Current Activity Calendar
| January 10, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Exploit Code Available for Multiple Vulnerabilities in Sun Java Runtime Environmentadded January 10, 2007US-CERT is aware of publicly available exploit code for multiple vulnerabilities in Sun Java Runtime Environment (JRE). There are several flaws in the JRE that may allow an untrusted Java Applet to elevate its privileges or execute malicious code. If successfully exploited, a remote, unauthenticated attacker may be able to execute arbitrary code with elevated privileges. More information about these vulnerabilities can be found in the Vulnerability Notes Database. US-CERT encourages users to take the following actions to help mitigate the effects of these vulnerabilities:
Multiple Vulnerabilities in Kerberos Administration Daemonadded January 9, 2007US-CERT is aware of multiple vulnerabilities in the Kerberos administration daemon. The impacts of these vulnerabilities include remote code execution or denial of service on a vulnerable system. There are several vulnerabilities related to the way memory management is handled by the Generic Security Services Application Program Interface (GSS-API) and Remote Procedure Call (RPC) library provided with MIT Kerberos (krb5) distribution. By sending specially crafted packets to a vulnerable system, a remote, unauthenticated attacker may be able to execute arbitrary code or crash the Kerberos administration daemon. More information about these vulnerabilities can be found in the following:
US-CERT encourages users and administrators to apply the patches as described in both the MIT krb5 Security Advisories 2006-002 and 2006-003 to address these vulnerabilities. Microsoft Releases January Security Bulletinadded January 9, 2007 | updated January 9, 2007Microsoft has released updates to address vulnerabilities in Microsoft Windows and Office as part of the Microsoft Security Bulletin Summary for January 2007. Microsoft indicates that the buffer overflow vulnerability in Vector Markup Language (VU#122084) is being actively exploited. US-CERT strongly encourage users to review the bulletins and follow best-practice security policies to determine what updates should be applied. Additionally, more information about these vulnerabilities can be found in the Vulnerability Notes Database and Technical Cyber Security Alert TA07-009A. Multiple Vulnerabilities in Cisco Secure ACSadded January 8, 2007US-CERT is aware of multiple vulnerabilities in Cisco Secure Access Control Server (ACS). The impacts of these vulnerabilities include remote code execution and denial of service on a vulnerable system. The first issue is a stack-based buffer overflow vulnerability in the CSAdmin service. There is a flaw in the way specially crafted HTTP GET requests are processed. If successfully exploited, a remote attacker may be able to execute arbitrary code or crash the CSAdmin service. The second issue is a stack-based buffer overflow vulnerability in the CSRadius service. There is a flaw in the way specially crafted RADIUS Accounting-Request packets are processed. If successfully exploited, a remote attacker with a RADIUS secret key may be able to execute arbitrary code or crash the CSRadius service. The third issue is due to multiple unspecified flaws in the way specially crafted RADIUS Access-Request packets are processed. If successfully exploited, a remote attacker may be able to crash the CSRadius service. The products affected by these vulnerabilities are Cisco Secure Access Control Server for Windows, and Cisco Secure Access Control Server Solution Engine running software versions 4.1 and prior. More information about this vulnerability can be found in the following:
US-CERT encourages users to take the following actions to help mitigate the security risks:
US-CERT will continue to investigate and provide additional information as it becomes available. Cross-Site Scripting Vulnerability in Adobe Acrobat Plug-Inadded January 4, 2007US-CERT is aware of a cross-site scripting vulnerability in the Adobe Acrobat Plug-In. The Adobe Acrobat Plug-In allows users to view PDF files inside of a web browser. The Adobe Acrobat Plug-In fails to properly validate URI parameters for JavaScript code. This allows user-supplied JavaScript to execute within the context of the web site hosting the PDF file causing a cross-site scripting vulnerability. More information about this vulnerability can be found in the following:
US-CERT encourages users to upgrade to the latest release of Adobe Acrobat Reader as soon as possible. If unable to upgrade, then US-CERT recommends that users take the following actions to help mitigate the security risks:
Note: Any website that hosts a PDF file may be used as an attack vector or launch point to exploit this vulnerability. Web site and network administrators may wish to filter JavaScript in both URLs and leaving the network to prevent their websites from being leveraged in attacks. Information on how to filter JavaScript out of URLs is available in VU#815960. IRS Phishing Scam and Identity Theftadded January 3, 2007US-CERT continues to receive reports of phishing scams that target online users. Most recently, users have reported receiving emails that appear to be from the Internal Revenue Service (IRS). The phishing email claims to offer a tax refund and requests users to click on a link to provide personal and possibly sensitive information. Identity thieves could use this information to further compromise unsuspecting victims. A spokesperson for the IRS has confirmed that they do not solicit anything by email. US-CERT reminds users to remain cautious when receiving unsolicited email that could be a potential phishing email. US-CERT reminds users to remain cautious when receiving unsolicited email. US-CERT encourages users to report phishing incidents based on the following guidelines:
Additionally, users are encouraged to take the following measures to prevent phishing attacks from occurring:
Proof-of-Concept Code for a Vulnerability in Apple QuickTimeadded January 2, 2007 | updated January 3, 2007US-CERT is aware of proof-of-concept code for a buffer overflow vulnerability in Apple QuickTime. The flaw is in the way that QuickTime handles Real Time Streaming Protocol (RTSP) URL strings. By persuading a user to access a specially crafted QuickTime file, a remote attacker may be able to execute arbitrary code or cause a denial of service on a vulnerable system. Note: Apple iTunes installations are also affected by this vulnerability. More information about this vulnerability can be found in the following:
Until a security fix or more information becomes available, US-CERT recommends the following action to help mitigate the security risks:
Public Exploit Code Available for DoS Vulnerability in Microsoft Windows Workstationadded December 27, 2006US-CERT is aware of a publicly available exploit code for a buffer overflow vulnerability in Microsoft Windows Workstation. According to Secunia Advisory SA23487, there is a flaw in the way the Workstation service handles large RPC requests. By sending specially crafted data to the Workstation service, a remote attacker could cause a denial-of-service condition on a vulnerable system. Initial analysis indicates that Windows XP and Windows 2000 are vulnerable to this flaw. Until a security fix from Microsoft becomes available, US-CERT recommends the following action to help mitigate the security risks:
US-CERT will continue to investigate and will provide additional information as it becomes available. Proof-of-Concept Code for Vulnerability in Microsoft Windowsadded December 26, 2006US-CERT is aware of publicly available proof-of-concept code for a local privilege escalation vulnerability in Microsoft Windows 2000, Windows Server 2003, Windows XP, and Windows Vista. More information concerning this flaw is available at the Microsoft Security Response Center Blog. US-CERT will continue to investigate and will provide additional information as it becomes available. Mozilla Releases Security Advisories to Address Multiple Vulnerabilitiesadded December 20, 2006 | updated December 21, 2006Mozilla has released Security Advisories to correct multiple vulnerabilities in Firefox, Thunderbird, and SeaMonkey. If successfully exploited, these vulnerabilities may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition on a vulnerable system. More information about these vulnerabilities can be found in the following:
US-CERT strongly encourages users to take the following actions to help mitigate the security risks:
Microsoft Publishes New Information on the Three Word Vulnerabilitiesadded December 19, 2006Microsoft has published new information on its Security Response Center Blog addressing the latest Word vulnerabilities reported earlier this month. Until a security fix from Microsoft becomes available, US-CERT recommends that users follow the recommendations in Microsoft Security Advisory 929433 to help mitigate the security risks for all three Word vulnerabilities. |
|||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
