Skip to content

customize
Current Activity Calendar
Left Arrow
January 2008
Right Arrow
Su M Tu W Th F Sa
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • January 22, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    January 22SymbianOS Worm
    January 18Skype Releases Security Bulletin to Address Cross Zone Scripting Vulnerability
    January 18Citrix Releases Update to Address Vulnerability
    January 17Adobe Releases Security Bulletins to Address Multiple Cross-Site Scripting Vulnerabilities
    January 17Oracle Releases Critical Patch Update for January 2008
    January 17Cisco Releases Security Advisory to Address Vulnerability in Cisco Unified Communication Manager
    January 16Apple Releases Security Updates to Address Multiple Vulnerabilities



    SymbianOS Worm

    added January 22, 2008 at 01:26 pm

    US-CERT is aware of public reports of a malicious SymbianOS worm that may be spreading on mobile phone networks.

    The SymbOS/Beselo.A! worm may affect mobile devices running SymbianOS using MMS and Bluetooth. It is reported that this worm spreads by convincing users to install an incoming file that contains the malicious code. These malicious files are noted to have, but are not limited to, the following file names:

    • Beauty.jpg
    • Sex.mp3
    • Love.rm
    US-CERT  encourages users to
    • Use caution when accepting incoming files via MMS and Bluetooth
    • Secure Bluetooth connections to prevent access from unauthorized devices
    • Install anti-virus software and keep its virus signature files up-to-date


    Skype Releases Security Bulletin to Address Cross Zone Scripting Vulnerability

    added January 18, 2008 at 03:18 pm

    Skype has released Security Bulletin SKYPE-SB/2008-001 to address a cross zone scripting vulnerability. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on an affected system.

    As per Security Bulletin SKYPE-SB/2008-001, Skype has temporarily disabled users' ability to add videos from Dailymotion gallery until an official fix has been made available.

    US-CERT will provide more information as it become available.


    Citrix Releases Update to Address Vulnerability

    added January 18, 2008 at 03:18 pm

    Citrix has released Knowledge Center Article CTX114487 to address a vulnerability in Citrix Presentation Server's IMA Service. This vulnerability may allow an attacker to execute arbitrary code on an affected system.

    US-CERT encourages users to review Citrix Knowledge Center Article CTX114487 and apply the appropriate hotfix as soon as possible.

    US-CERT will continue to investigate and provide additional information as it becomes available.


    Adobe Releases Security Bulletins to Address Multiple Cross-Site Scripting Vulnerabilities

    added January 17, 2008 at 02:35 pm

    Adobe has issued Security Bulletin APSB08-01 and Security Bulletin APSB08-02 to address multiple vulnerabilities in Adobe Dreamweaver, Adobe Contribute, and Adobe Connect Enterprise Server. These software packages may contain cross-site scripting vulnerabilities that could allow a remote, unauthenticated attacker to execute arbitrary code on an affected system.

    US-CERT encourages users to review Security Bulletin APSB08-01 for the Adobe Dreamweaver and Adobe Contribute updates and Security Bulletin APSB08-02 for the Adobe Connect Enterprise Server update. Users are also encouraged to apply the appropriate updates as soon as possible.

    US-CERT will continue to investigate and provide additional information as it becomes available.


    Oracle Releases Critical Patch Update for January 2008

    added January 16, 2008 at 02:18 pm | updated January 17, 2008 at 02:35 pm

    Oracle has released their Critical Patch Update (CPU) for January 2008 to address 26 vulnerabilities across several products. This CPU contains eight security fixes for Oracle Database products; six for Oracle Application Server; one for Oracle Collaboration Suite; seven for Oracle E-Business Suite; and four for Oracle PeopleSoft Enterprise PeopleTools.

    US-CERT strongly encourages users to review the January CPU and follow best-practice security policies to determine which updates to apply.

    More information regarding these vulnerabilities can be found in Technical Cyber Security Alert TA08-017A.


    Cisco Releases Security Advisory to Address Vulnerability in Cisco Unified Communication Manager

    added January 17, 2008 at 10:45 am

    Cisco has released Security Advisory cisco-sa-20080116-cucmctl to address a heap overflow in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM). This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service condition on an affected system.

    More information regarding this vulnerability can be found in the Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow.

    US-CERT strongly recommends that administrators review the Cisco Security Advisory above and follow best-practice security policies to determine what updates or workarounds should be applied.


    Apple Releases Security Updates to Address Multiple Vulnerabilities

    added January 16, 2008 at 02:18 pm | updated January 16, 2008 at 03:56 pm

    Apple has released QuickTime 7.4, iPhone v1.1.3, and iPod touch v1.1.3 to address multiple vulnerabilities in these products. The impacts of these vulnerabilities include arbitrary code execution, application termination, authentication bypass, and cross-site scripting.

    US-CERT encourages users to review Apple Article 307301 for the QuickTime update and Apple Article 307302 for the iPhone and iPod touch updates. Users are also encouraged to apply the appropriate updates as soon as possible.

    More information regarding the QuickTime vulnerabilies can be found in Technical Cyber Security Alert TA08-016A.

    US-CERT will continue to investigate and provide additional information as it becomes available.