<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>US-CERT Current Activity</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current"/>
<link rel="self" type="application/atom+xml" hreflang="en" href="http://www.us-cert.gov/current/index.atom"/>
<updated>2009-11-16T09:21:36-05:00</updated>
<author>
<name>US-CERT</name>
<email>info@us-cert.gov</email>
<uri>http://www.us-cert.gov</uri>
</author>
<id>http://www.us-cert.gov/</id>
<subtitle>The US-CERT Current Activity web
        page is a regularly updated summary of the most frequent, high-impact types of security
        incidents currently being reported to the US-CERT.</subtitle>
<rights>Copyright 2009 Carnegie Mellon University</rights>
<entry>
<title>Microsoft Releases Security Advisory 977544</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory_977544"/>
<id>http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory_977544</id>
<published>2009-11-16T09:21:36-05:00</published>
<updated>2009-11-16T09:21:36-05:00</updated>
<content type="html">          










Microsoft has released security advisory 977544 to address a vulnerability in the Server Message Block (SMB) protocol. This vulnerability may allow an attacker to cause a denial-of-service condition. This vulnerability only affects Windows 7 and Server 2008 software.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Microsoft security advisory &lt;a href="http://www.microsoft.com/technet/security/advisory/977544.mspx" target="_self"&gt;977544&lt;/a&gt; and apply the workarounds.












  </content>
</entry>
<entry>
<title>SSL and TLS Vulnerable to Man-in-the-middle Attacks</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#ssl_and_tls_vulnerable_to"/>
<id>http://www.us-cert.gov/current/index.html#ssl_and_tls_vulnerable_to</id>
<published>2009-11-06T19:01:52-05:00</published>
<updated>2009-11-16T08:57:34-05:00</updated>
<content type="html">          











US-CERT is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream.&lt;br&gt;&lt;br&gt;US-CERT encourages OpenSSL users and administrators to review the &lt;a href="http://www.openssl.org/source/" target="_self"&gt;OpenSSL 0.9.8l&lt;/a&gt; release and apply any updates.&lt;br&gt;&lt;br&gt;US-CERT has not received any reports of active exploitation and will continue to provide additional information as it becomes available.


  </content>
</entry>
<entry>
<title>Apple Releases Safari 4.0.4</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03"/>
<id>http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03</id>
<published>2009-11-12T08:08:48-05:00</published>
<updated>2009-11-12T08:08:48-05:00</updated>
<content type="html">          
Apple has released Safari 4.0.4 to address multiple vulnerabilities in a number of components. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct cross-site request forgery, or obtain sensitive information. These vulnerabilities affect Safari running on both the Mac OS X and Windows platforms.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT3949" target="_self"&gt;HT3949&lt;/a&gt; and upgrade to Safari 4.0.4 to help mitigate the risks.

  </content>
</entry>
<entry>
<title>Microsoft Releases November Security Bulletin</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#microsoft_releases_november_security_bulletin1"/>
<id>http://www.us-cert.gov/current/index.html#microsoft_releases_november_security_bulletin1</id>
<published>2009-11-10T13:50:33-05:00</published>
<updated>2009-11-10T13:50:33-05:00</updated>
<content type="html">          



Microsoft has released an update to address vulnerabilities in Microsoft Windows and Office as part of the Microsoft Security Bulletin Summary for &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_self"&gt;November 2009&lt;/a&gt;. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or operate with escalated privileges.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_self"&gt;bulletins&lt;/a&gt; and follow best-practice security policies to determine which updates should be applied.&amp;nbsp;






  </content>
</entry>
<entry>
<title>Apple Releases Mac OS X v10.6.2 and Security Update 2009-006</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#apple_releases_mac_os_x2"/>
<id>http://www.us-cert.gov/current/index.html#apple_releases_mac_os_x2</id>
<published>2009-11-10T08:02:17-05:00</published>
<updated>2009-11-10T08:02:17-05:00</updated>
<content type="html">          

Apple has released Mac OS X v10.6.2 and Security Update 2009-006 to address multiple vulnerabilities in a number of applications. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct a man-in-the-middle attack, operate with escalated privileges, or obtain sensitive information.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT3937" target="_self"&gt;HT3937&lt;/a&gt; and apply any necessary updates to help mitigate the risks.


  </content>
</entry>
<entry>
<title>Microsoft Releases Advance Notification for November Security Bulletin</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#microsoft_releases_advance_notification_for28"/>
<id>http://www.us-cert.gov/current/index.html#microsoft_releases_advance_notification_for28</id>
<published>2009-11-05T16:17:12-05:00</published>
<updated>2009-11-05T16:17:12-05:00</updated>
<content type="html">          

Microsoft has issued a &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_self"&gt;Security Bulletin Advance Notification&lt;/a&gt; indicating that its November release cycle will contain six bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows. There will also be three important bulletins for Microsoft Windows and Microsoft Office. Release of these bulletins is scheduled for Tuesday, November 10.&lt;br&gt;&lt;br&gt;US-CERT will provide additional information as it becomes available.




  </content>
</entry>
<entry>
<title>BlackBerry Desktop Manager Vulnerability</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#blackberry_desktop_manager_vulnerability"/>
<id>http://www.us-cert.gov/current/index.html#blackberry_desktop_manager_vulnerability</id>
<published>2009-11-05T08:45:35-05:00</published>
<updated>2009-11-05T08:45:35-05:00</updated>
<content type="html">          

Research in Motion has released Security Advisory &lt;a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB19701" target="_self"&gt;KB19701&lt;/a&gt; to address a vulnerability in BlackBerry Desktop Manager. This vulnerability may allow an attacker to execute arbitrary code.&lt;br&gt;&lt;br&gt;US-CERT encourages users to review BlackBerry Security Advisory &lt;a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB19701" target="_self"&gt;KB19701&lt;/a&gt; and apply any necessary updates.




  </content>
</entry>
<entry>
<title>Sun Releases Update 17 for Java SE 6</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#sun_releases_update_17_for"/>
<id>http://www.us-cert.gov/current/index.html#sun_releases_update_17_for</id>
<published>2009-11-04T09:04:38-05:00</published>
<updated>2009-11-04T09:04:38-05:00</updated>
<content type="html">          





Sun has released update 17 for Java SE JDK 6 and Java SE JRE 6 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, denial of service, and information disclosure.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the Java the Java SE 6 Update 17 &lt;a href="http://java.sun.com/javase/6/webnotes/6u17.html" target="_self"&gt;release notes&lt;/a&gt; and apply any necessary &lt;a href="http://java.sun.com/javase/downloads/index.jsp" target="_self"&gt;updates&lt;/a&gt; to help mitigate the risks.








  </content>
</entry>
<entry>
<title>Adobe Releases Update for Shockwave Player</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#adobe_releases_update_for_shockwave1"/>
<id>http://www.us-cert.gov/current/index.html#adobe_releases_update_for_shockwave1</id>
<published>2009-11-04T09:04:34-05:00</published>
<updated>2009-11-04T09:04:34-05:00</updated>
<content type="html">          






Adobe has released Shockwave Player 11.5.2.602 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to run malicious code on the user's machine.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Adobe security bulletin &lt;a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html" target="_self"&gt;APSB09-16&lt;/a&gt; and update to Shockwave Player 11.5.2.602 to help mitigate the risks.&lt;br&gt;









  </content>
</entry>
<entry>
<title>Mozilla Releases Firefox 3.0.15 and Firefox 3.5.4</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_3_01"/>
<id>http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_3_01</id>
<published>2009-10-28T09:13:33-04:00</published>
<updated>2009-10-28T09:13:33-04:00</updated>
<content type="html">          

Mozilla has released Firefox 3.0.15 and Firefox 3.5.4 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, execute arbitrary JavaScript with chrome privileges, or cause a denial-of-service condition. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect SeaMonkey.&lt;br&gt;&lt;br&gt;US-CERT encourages users to review the Mozilla Foundation security advisories for &lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html" target="_self"&gt;Firefox 3.0&lt;/a&gt; and &lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html" target="_self"&gt;Firefox 3.5&lt;/a&gt; and apply any necessary updates or workarounds to help mitigate the risks.


  </content>
</entry>
</feed>
