Skip to content

customize
Current Activity Calendar
Left Arrow
June 2007
Right Arrow
Su M Tu W Th F Sa
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • June 07, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    June 7Microsoft Releases Advance Notification for June Security Bulletins
    June 7Computer Associates Release Security Notice for Anti-Virus Engine
    June 6Sun Microsystems Releases Security Advisory for Java Runtime Environment Image Parsing Code
    June 6Microsoft Windows GDI+ ICO Vulnerability
    June 6PHP Vulnerabilty
    June 5Microsoft Internet Explorer and Mozilla Firefox Vulnerabilities
    June 1Apple Releases Update for Xserve Lights-Out Management Firmware



    Microsoft Releases Advance Notification for June Security Bulletins

    added June 7, 2007 at 03:23 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that their June release cycle will contain six bulletins, four of which have a maximum severity rating of Critical. The notification further states that the four Critical bulletins are for Windows, Internet Explorer, and Outlook Express.  There will also be two non-critical bulletins for Visio and Windows as well as an updated version of the Microsoft Windows Malicious Software Removal Tool.  The release is scheduled for Tuesday, June 12, 2007.

    US-CERT will provide additional information as it becomes available.


    Computer Associates Release Security Notice for Anti-Virus Engine

    added June 7, 2007 at 03:20 pm

    The Computer Associates Anti-Virus engine fails to properly process CAB archives.  These vulnerabilities may allow an unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition.

    More information can be found in the following:

    US-CERT encourages users to apply the updates as described in the Computer Associates Security Notice.


    Sun Microsystems Releases Security Advisory for Java Runtime Environment Image Parsing Code

    added June 6, 2007 at 09:02 am | updated June 6, 2007 at 01:20 pm

    Sun Microsystems released a Security Advisory for the Java Runtime Environment Image Parsing Code.  This vulnerability may allow an applet to read and write local files or execute local applications. 

    US-CERT encourages users to examine the resolutions that are described in the Sun Security Advisory as soon as possible and follow the steps in the Securing Your Web Browser document.

    More information can be found in Vulnerability Note VU#138545


    Microsoft Windows GDI+ ICO Vulnerability

    added June 6, 2007 at 11:56 am | updated June 6, 2007 at 01:18 pm

    Microsoft Windows Graphics Device Interface is vulnerable to an integer division-by-zero error.  This vulnerability may lead to a denial-of-service condition due to the introduction of a specially crafted icon file.

    It may be possible for a malformed icon file to be embedded in an executable or other file.

    More information can be found in the following:

    US-CERT strongly encourages users to review the bulletin and follow best-practice security policies to determine what actions should be applied.


    PHP Vulnerabilty

    added June 5, 2007 at 03:33 pm | updated June 6, 2007 at 11:07 am

    US-CERT is aware of a publicly reported vulnerability in PHP.  PHP version 5.2.3 may be vulnerable to an integer overflow within the chunk_split() function.

    More information can be found in the following PHP Security Blog.

    US-CERT will provide additional information as it becomes available.


    Microsoft Internet Explorer and Mozilla Firefox Vulnerabilities

    added June 4, 2007 at 03:25 pm | updated June 5, 2007 at 09:33 am

    US-CERT is aware of a public report of multiple vulnerabilities in Mozilla Firefox and Microsoft Internet Explorer.

    More information can be found in Vulnerability Note VU#471361.

    US-CERT encourages users to follow the steps in the Securing Your Web Browser document.


    Apple Releases Update for Xserve Lights-Out Management Firmware

    added June 1, 2007 at 03:48 pm

    Apple releases Firmware Update 1.0 to address a vulnerability in Xserve Lights-Out Management Firmware.  The vulnerability lies in Apple's implementation of IPMI and may allow a remote, unprivileged ipmitool user to gain administrative privileges on a Xserve system.

    US-CERT encourages users to apply Firmware Update 1.0 as soon as possible.

    US-CERT will continue to investigate this vulnerability and provide additional details as they become available.