Skip to content

customize

US-CERT Current Activity

current activity RSS feed current activity ATOM feed

The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.

Last reviewed: May 9, 2008 09:13:25 EDT

May 9Mozilla Releases Thunderbird 2.0.0.14
May 8Microsoft Releases Advance Notification for May Security Bulletin
May 7Microsoft Releases Windows XP Service Pack 3
May 6PHP 5.2.6 Released
May 5Common Data Format Buffer Overflow Vulnerability
April 28WordPress Vulnerabilities
April 25Compromised Websites Hosting Malicious JavaScript
April 25HP Software Update Vulnerabilities
April 24IRS Rebate Phishing Scam
April 23Apple QuickTime Vulnerability Report



Mozilla Releases Thunderbird 2.0.0.14

added May 9, 2008 at 09:11 am

Mozilla has released Thunderbird 2.0.0.14 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to escalate privileges or execute arbitrary code.

US-CERT encourages users to review Mozilla Foundation Security Advisories 2008-14 and 2008-15 and to update to Thunderbird 2.0.0.14.


Microsoft Releases Advance Notification for May Security Bulletin

added May 8, 2008 at 03:06 pm

Microsoft has issued a Security Bulletin Advance Notification indicating that its May release cycle will contain four bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows and Office. The notification also states that there will be one Important bulletin for Windows Live OneCare, Antigen, Defender, and Forefront Security. Release of these bulletins is scheduled for Tuesday, May 12.

US-CERT will provide additional information as it becomes available.


Microsoft Releases Windows XP Service Pack 3

added May 7, 2008 at 08:24 am

Microsoft has released Service Pack 3 for Windows XP. Service Pack 3 includes multiple Hotfixes and security updates and is available through Automatic Updates and Windows Update.

Users should note that Windows XP SP3 does not include Internet Explorer 7, however it does include updates to both IE 6 and IE 7, and will update whichever version is currently installed.

US-CERT encourages users to review the release notes for Service Pack 3 for Windows XP and apply any necessary updates.


PHP 5.2.6 Released

added May 6, 2008 at 09:03 am

PHP has released version 5.2.6 to address multiple vulnerabilities. These vulnerabilities include

  • an error in FastCGI SAPI which may result stack-based buffer overflow
  • an integer overflow in printf()
  • an error in init_request_info(), which may result in a buffer overflow
  • an error in cURL, which may result in safe_mode bypass
  • improper handling of input passed to escapeshellcmd()
  • a boundary error in the bundled version of the PCRE library
These vulnerabilities may allow an attacker to execute arbitrary code, bypass security restrictions, or cause a denial-of-service condition.

US-CERT encourages users to review the PHP 5.2.6 Release Announcement and update to version 5.2.6.


Common Data Format Buffer Overflow Vulnerability

added May 5, 2008 at 04:04 pm

NASA has issued an advisory regarding a vulnerability in Common Data Format (CDF) version 3.2 and earlier. This vulnerability is due to a buffer overflow condition in the handling of specially-crafted CDF files. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.

US-CERT encourages users to review the NASA advisory and update to CDF 3.2.1 to help mitigate the risk.

US-CERT will provide additional information as it becomes available.


WordPress Vulnerabilities

added April 28, 2008 at 01:50 pm

WordPress has released version 2.5.1 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to bypass security restrictions or conduct a cross-site scripting attack.

US-CERT encourages users to review the WordPress 2.5.1 release notes and apply any necessary updates.


Compromised Websites Hosting Malicious JavaScript

added April 25, 2008 at 04:45 pm

US-CERT is following reports of SQL injection attacks that have compromised a large number of legitimate websites. The compromised websites contain injected JavaScript that attempts to exploit multiple, known vulnerabilities. Users who visit a compromised website may unknowingly execute malicious code.

US-CERT encourages users to do the following to help mitigate the risks of this and similar attacks:

  • Regularly apply software updates and patches provided by vendors.
  • Disable JavaScript and ActiveX as described in the Securing Your Web Browser document.
For more technical information, visit SANS Internet Storm Center at http://isc.sans.org/diary.html?storyid=4331.

US-CERT will provide more information as it becomes available.


HP Software Update Vulnerabilities

added April 25, 2008 at 10:44 am

US-CERT is aware of reports of multiple vulnerabilities affecting HP Software Update. These vulnerabilities are due to insecure methods in multiple ActiveX controls. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code or view or modify sensitive information.

US-CERT encourages users to do the following to help mitigate the risks:


IRS Rebate Phishing Scam

added April 24, 2008 at 09:31 am

US-CERT is aware of a public report indicating that a phishing scam is circulating. This scam is related to the U.S. Internal Revenue Service economic stimulus rebate and arrives via email messages that appear to be from the IRS. The messages include text that attempts to convince users to follow a link to a website before a deadline to expedite the rebate process. This website requests that the user provide bank account information.

US-CERT encourages users to do the following to help mitigate the risks:


Apple QuickTime Vulnerability Report

added April 23, 2008 at 06:33 pm

US-CERT is aware of a public report of a new vulnerability in Apple QuickTime. The report indicates that if a user opens a specially crafted QuickTime file, an attacker may be able to execute arbitrary code. This vulnerability may have several attack vectors, such as visiting a malicious or compromised website. US-CERT is currently investigating this report and will provide additional details as needed.

US-CERT encourages users to use caution when opening QuickTime files, and apply the best security practices described in the Securing Your Web Browser document, to help mitigate the risks.

Additional Information

National Cyber Alert System

Technical Cyber Security Alerts
Cyber Security Alerts
Cyber Security Bulletins
Cyber Security Tips

General Tips
  • Apply vendor-supplied software patches in a timely manner
  • Disable features/services that are not explicitly required
  • Install anti-virus software and keep it up to date
  • Use caution when opening email attachments and following URLs