Skip to content

customize
Current Activity Calendar
Left Arrow
April 2007
Right Arrow
Su M Tu W Th F Sa
1
2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • April 30, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    April 30OPeNDAP Releases Update to Address Vulnerability in Network Data Access Protocol Software
    April 30Cisco Releases Security Advisory to Address Vulnerability in NetFlow Collection Engine
    April 26Adobe Photoshop Bitmap File Handling Vulnerability
    April 26Vulnerability in HP-UX Running Sendmail
    April 24Vulnerability Involving Apple QuickTime and Java
    April 20New Attack Technique for ARM Architecture
    April 20Multiple Vulnerabilities in MIT Kerberos 5



    OPeNDAP Releases Update to Address Vulnerability in Network Data Access Protocol Software

    added April 30, 2007 at 10:06 am

    OPeNDAP has released an update to address a vulnerability in Version 3 of the OPeNDAP Network Data Access Protocol software.

    US-CERT encourages administrators to apply the fixes and workarounds described in Vulnerability Note VU#857153 and in the OPeNDAP Server 3 update.


    Cisco Releases Security Advisory to Address Vulnerability in NetFlow Collection Engine

    added April 26, 2007 at 10:46 am | updated April 30, 2007 at 10:05 am

    Cisco has released Security Advisory cisco-sa-20070425-nfc to address a vulnerability in Cisco NetFlow Collection Engine. Upon installation, default user credentials are created on the system. A remote attacker with knowledge of these hard-coded credentials may be able to gain access to an affected system.

    US-CERT encourages administrators to apply the fixes and workarounds described in Vulnerability Note VU#127545 and Security Advisory cisco-sa-20070425-nfc


    Adobe Photoshop Bitmap File Handling Vulnerability

    added April 26, 2007 at 10:46 am

    US-CERT is aware of a possible vulnerability in Adobe Photoshop that may allow an attacker to cause a stack-based buffer overflow. By persuading a user to open a crafted bitmap file (e.g., .BMP, .DIB, .RLE), an attacker may be able to execute arbitrary code on the user's system.

    US-CERT recommends that users not open untrusted bitmap files, and will continue to investigate and provide additional information as it becomes available.


    Vulnerability in HP-UX Running Sendmail

    added April 25, 2007 at 11:15 am | updated April 26, 2007 at 09:39 am

    US-CERT is aware of a vulnerability in HP-UX running sendmail that may allow a remote user to cause a denial-of-service condition.

    US-CERT recommends users apply the patches as described in HP Technical Knowledge Base Document c00841370.  Please note that logon credentials may be needed to access this document.

    More information regarding this vulnerability is available in Vulnerability Note VU#349305.


    Vulnerability Involving Apple QuickTime and Java

    added April 24, 2007 at 04:07 pm

    US-CERT is aware of a new vulnerability involving Apple QuickTime and Java. Any platform supporting QuickTime and Java may be affected. Details about the vulnerability are currently limited; however, it is reported that disabling Java will protect users.

    US-CERT recommends users follow the Securing Your Web Browser document to disable Java.

    US-CERT will continue to investigate this vulnerability and provide more information as it becomes available.


    New Attack Technique for ARM Architecture

    added April 20, 2007 at 12:00 pm

    US-CERT is aware of a new attack technique presented at CansecWest and Black Hat Amsterdam. This technique affects devices that use the ARM (including Xscale) architecture, such as routers, wireless access points and mobile phones. The technique demonstrates that a vulnerability that results in a NULL pointer dereference can be used to execute arbitrary code.

    US-CERT has been working with vendors to inform them of this attack technique and provide mitigation strategies.

    US-CERT will continue to investigate and provide additional information as it becomes available.


    Multiple Vulnerabilities in MIT Kerberos 5

    added April 19, 2007 at 05:00 pm | updated April 20, 2007 at 09:00 am

    US-CERT is aware of multiple vulnerabilities affecting the MIT Kerberos 5 implementation. The most severe of these vulnerabilities may allow a remote attacker to execute arbitrary code on a Kerberos Distribution Center (KDC), which may result in a compromise of the Kerberos key database.

    More information about these vulnerabilities can be found in the following:

    US-CERT recommends users apply the patches as described in MIT krb5 Security Advisories 2007-001, 2007-002, and 2007-003.