Current Activity Calendar
| January 16, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Apple Releases Security Updates to Address Multiple Vulnerabilitiesadded January 16, 2008 at 02:18 pm | updated January 16, 2008 at 03:56 pm
Apple has released QuickTime 7.4, iPhone v1.1.3, and iPod touch v1.1.3 to address multiple vulnerabilities in these products. The impacts of these vulnerabilities include arbitrary code execution, application termination, authentication bypass, and cross-site scripting. Microsoft Office Excel Remote Code Vulnerabilityadded January 16, 2008 at 07:48 am | updated January 16, 2008 at 03:41 pm
Microsoft has released Security Advisory 947563 to address a vulnerability in Excel. Successful exploitation could allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the local user.
New Storm Worm Variant Spreadsadded January 16, 2008 at 02:18 pm
US-CERT has received reports of new Storm Worm
activity circulating. The emails contain
romantic or Valentine's Day greetings and provide links for users to click
on. The links are in the form of actual
IP addresses, such as http:/x.x.x.x, although actual domain names may also be
used. If a user clicks on the link
provided, they will be directed to a malicious website that will attempt to
exploit a variety of vulnerabilities and install malware onto the user's
system.
Oracle Releases Critical Patch Update for January 2008added January 16, 2008 at 02:18 pm
Oracle has released their Critical Patch Update (CPU) for January 2008 to address 26 vulnerabilities across several products. This CPU contains eight security fixes for Oracle Database products; six for Oracle Application Server; one for Oracle Collaboration Suite; seven for Oracle E-Business Suite; and four for Oracle PeopleSoft Enterprise PeopleTools. Fraudulent Mac OS Security Tool Circulatingadded January 15, 2008 at 12:33 pm | updated January 15, 2008 at 05:19 pm
US-CERT is aware of reports of a rogue security scanning tool circulating for Apple Mac OS, known as MacSweeper. The website hosting the tool appears to offer a free scan that when clicked on, highlights purported security issues on a users system. The website then indicates that a subscription fee is necessary in order to fix the alleged issues. Researchers have raised concern over the legitimacy of this tool and point to discrepancies in the language used to describe the software, citing plagiarism from well-known security vendor websites. In addition, some users on the Apple message boards have indicated that they are automatically being directed to the MacSweeper website while browsing online. Attack Vector Targets UPnPadded January 14, 2008 at 03:37 pm | updated January 15, 2008 at 05:01 pm
US-CERT is aware of an attack vector targeting networking devices that support UPnP (Universal Plug and Play). This specific attack occurs via a maliciously crafted SWF file that is contained in a web site. When the web site is visited, changes may occur to a router's configuration via UPnP. This may allow an attacker to change any parameter on the router or device that can be set by UPnP. QuickTime Real Time Streaming Protocol Vulnerabilityadded January 10, 2008 at 03:49 pm | updated January 11, 2008 at 11:07 am
US-CERT is aware of a public report of a vulnerability in Apple QuickTime. The flaw is in the way that QuickTime handles Real Time Streaming Protocol (RTSP) Response message headers. By persuading a user to access a specially crafted QuickTime file, or RTSP stream, a remote attacker may be able to execute arbitrary code or cause a denial of service on a vulnerable system. |
|||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
