Skip to content

customize
Current Activity Calendar
Left Arrow
May 2009
Right Arrow
Su M Tu W Th F Sa
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • May 20, 2009 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    May 20NSD DNS Buffer Overflow Vulnerability
    May 20Cisco Releases Security Advisory for CiscoWorks TFTP Vulnerability
    May 20Mac OS X Includes Known Vulnerable Version of Java
    May 19Microsoft Internet Information Services (IIS) WebDAV Request Vulnerability
    May 18Gumblar Malware Exploit Circulating
    May 13Adobe Releases Security Updates for Adobe Reader and Acrobat
    May 13Apple Releases Security Update 2009-002, Mac OS X v10.5.7 and Safari 3.2.3
    May 13Microsoft Releases May Security Bulletin
    May 7Microsoft Releases Advance Notification for May Security Bulletin
    May 7Adobe Releases Security Bulletin for Flash Media Server



    NSD DNS Buffer Overflow Vulnerability

    added May 20, 2009 at 09:23 am | updated May 20, 2009 at 03:54 pm

    NLnet Labs has released a patch to address a vulnerability in NSD DNS versions 2.0.0 through 3.2.1. This vulnerability is due to an error in the way NSD processes certain types of packets that may lead to a buffer overflow. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to cause the DNS software to crash, resulting in a denial-of-service condition.

    US-CERT encourages users and administrators to review the NSD announcement regarding this vulnerability and apply any necessary updates or patches to help mitigate the risks. Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.


    Cisco Releases Security Advisory for CiscoWorks TFTP Vulnerability

    added May 20, 2009 at 01:31 pm

    Cisco has released a security advisory to address a vulnerability in CiscoWorks TFTP. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to view or modify application and host operating system files, possibly resulting in arbitrary code execution or a denial-of-service condition. The security advisory indicates that the following Cisco products are affected by this vulnerability:

    • Cisco Unified Service Monitor versions 1.0, 1.1, 2.0, and 2.1
    • CiscoWorks QoS Policy Manager versions 4.0 and 4.1
    • CiscoWorks LAN Management Solution versions 2.5, 2.6, and 3.0
    • Cisco Security Manager versions 3.0, 3.1, and 3.2
    • Cisco TelePresence Readiness Assessment Manager version 1.0
    • CiscoWorks Voice Manager versions 3.0 and 3.1
    • CiscoWorks Heath and Utilization Monitor versions 1.0 and 1.1
    • Cisco Unified Operations Manager versions 1.0, 1.1, 2.0 and 2.1
    • Cisco Unified Provisioning Manager versions 1.0, 1.1, 1.2 and 1.3
    US-CERT encourages users and administrators to review Cisco Security Advisory cisco-sa-20090520-cw and apply any necessary updates to help mitigate the risks.


    Mac OS X Includes Known Vulnerable Version of Java

    added May 20, 2009 at 11:22 am

    Current releases of Mac OS X (version 10.5.7 and version 10.4.11 with security update 2009-002) include a version of Java Runtime Environment (JRE) containing known security vulnerabilities. US-CERT is aware of publicly available exploit code for one of these vulnerabilities. This vulnerability may allow untrusted applets to obtain read, write, and execute permissions to local files and applications with the privileges of the local user. A fix for this vulnerability has been released by Sun, but Mac OS X users cannot apply the fix directly. Mac OS X users must use Apple updates to obtain updated JRE versions. At this time, Apple has not yet released an update to address this issue.

    US-CERT encourages Mac OS X users to disable Java in each web browser they use until a patch is available from Apple. Guidance for disabling Java can be found in the Securing Your Web Browser document. Please note that disabling Java may affect the functionality of websites that use Java.

    US-CERT will provide additional information as it becomes available.


    Microsoft Internet Information Services (IIS) WebDAV Request Vulnerability

    added May 18, 2009 at 08:54 am | updated May 19, 2009 at 08:02 am

    US-CERT is aware of public reports of a vulnerability affecting Microsoft Internet Information Services 6 (IIS6). Reports indicate that this vulnerability is due to improper handling of unicode tokens. Exploitation of this vulnerability may allow a remote attacker to bypass authentication methods, allowing an attacker to upload files to a WebDAV folder or obtain sensitive information. NTFS file ACLs will generally prevent the anonymous internet user from writing to an unauthorized area. US-CERT is also aware of publicly available exploit code and active exploitation of this vulnerability.

    US-CERT encourages users to implement the following workaround to help mitigate the risks until a patch or update is available from the vendor:

    Disable WebDAV. Administrators who are unable to disable WebDAV may be able to mitigate some risk by configuring their IDS to refuse external HTTP requests containing "Translate: f" headers. Please note that disabling WebDAV may affect the functionality of other applications such as SharePoint.

    Microsoft has released Security Advisory 971492 to provide information about this vulnerability. Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.


    Gumblar Malware Exploit Circulating

    added May 18, 2009 at 12:47 pm

    US-CERT is aware of public reports of a malware exploit circulating. This is a drive-by-download exploit with multiple stages and is being referred to as Gumblar. The first stage of this exploit attempts to compromise legitimate websites by injecting malicious code into them. Reports indicate that these website infections occur primarily through stolen FTP credentials but may also be compromised through poor configuration settings, vulnerable web applications, etc.  The second stage of this exploit occurs when users visit a website compromised by Gumblar. Users who visit these compromised websites and have not applied updates for known PDF and Flash Player vulnerabilities may become infected with malware. This malware may be used by attackers to monitor network traffic and obtain sensitive information, including FTP and login credentials, that can be used to conduct further exploits. Additionally, this malware may also redirect Google search results for the infected user.

    US-CERT encourages users and administrators to apply software updates in a timely manner and use up-to-date antivirus software to help mitigate the risks.

    US-CERT will provide additional information as it becomes available.


    Adobe Releases Security Updates for Adobe Reader and Acrobat

    added May 13, 2009 at 09:12 am | updated May 13, 2009 at 04:34 pm

    Adobe has released security updates to address a vulnerability that affects Reader 9.1 and earlier and Acrobat 9.1 and earlier. This vulnerability could allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users and administrators to review Adobe Security Bulletin APSB09-06 and apply any necessary updates to help mitigate the risks. Additional information regarding this vulnerability can be found in Technical Cyber Security Alert TA09-133B.


    Apple Releases Security Update 2009-002, Mac OS X v10.5.7 and Safari 3.2.3

    added May 13, 2009 at 09:12 am | updated May 13, 2009 at 04:33 pm

    Apple has released Security Update 2009-002 and Mac OS X v10.5.7 to address multiple vulnerabilities in a number of applications. These vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, cause a denial-of-service condition, leverage additional attacks, or obtain elevated privileges.

    Additionally, Apple has released Safari 3.2.3 to address vulnerabilities in libxml, Safari, and Webkit. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users and administrators to review Apple articles HT3549 and HT3550 and apply any necessary updates to help mitigate the risks. Additional information regarding these vulnerabilities can be found in Technical Cyber Security Alert TA09-133A.


    Microsoft Releases May Security Bulletin

    added May 12, 2009 at 01:35 pm | updated May 13, 2009 at 04:32 pm

    Microsoft has released an update to address a vulnerability in Microsoft Office as part of the Microsoft Security Bulletin Summary for May 2009. By convincing a user to open a specially crafted PowerPoint file, an attacker may be able to execute arbitrary code.

    US-CERT encourages users and administrators to review the bulletin and follow best-practice security policies to determine if the update should be applied. Additional information regarding this vulnerability can be found in Technical Cyber Security Alert TA09-132A.


    Microsoft Releases Advance Notification for May Security Bulletin

    added May 7, 2009 at 02:58 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that the May release cycle will contain one bulletin with a maximum severity rating of Critical. The notification states that the Critical bulletin is for Microsoft PowerPoint. The release is scheduled for Tuesday, May 12.

    US-CERT will provide additional information as it becomes available.


    Adobe Releases Security Bulletin for Flash Media Server

    added May 7, 2009 at 02:30 pm

    Adobe has released Security Bulletin APSB09-05 to address a potential vulnerability in versions of Flash Media Server up to and including version 3.5.1. This vulnerability may allow an attacker to "execute remote procedures within a server side ActionScript file running on a Flash Media Server." According to Adobe, this issue affects versions of Flash Media Interactive Server and Flash Media Streaming Server.

    US-CERT encourages users to review Adobe Security Bulletin APSB09-05 and upgrade to the most current version of Flash Media Server.