <br />
ACTION<br />
======<br />
Please advise all users to permanently delete the email.</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=933</link>
	<pubDate>2009-11-05</pubDate>
	</item>
<item>
	<title>[Important] - IT Security Services - Java SE 6 Update 17 released</title>
	<description><p>To Administrators of computers running Java, </p>ITSS-Advisory : MEDIUM : Sun : Java : Java SE 6 Update 17 released<br />
<br />
It would be appreciated if this information can be communicated<br />
to students and staff through appropriate means, such as notice<br />
boards or linked through web information services.<br />
The web address of this article is:<br />
[<a href="http://www.infodiv.unimelb.edu.au/it-security/1-04-11-2009.html" target='_blank'>http://www.infodiv.unimelb.edu.au/it-security/1-04-11-2009.html</a>]<br />
<br />
THREAT LEVEL<br />
============<br />
Medium.<br />
<br />
INFORMATION<br />
===========<br />
Sun has released Java SE 6 Update 17. This version fixes a number of <br />
vulnerabilities, impacts include denial of service and arbitrary code <br />
execution. More information is available at:<br />
[<a href="http://java.sun.com/javase/6/webnotes/6u17.html" target='_blank'>http://java.sun.com/javase/6/webnotes/6u17.html</a>]<br />
 <br />
AFFECTED PLATFORMS<br />
==================<br />
Computer of various platforms running Java versions earlier than <br />
Java SE 6 Update 17.<br />
 <br />
ACTION<br />
======<br />
Administrators of affected computers are advised to review the <br />
bulletin, test and apply relevant updates. <br />
<br />
Links to download Java are available at:<br />
[<a href="http://www.java.com" target='_blank'>http://www.java.com</a>]<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=932</link>
	<pubDate>2009-11-04</pubDate>
	</item>
<item>
	<title>[Important] - ITSS-Advisory :  Microsoft : Internet Explorer - IT Security Notification</title>
	<description><p>To Users and administrators of systems with Internet Explorer installed, </p>ITSS-Advisory : Medium : Microsoft : UPDATED ALERT Internet Explorer<br />
<br />
It would be appreciated if this information can be communicated to students and staff through appropriate means, such as notice boards or linked through web information services.<br />
<br />
The web address of this article is: [<a href="http://www.infodiv.unimelb.edu.au/it-security" target='_blank'>http://www.infodiv.unimelb.edu.au/it-security</a> 04-11-2009-02.html]<br />
<br />
THREAT LEVEL<br />
============<br />
Medium<br />
<br />
INFORMATION<br />
===========<br />
Product:           Internet Explorer<br />
Publisher:         Microsoft<br />
<br />
Resolution:        Patch/Upgrade<br />
<br />
AFFECTED PLATFORMS<br />
==================<br />
Operating System:  Windows 2000<br />
                   Windows XP<br />
                   Windows Server 2003<br />
                   Windows Vista<br />
                   Windows Server 2008<br />
                   Windows 7<br />
<br />
IMPACT<br />
======<br />
Microsoft have released an update to MS09-054 to correct a number of issues that occur after applying the original patch. Users who have installed the original patch will need to apply the latest update available from:<br />
         <br />
[<a href="http://support.microsoft.com/kb/976749" target='_blank'>http://support.microsoft.com/kb/976749</a>]<br />
<br />
Revision History:  <br />
November  3 2009: Added a comment on the required update to the original patch<br />
October  14 2009: Initial Release Relevant vulnerable releases:<br />
    <br />
Internet Explorer 5.01 Service Pack 4 when installed on Microsoft Windows 2000 Service Pack 4<br />
    <br />
Internet Explorer 6 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4<br />
<br />
Internet Explorer 6 for Windows XP Service Pack 2 and Windows XP Service  Pack 3<br />
<br />
Internet Explorer 6 for Windows XP Professional x64 Edition Service Pack 2<br />
<br />
Internet Explorer 6 for Windows Server 2003 Service Pack 2<br />
<br />
Internet Explorer 6 for Windows Server 2003 x64 Edition Service Pack 2<br />
<br />
Internet Explorer 6 for Windows Server 2003 with SP2 for Itanium-based  Systems<br />
<br />
Internet Explorer 7 for Windows XP Service Pack 2 and Windows XP Service Pack 3<br />
<br />
Internet Explorer 7 for Windows XP Professional x64 Edition Service Pack 2<br />
<br />
Internet Explorer 7 for Windows Server 2003 Service Pack 2<br />
<br />
Internet Explorer 7 for Windows Server 2003 x64 Edition Service Pack 2<br />
<br />
Internet Explorer 7 for Windows Server 2003 with SP2 for Itanium-based Systems<br />
<br />
Internet Explorer 7 in Windows Vista, Windows Vista Service Pack 1, and  Windows Vista Service Pack 2<br />
<br />
Internet Explorer 7 in Windows Vista x64 Edition, Windows Vista x64 Edition  Service Pack 1, and Windows Vista x64 Edition Service Pack 2<br />
<br />
Internet Explorer 7 in Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2 (Windows Server 2008 Server Core installation not affected)<br />
<br />
Internet Explorer 7 in Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2 (Windows Server 2008 Server Core installation not affected)<br />
<br />
Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2<br />
<br />
Internet Explorer 8 for Windows XP Service Pack 2 and Windows XP Service Pack 3<br />
<br />
Internet Explorer 8 for Windows XP Professional x64 Edition Service Pack 2<br />
<br />
Internet Explorer 8 for Windows Server 2003 Service Pack 2<br />
<br />
Internet Explorer 8 for Windows Server 2003 x64 Edition Service Pack 2<br />
<br />
Internet Explorer 8 in Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service<br />
Pack 2<br />
<br />
Internet Explorer 8 in Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2<br />
<br />
Internet Explorer 8 in Windows Server 2008 for 32-bit Systems and Windows Server 2008 for<br />
32-bit Systems Service Pack 2 (Windows Server 2008 Server Core installation not affected)<br />
<br />
Internet Explorer 8 in Windows Server 2008 for x64-based Systems and  Windows Server 2008<br />
for x64-based Systems Service Pack 2 (Windows Server 2008 Server Core installation not affected)<br />
<br />
Internet Explorer 8 in Windows 7 for 32-bit Systems<br />
<br />
Internet Explorer 8 in Windows 7 for x64-based Systems<br />
<br />
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems (Windows Server 2008 R2 Server Core installation not affected)<br />
<br />
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems<br />
<br />
<br />
Vulnerability Information<br />
=========================<br />
	<br />
Data Stream Header Corruption Vulnerability - CVE-2009-1547<br />
<br />
A remote code execution vulnerability exists in the way that Internet   Explorer processes data stream headers in specific situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. <br />
<br />
When a user views the Web page, the vulnerability could allow remote code execution. An   attacker who successfully exploited this vulnerability could gain the same user rights as the  logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.<br />
	<br />
HTML Component Handling Vulnerability - CVE-2009-2529<br />
<br />
A remote code execution vulnerability exists in the way that Internet  Explorer handles argument validation of a variable in specific situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.<br />
	<br />
Uninitialized Memory Corruption Vulnerability - CVE-2009-2530<br />
<br />
A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.<br />
<br />
Uninitialized Memory Corruption Vulnerability - CVE-2009-2531<br />
<br />
A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.<br />
<br />
<br />
MITIGATION<br />
==========<br />
Users who have installed the original patch will need to apply the latest update available from:<br />
         <br />
[<a href="http://support.microsoft.com/kb/976749" target='_blank'>http://support.microsoft.com/kb/976749</a>]<br />
Or via Microsoft Windows update<br />
<br />
<br />
REFERENCES<br />
=========<br />
Original Bulletin: <br />
[<a href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target='_blank'>http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx</a>]<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=931</link>
	<pubDate>2009-11-04</pubDate>
	</item>
<item>
	<title>[Important] - IT Security Services - Adobe Shockwave Player - new version released</title>
	<description><p>To Administrators of computers running Adobe Shockwave Player, </p>ITSS-Advisory : MEDIUM : Adobe : Shockwave Player : Version 11.5.2.602 released<br />
<br />
It would be appreciated if this information can be communicated<br />
to students and staff through appropriate means, such as notice<br />
boards or linked through web information services.<br />
The web address of this article is:<br />
[<a href="http://www.infodiv.unimelb.edu.au/it-security/04-11-2009.html" target='_blank'>http://www.infodiv.unimelb.edu.au/it-security/04-11-2009.html</a>]<br />
<br />
<br />
THREAT LEVEL<br />
============<br />
Medium.<br />
<br />
<br />
INFORMATION<br />
===========<br />
On 03 Nov 2009, Adobe released Shockwave Player 11.5.2.602. This version fixes <br />
a number of vulnerabilities, impacts include denial of service and arbitrary code <br />
execution. More information is available at:<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html" target='_blank'>http://www.adobe.com/support/security/bulletins/apsb09-16.html</a><br />
<br />
AFFECTED PLATFORMS<br />
==================<br />
Computers of various operating systems running Adobe Shockwave Player versions <br />
11.5.1.601 and earlier.<br />
 <br />
<br />
ACTION<br />
======<br />
Administrators of affected computers are advised to review the bulletin, test and <br />
apply relevant updates. <br />
<br />
Links to download Shockwave Player are available at:<br />
[<a href="http://get.adobe.com/shockwave/" target='_blank'>http://get.adobe.com/shockwave/</a>]</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=930</link>
	<pubDate>2009-11-04</pubDate>
	</item>
<item>
	<title>[Important] - ITS Procurement - General Notification</title>
	<description><p>To All University Staff, </p>Please check ITS Procurement website <a href="http://www.infodiv.unimelb.edu.au/itpl/purchase/departments.html" target='_blank'>http://www.infodiv.unimelb.edu.au/itpl/purchase/departments.html</a> for interim arrangements - for the purchase of Desktops and Laptops, effective from 13th of October 2009 until further notice.<br />
<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=929</link>
	<pubDate>2009-11-03</pubDate>
	</item>
<item>
	<title>[Important] - Themis - Planned Outage - 3:00pm Friday 6 November 2009 to Monday morning 9 November</title>
	<description><p>To Themis users, </p>Information Technology Services advise that Themis will be unavailable from 3:00pm Friday 6 November until Monday morning 9 November. We are upgrading Themis to the most recent technology patches.<br />
<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=928</link>
	<pubDate>2009-10-29</pubDate>
	</item>
<item>
	<title>[For Information] - Account Registration System - Decommission - 2009 - 2010</title>
	<description><p>To Staff, </p>Information Technology Services is replacing ARS, our Account Registration System, with a new Identity Management System.  The complete replacement of ARS will take place incrementally over the course of 2010.  Work will commence in late 2009.  <br />
<br />
Whilst ARS will continue to be maintained until fully replaced, limited changes or modifications to the retiring ARS system will be undertaken during the replacement period.   Currently there are no pending requests for changes to the ARS system, and only critical new work will be considered after 16 October.<br />
<br />
Please direct all queries to Terry Brennan, Identity Management Project Manager.<br />
<br />
Further information about the Identity and Access Management Project is available at [<a href="http://go.unimelb.edu.au/sa6" target='_blank'>http://go.unimelb.edu.au/sa6</a>]<br />
<br />
</description>
	<link>http://servicedesk.unimelb.edu.au/announcements/display_full.php?id=912</link>
	<pubDate>2009-10-09</pubDate>
	</item>
</channel></rss>