Skip to content

customize
Current Activity Calendar
Left Arrow
March 2008
Right Arrow
Su M Tu W Th F Sa
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • March 31, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    March 31Internal Revenue Service Scams
    March 26Mozilla Releases Firefox 2.0.0.13
    March 26Cisco Releases Security Advisories
    March 26Novell eDirectory Vulnerability
    March 26VLC Media Player Vulnerability
    March 21Microsoft Jet Database Engine Vulnerability
    March 21Apple Aperture and iPhoto Vulnerability
    March 19Microsoft Releases Windows Vista Service Pack 1
    March 19MIT Kerberos Security Advisories
    March 19Apple Security Updates



    Internal Revenue Service Scams

    added March 31, 2008 at 03:27 pm

    US-CERT is aware of a series of scams circulating that are related to the United States Internal Revenue Service.

    The first of these attacks attempts to convince users to open bogus tax documents that may contain malicious code. Additional attacks attempt to convince users to follow a link in an email message to an unofficial tax website that may contain malicious code or request personal information as part of a phishing scam.

    US-CERT encourages users to do the following to help mitigate the risks:


    Mozilla Releases Firefox 2.0.0.13

    added March 26, 2008 at 08:23 am | updated March 26, 2008 at 02:27 pm

    Mozilla has released Firefox 2.0.0.13. This version addresses multiple vulnerabilities that may allow an attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information, or conduct cross-site scripting or phishing attacks.  As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect Thunderbird and SeaMonkey.

    US-CERT encourages users to do the following to help mitigate the risks:


    Cisco Releases Security Advisories

    added March 26, 2008 at 02:15 pm

    Cisco has released five security advisories to address multiple vulnerabilities in Cisco IOS. These vulnerabilities may allow a remote, unauthenticated attacker to cause a denial-of-service condition on the affected device.

    US-CERT encourages users to review the Cisco Security Advisories and apply the appropriate updates or workarounds.


    Novell eDirectory Vulnerability

    added March 26, 2008 at 08:23 am

    Novell has released Security Vulnerability document 3382120 to address a vulnerability in eDirectory. This vulnerability is caused by improper handling of large LDAP Extended Request messages. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users to review Novell document 3382120 and update to eDirectory 8.8.2.


    VLC Media Player Vulnerability

    added March 26, 2008 at 08:23 am

    VLC has released a patch to address an integer overflow vulnerability in VLC Media Player. By convincing a user to open an MP4 file with a specially crafted RDRF atom, a remote attacker may be able to execute arbitrary code.

    For users who compile VLC Media Player from source, VLC has provided a patch to address this issue.

    US-CERT will provide more information as it becomes available.


    Microsoft Jet Database Engine Vulnerability

    added March 21, 2008 at 09:54 pm

    Microsoft has released a Security Advisory to address a vulnerability in Microsoft Jet Database Engine. This vulnerability is due to a buffer overflow condition in msjet40.dll. By convincing a user to open a Word document that is designed to load a specially crafted database file using msjet40.dll, an attacker may be able execute arbitrary code.

    US-CERT encourages users to review Microsoft Security Advisory 950627 and apply the suggested workarounds.

    US-CERT will provide more information as it becomes available.


    Apple Aperture and iPhoto Vulnerability

    added March 21, 2008 at 10:14 am

    Apple has released Digital Camera RAW Compatibility Update 2.0 to address a vulnerability in Apple Aperture and iPhoto. This vulnerability is due to a boundary error that occurs when processing DNG image files. By convincing a user to open a specially crafted image file, a remote attacker may be able to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users to review Apple knowledgebase article HT1232 and apply any necessary updates.

    US-CERT will provide more information as it becomes available.


    Microsoft Releases Windows Vista Service Pack 1

    added March 19, 2008 at 04:53 pm

    Microsoft has released Windows Vista Service Pack 1.  This Service Pack provides updates to increase reliability, performance, compatibility, and security.

    US-CERT encourages users review the following Microsoft articles:


    MIT Kerberos Security Advisories

    added March 19, 2008 at 07:41 am | updated March 19, 2008 at 03:12 pm

    MIT has released two Security Advisories to address multiple vulnerabilities in Kerberos 5. These vulnerabilities affect krb4-enabled KDC servers and the GSS RPC library used by kadmind. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code, obtain sensitive information, or cause a denial of service condition.

    US-CERT encourages users to do the following to help mitigate the risks:

    US-CERT will provide more information as it becomes available.


    Apple Security Updates

    added March 18, 2008 at 05:08 pm | updated March 19, 2008 at 03:03 pm

    Apple has released Safari 3.1 and Security Update 2008-002 to address multiple vulnerabilities.

    These vulnerabilities may allow an attacker to do the following:

    • Execute arbitrary code
    • Cause a denial-of-service condition
    • Bypass authentication
    • Elevate privileges
    • Obtain sensitive information
    • Cause untrusted certificates to appear trusted
    US-CERT encourages users to do the following to help mitigate the risk:
    • Review Apple Article 307563 and upgrade to Safari 3.1.
    • Review Apple Security Update 2008-002 and apply any necessary updates.
    • Review Technical Cyber Security Alert TA08-079A.
    US-CERT will provide more information as it becomes available.