Skip to content

customize
Current Activity Calendar
Left Arrow
September 2008
Right Arrow
Su M Tu W Th F Sa
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • September 09, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    September 9Microsoft Releases September Security Bulletin
    September 9Google Releases Chrome Version 0.2.149.29
    September 9WordPress Releases Version 2.6.2
    September 8Exploit Code Available for CitectSCADA Vulnerability
    September 5Cisco Releases Advisory and Security Response
    September 4Microsoft Releases Advance Notification for September Security Bulletin
    September 4FCC Releases Public Notice about Phishing Scam
    September 4Novell Releases Update for iPrint Vulnerability
    September 3Google Chrome Download Vulnerability
    September 2VMware Releases Security Announcement



    Microsoft Releases September Security Bulletin

    added September 9, 2008 at 01:10 pm

    Microsoft has released updates to address vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, and Visual Studio as part of the Microsoft Security Bulletin Summary for September 2008. These vulnerabilities may allow an attacker to execute arbitrary code.

    US-CERT encourages users to review the bulletins and follow best-practice security policies to determine which updates should be applied.


    Google Releases Chrome Version 0.2.149.29

    added September 9, 2008 at 09:14 am

    Google has released Chrome version 0.2.149.29 to address multiple vulnerabilities. The four vulnerabilities are due to the following:

    1. a buffer overflow condition in the handling of filenames displayed in the "Save As" dialog
    2. a buffer overflow condition in the handling of link targets displayed in the status area when a user hovers over a link
    3. an out-of-bounds memory read error when parsing URLs ending with :%
    4. a default configuration that allows files to be downloaded to the desktop without prompting the user first
    Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    Google has indicated that the fixed version is being applied to all users through automatic updates. US-CERT encourages users to review the Chrome 0.2.149.29 release notes and upgrade if the newest version has not been automatically applied.


    WordPress Releases Version 2.6.2

    added September 9, 2008 at 08:47 am

    WordPress has released version 2.6.2 to address multiple vulnerabilities. These vulnerabilities are due to SQL column truncation and weaknesses in random number generation. Combined, these vulnerabilities may allow an attacker to reset a user's password and possibly predict the newly generated password. Exploitation of these vulnerabilities could permit an attacker to gain access to a system running WordPress with open registration enabled under the context of a legitimate user.

    US-CERT encourages users to review the WordPress Blog entry related to these issues and upgrade to version 2.6.2 as necessary.


    Exploit Code Available for CitectSCADA Vulnerability

    added September 8, 2008 at 04:15 pm

    In June, US-CERT published Vulnerability Note VU#476345 to alert users of a vulnerability affecting Citect CitectSCADA. This vulnerability is due to a buffer overflow condition in the handling of ODBC requests from clients. Exploit code for this vulnerability is publicly available and exploitation may allow an attacker to execute arbitrary code.

    US-CERT encourages users to review Vulnerability Note VU#476345 and apply the patch as described in the document.


    Cisco Releases Advisory and Security Response

    added September 5, 2008 at 07:55 am

    Cisco has released a Cisco Security Advisory to address multiple vulnerabilities in Cisco PIX and ASA. These vulnerabilities may allow an attacker to cause a denial-of-service condition or obtain sensitive information. Additionally, Cisco has released a Security Response to address a vulnerability in Cisco Secure ACS. This vulnerability may allow an attacker to cause a denial-of-service condition on the affected system.

    US-CERT encourages users to review Cisco Security Advisory cisco-sa-20080903-asa, review Cisco Security Response document 107443, and apply any necessary workarounds or updates listed in those documents to help mitigate the risks.


    Microsoft Releases Advance Notification for September Security Bulletin

    added September 4, 2008 at 03:18 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that its September release cycle will contain four bulletins, all of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, and Visual Studio. Release of these bulletins is scheduled for Tuesday, September 9.

    US-CERT will provide additional information as it becomes available.


    FCC Releases Public Notice about Phishing Scam

    added September 4, 2008 at 03:17 pm

    The Federal Communications Commission (FCC) has released a public notice alerting users of a potential phishing attack. The notice indicates that non-government entities may be using websites to misdirect regulatory fee payers to an illegitimate website in an attempt to obtain their financial information.

    US-CERT encourages users to review the FCC public notice (pdf) and refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.


    Novell Releases Update for iPrint Vulnerability

    added September 4, 2008 at 03:15 pm

    Novell has released an update to address multiple vulnerabilities in iPrint. These vulnerabilities are due to the following:

    • multiple buffer overflow conditions within the Novell iPrint ActiveX control (ienipp.ocx)
    • multiple buffer overflow conditions within nipplib.dll
    • an insecure "GetFileList()" method
    Exploitation of this vulnerability may allow an attacker to execute arbitrary code or obtain sensitive information.

    US-CERT encourages users to review Novell documents 5034540 and 5034560 and apply any necessary updates.


    Google Chrome Download Vulnerability

    added September 3, 2008 at 01:52 pm

    US-CERT is aware of a vulnerability that affects the Google Chrome web browser. This vulnerability is due to a default configuration that allows files to be downloaded without prompting the user. In addition, downloaded files can be opened with a single click, which could allow a user to inadvertently open a malicious file.

    US-CERT encourages users to enable the "Ask where to save each file before downloading" option within the "Minor Tweaks" tab in the browser preferences. Although this does not fix the underlying vulnerability, selecting this option will warn the user before files are downloaded. Users should still exercise caution when visiting and downloading items from untrusted websites.

    US-CERT will provide additional information as it becomes available.


    VMware Releases Security Announcement

    added September 2, 2008 at 03:00 pm

    VMware has released a security announcement to address multiple vulnerabilities in VMware Workstation, VMware Player, VMware ACE, VMware Server, and VMware ESX. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, access the system with elevated privileges, or obtain sensitive information.

    US-CERT encourages users and administrators to review the VMware security announcement and apply any necessary updates.