Skip to content

customize
Current Activity Calendar
Left Arrow
July 2009
Right Arrow
Su M Tu W Th F Sa
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • July 22, 2009 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    July 22Adobe Reader, Acrobat and Flash Player Vulnerability
    July 22Mozilla Releases Firefox 3.0.12
    July 22WordPress Releases Version 2.8.2
    July 17Mozilla Firefox 3.5 Vulnerability
    July 14Oracle Releases Critical Patch Update for July 2009
    July 14Microsoft Releases July Security Bulletin
    July 14Microsoft Releases Security Advisory 973472
    July 13VMware Releases Security Advisory VMSA-2009-0009 and Updates Security Advisory VMSA-2009-0008.1
    July 10WordPress Releases Version 2.8.1
    July 9Microsoft Releases Advance Notification for July Security Bulletin



    Adobe Reader, Acrobat and Flash Player Vulnerability

    added July 22, 2009 at 04:41 pm

    Adobe has released a blog post indicating that it is aware of reports of a vulnerability affecting Adobe Reader and Acrobat 9.1.2 and Flash Player 9 and 10.

    US-CERT encourages users and administrators to review the blog post and implement the following workarounds until the vendor releases additional information:

    • Disable Flash in Adobe Reader 9 on Windows platforms by renaming the following files: "%ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll" and "%ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll".
    Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.

    US-CERT will provide additional information as it becomes available.


    Mozilla Releases Firefox 3.0.12

    added July 22, 2009 at 09:28 am

    The Mozilla Foundation has released Firefox 3.0.12 to address multiple vulnerabilities in Firefox 3.0.x. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or launch cross-site-scripting attacks.

    US-CERT encourages users and administrators to review Mozilla Foundation Security Advisories released on July 21, 2009 and upgrade to Firefox 3.0.12 to help mitigate the risks.


    WordPress Releases Version 2.8.2

    added July 22, 2009 at 09:01 am

    WordPress has released version 2.8.2 to address a cross-site-scripting vulnerability.

    US-CERT encourages users and administrators to review the WordPress Blog entry on WordPress 2.8.2 and apply the upgrade to help mitigate the risks.


    Mozilla Firefox 3.5 Vulnerability

    added July 14, 2009 at 08:38 am | updated July 17, 2009 at 08:00 am

    The Mozilla Foundation has released Firefox 3.5.1 to address a vulnerability. This vulnerability is due to an error in the way the Just-in-Time (JIT) compiler returns from native functions. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.

    US-CERT encourages users and administrators to review Mozilla Foundation Security Advisory 2009-41 and upgrade to Firefox 3.5.1 or apply the suggested workaround provided in the advisory. Additional information can also be found in the Vulnerability Notes Database.


    Oracle Releases Critical Patch Update for July 2009

    added July 14, 2009 at 04:08 pm

    Oracle has released its Critical Patch Update for July 2009 to address 30 vulnerabilities across several products. This update contains the following security fixes:

    • 10 for the Oracle Database Server
    • 2 for Oracle Secure Backup
    • 2 for the Oracle Application Server
    • 5 for Oracle Applications
    • 2 for Oracle Enterprise Manager
    • 3 for the Oracle PeopleSoft and JDEdwards Suite
    • 1 for the Oracle Siebel Suite
    • 5 for the Oracle BEA Products Suite
    US-CERT encourages users and administrators to review the July Critical Patch Update and apply any necessary updates.


    Microsoft Releases July Security Bulletin

    added July 14, 2009 at 01:17 pm

    Microsoft has released an update to address vulnerabilities in Microsoft Windows, Virtual PC, Virtual Server, ISA Server, and Office as part of the Microsoft Security Bulletin Summary for July 2009. These vulnerabilities may allow an attacker to execute arbitrary code or operate with elevated privileges.

    US-CERT encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied.


    Microsoft Releases Security Advisory 973472

    added July 13, 2009 at 11:20 am | updated July 14, 2009 at 08:37 am

    Microsoft has released Security Advisory 973472 to alert users about a vulnerability in Microsoft Office Web Components. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code. The advisory indicates that Microsoft is aware of attacks attempting to exploit the vulnerability.

    US-CERT encourages users and administrators to review Microsoft Security Advisory 973472 and implement the suggested workaround. Additionally, a Microsoft Fix it tool has been released to assist users in mitigating the risks associated with this vulnerability.

    US-CERT will provide additional information as it becomes available.


    VMware Releases Security Advisory VMSA-2009-0009 and Updates Security Advisory VMSA-2009-0008.1

    added July 13, 2009 at 08:58 am

    VMware has released security advisory VMSA-2009-0009 to address multiple vulnerabilities involving the udev, sudo, and curl packages of the ESX Service Console. These vulnerabilities may allow an attacker to execute arbitrary requests to an affected intranet server, read or overwrite files, or gain elevated privileges on the affected system.

    Additionally, VMware has updated security advisory VMSA-2009-0008.1. This advisory addresses a vulnerability in the krb5 package of the ESX Service Console. Exploitation of this vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users and administrators to review VMware security advisories VMSA-2009-0009 and VMSA-2009-0008.1 and apply any necessary workarounds or updates to help mitigate the risks.


    WordPress Releases Version 2.8.1

    added July 10, 2009 at 02:20 pm

    WordPress has released version 2.8.1 to address multiple vulnerabilities.

    US-CERT encourages users to review the WordPress Blog entry related to these issues and upgrade to version 2.8.1 as necessary.


    Microsoft Releases Advance Notification for July Security Bulletin

    added July 9, 2009 at 01:58 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that the July release cycle will contain six bulletins, three of which will have a severity rating of critical. The notification states that these critical bulletins are for Microsoft Windows. There will also be three important bulletins for Microsoft Office, Virtual PC and Virtual Server, and ISA Server. Release of these bulletins is scheduled for Tuesday, July 14.

    US-CERT will provide additional information as it becomes available.