Skip to content

customize
Current Activity Calendar
Left Arrow
October 2008
Right Arrow
Su M Tu W Th F Sa
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • October 29, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    October 29OpenOffice.org Releases Two Security Bulletins
    October 27Microsoft Releases Security Advisory 958963
    October 27Microsoft Releases Out-of-Band Security Bulletin MS08-067
    October 23Cisco Releases Advisory for Cisco PIX and ASA
    October 23Microsoft Releases Advance Notification for Out-of-Band October Security Bulletin
    October 22Trend Micro OfficeScan Critical Patch Release
    October 21F-Secure Releases Security Bulletin FSC-2008-3
    October 16Adobe Releases Security Bulletin for Flash Player
    October 15Oracle Releases Critical Patch Update for October 2008
    October 14Microsoft Updates Security Advisory 951306



    OpenOffice.org Releases Two Security Bulletins

    added October 29, 2008 at 11:38 am

    OpenOffice.org has released bulletins to address two vulnerabilities. These bulletins address heap-based buffer overflow vulnerabilities in the processing of WMF and EMF files. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code.

    US-CERT encourages users and administrators to review the following OpenOffice.org security bulletins and apply the resolutions provided by the vendor:


    Microsoft Releases Security Advisory 958963

    added October 27, 2008 at 08:16 pm

    Microsoft has released Security Advisory 958963 to alert users that exploit code is publicly available for the Windows Server Service vulnerability addressed in Microsoft Security Bulletin MS08-067. The advisory states that this exploit code has demonstrated arbitrary code execution on Windows 2000, XP and Server 2003.

    US-CERT encourages users and administrators to review Microsoft Security Advisory 958963 and apply the update or workarounds listed in Microsoft Security Bulletin MS08-067 to help mitigate the risks.

    Additional information regarding the Windows Server Service vulnerability is available in:


    Microsoft Releases Out-of-Band Security Bulletin MS08-067

    added October 23, 2008 at 01:08 pm | updated October 27, 2008 at 09:44 am

    Update: The Microsoft Security Response Center (MSRC) has posted a blog entry to provide additional information regarding the status of this vulnerability and the state of security update deployments. Users and administrators are encouraged to review the blog entry as it provides information about known malicious code targeting this vulnerability.

    Microsoft has released Security Bulletin MS08-067 to address a vulnerability in the Windows Server Service. This vulnerability is due to improper handling of specially crafted RPC requests. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.

    US-CERT encourages users and administrators to review Microsoft Security Bulletin MS08-067 and apply any necessary updates to help mitigate the risks. Additional information is also available in Vulnerability Note VU#827267.


    Cisco Releases Advisory for Cisco PIX and ASA

    added October 23, 2008 at 07:59 am

    Cisco Security Advisory cisco-sa-20081022-asa was released to address multiple vulnerabilities in Cisco ASA and PIX. These vulnerabilities may allow an attacker to bypass authentication mechanisms or cause a denial-of-service condition.

    US-CERT encourages users and administrators to review Cisco Security Advisory cisco-sa-20081022-asa and apply any necessary updates or workarounds to help mitigate the risks.


    Microsoft Releases Advance Notification for Out-of-Band October Security Bulletin

    added October 23, 2008 at 07:47 am

    Microsoft has issued a Security Bulletin Advance Notification indicating the upcoming release of an out-of-band bulletin. The notification states that this is a Critical bulletin and is for Microsoft Windows. Release of this bulletin is scheduled for Thursday, October 23.

    US-CERT will provide additional information as it becomes available.


    Trend Micro OfficeScan Critical Patch Release

    added October 22, 2008 at 09:05 am

    Trend Micro has released a Critical Patch to address a vulnerability in OfficeScan. This vulnerability is due to a stack-based buffer overflow condition. By sending a specially crafted HTTP request containing form data to the server CGI module, an attacker may be able to execute arbitrary code on the affected system.

    US-CERT encourages users and administrators to review Trend Micro Critical Patch Release overview for Build 1374 and Build 3110 and apply any necessary updates to help mitigate the risks.


    F-Secure Releases Security Bulletin FSC-2008-3

    added October 21, 2008 at 02:11 pm

    F-Secure has released a Security Bulletin to address a vulnerability that affects a number of their products. This vulnerability is due to improper RPM parsing. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.

    US-CERT encourages users to review F-Secure Security Bulletin FSC-2008-3 and apply any necessary updates to help mitigate the risks.


    Adobe Releases Security Bulletin for Flash Player

    added October 16, 2008 at 12:38 pm

    Adobe has released a Security Bulletin to address multiple security issues in Flash Player. Some of these issues may allow an attacker to conduct clickjacking types of attacks that could enable the camera or microphone through Flash Player. Additional information about clickjacking attacks can be found in a recently posted Current Activity entry.

    US-CERT encourages users and administrators to review the Adobe Security Bulletin and upgrade to Flash Player version 10.0.12.36 to help mitigate the risks.


    Oracle Releases Critical Patch Update for October 2008

    added October 15, 2008 at 09:14 am

    Oracle has released their Critical Patch Update for October 2008 to address 36 vulnerabilities across several products. This update contains the following security fixes:

    • 15 updates for Oracle Database Suite
    • 6 updates for Oracle Application Server
    • 4 updates for Oracle E-Business Suite and Applications
    • 5 updates for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne
    • 6 Updates for BEA Product Suite
    US-CERT encourages users and administrators to review the Critical Patch Update for October 2008 and apply any necessary updates.


    Microsoft Updates Security Advisory 951306

    added October 14, 2008 at 01:53 pm

    In April 2008, Microsoft released Security Advisory 951306 to alert users of a vulnerability in Microsoft Windows. This vulnerability may allow local users, or users who can legitimately run code in the context of IIS or SQL Server, to operate with elevated privileges. Recently, Microsoft Security Response Center (MSRC) posted several blog entries indicating that the Security Advisory was updated to reflect the availability of public exploit code. A patch or update is not available to correct this issue.

    US-CERT encourages users and administrators to do the following to help mitigate the risks: