Skip to content

customize
Current Activity Calendar
Left Arrow
May 2007
Right Arrow
Su M Tu W Th F Sa
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • May 09, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    May 9Microsoft Releases May Security Bulletin
    May 3Microsoft Releases Advance Notification for May Security Bulletins
    May 2Cisco Releases Security Advisory to Address Multiple Vulnerabilities in ASA and PIX Appliances
    April 30OPeNDAP Releases Update to Address Vulnerability in Network Data Access Protocol Software
    April 30Cisco Releases Security Advisory to Address Vulnerability in NetFlow Collection Engine
    April 26Adobe Photoshop Bitmap File Handling Vulnerability
    April 26Vulnerability in HP-UX Running Sendmail



    Microsoft Releases May Security Bulletin

    added May 8, 2007 at 02:20 pm | updated May 9, 2007 at 10:11 am

    Microsoft has released updates to address vulnerabilities in Microsoft Windows, Internet Explorer, Windows DNS RPC Interface, Office, Exchange, CAPICOM, and BizTalk as part of the Microsoft Security Bulletin Summary for May 2007.

    More information about these vulnerabilities is located in the Vulnerability Notes Database and Technical Cyber Security Alert TA07-128A.

    US-CERT strongly encourages users to review the bulletins and follow best-practice security policies to determine what updates should be applied.


    Microsoft Releases Advance Notification for May Security Bulletins

    added May 3, 2007 at 04:03 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that their May release cycle will contain seven bulletins, some of which have a maximum rating of Critical. The notification further states that two of the bulletins are for Windows; three for Office; one for Exchange; and one for CAPICOM and BizTalk. The release is scheduled for May 8, 2007.

    US-CERT will provide additional information as it becomes available.


    Cisco Releases Security Advisory to Address Multiple Vulnerabilities in ASA and PIX Appliances

    added May 2, 2007 at 03:59 pm | updated May 2, 2007 at 04:30 pm

    Cisco has released Security Advisory cisco-sa-20070502-asa to address multiple vulnerabilities in Cisco ASA and PIX appliances.  These vulnerabilities include two authentication bypass vulnerabilities affecting the Lightweight Directory Access Protocol (LDAP) authentication system and two denial-of-service (DoS) vulnerabilities affecting Virtual Private Networks (VPNs).

    More information about these vulnerabilities can be found in the Vulnerability Notes Database.

    US-CERT recommends administrators apply the workarounds and patches as described in Cisco Security Advisory cisco-sa-20070502-asa.


    OPeNDAP Releases Update to Address Vulnerability in Network Data Access Protocol Software

    added April 30, 2007 at 10:06 am

    OPeNDAP has released an update to address a vulnerability in Version 3 of the OPeNDAP Network Data Access Protocol software.

    US-CERT encourages administrators to apply the fixes and workarounds described in Vulnerability Note VU#857153 and in the OPeNDAP Server 3 update.


    Cisco Releases Security Advisory to Address Vulnerability in NetFlow Collection Engine

    added April 26, 2007 at 10:46 am | updated April 30, 2007 at 10:05 am

    Cisco has released Security Advisory cisco-sa-20070425-nfc to address a vulnerability in Cisco NetFlow Collection Engine. Upon installation, default user credentials are created on the system. A remote attacker with knowledge of these hard-coded credentials may be able to gain access to an affected system.

    US-CERT encourages administrators to apply the fixes and workarounds described in Vulnerability Note VU#127545 and Security Advisory cisco-sa-20070425-nfc


    Adobe Photoshop Bitmap File Handling Vulnerability

    added April 26, 2007 at 10:46 am

    US-CERT is aware of a possible vulnerability in Adobe Photoshop that may allow an attacker to cause a stack-based buffer overflow. By persuading a user to open a crafted bitmap file (e.g., .BMP, .DIB, .RLE), an attacker may be able to execute arbitrary code on the user's system.

    US-CERT recommends that users not open untrusted bitmap files, and will continue to investigate and provide additional information as it becomes available.


    Vulnerability in HP-UX Running Sendmail

    added April 25, 2007 at 11:15 am | updated April 26, 2007 at 09:39 am

    US-CERT is aware of a vulnerability in HP-UX running sendmail that may allow a remote user to cause a denial-of-service condition.

    US-CERT recommends users apply the patches as described in HP Technical Knowledge Base Document c00841370.  Please note that logon credentials may be needed to access this document.

    More information regarding this vulnerability is available in Vulnerability Note VU#349305.