Skip to content

customize
Current Activity Calendar
Left Arrow
June 2008
Right Arrow
Su M Tu W Th F Sa
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • June 16, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    June 10Microsoft Releases June Security Bulletin
    June 10SNMPv3 Authentication Bypass Vulnerability
    June 10Apple Releases QuickTime 7.5
    June 5Microsoft Releases Advance Notification for June Security Bulletin
    June 5Skype Releases Security Bulletin
    June 5Cisco Releases Security Advisory
    June 4HP Instant Support ActiveX Control Vulnerabilities
    June 4Sun Releases Java ASP Server 4.0.3
    June 4United States Tax Court Phishing Attack
    June 2Microsoft Releases Security Advisory



    Microsoft Releases June Security Bulletin

    added June 10, 2008 at 01:48 pm

    Microsoft has released updates to address vulnerabilities in Microsoft Windows and Internet Explorer as part of the Microsoft Security Bulletin Summary for June 2008. These vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, or cause a denial-of-service condition.

    US-CERT encourages users to review the bulletins and follow best-practice security policies to determine which updates should be applied.


    SNMPv3 Authentication Bypass Vulnerability

    added June 10, 2008 at 10:41 am

    US-CERT is aware of a vulnerability in implementations of SNMPv3. This vulnerability is due to an error in the way the authenticator field handles shortened hash message authentication code (HMAC). Exploitation of this vulnerability may allow an attacker to read and modify any SNMP object or the configuration of the affected device using the credentials that got them onto the system.

    US-CERT encourages users to review Vulnerability Notes VU#878044 and apply the solutions or workarounds listed in the document to help mitigate the risks.

    US-CERT will provide additional information as it becomes available.


    Apple Releases QuickTime 7.5

    added June 10, 2008 at 09:05 am

    Apple has released QuickTime 7.5 to address multiple vulnerabilities. These vulnerabilities include the following:

    • a heap-based buffer overflow condition in the handling of PixData structures when processing a PICT image that may allow an attacker to execute arbitrary code or cause a denial-of-service condition
    • a memory corruption condition in the handling of AAC-encoded media content that may allow an attacker to execute arbitrary code or cause a denial-of-service condition
    • a heap-based buffer overflow condition in the handling of PICT images that may allow an attacker to execute arbitrary code or cause a denial-of-service condition
    • a stack-based buffer overflow condition in the handling of Indeo video codec content that may allow an attacker to execute arbitrary code execution or cause a denial-of-service condition
    • an unspecified error in the handling of file: URLs that may allow an attacker to execute arbitrary files and applications
    US-CERT encourages users to review Apple Article HT1991 and upgrade to QuickTime 7.5.


    Microsoft Releases Advance Notification for June Security Bulletin

    added June 5, 2008 at 03:07 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that its June release cycle will contain seven bulletins, three of which will have the severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows and Internet Explorer. The notification also states that there will be three Important bulletins for Microsoft Windows. The last of these bulletins has the severity rating of Moderate and is for Microsoft Windows. Release of these bulletins is scheduled for Tuesday, June 10.

    US-CERT will provide additional information as it becomes available.


    Skype Releases Security Bulletin

    added June 5, 2008 at 11:38 am

    Skype has released a security bulletin to address a vulnerability. This vulnerability is due to an error in the handling of "file:" URIs. By convincing a user to click on a specially crafted "file:" URI, a remote, unauthenticated attacker may be able to execute arbitrary code.

    US-CERT encourages users to review Skype security bulletin SKYPE-SB/2008-003 and upgrade to Skype version 3.8.0.139.


    Cisco Releases Security Advisory

    added June 5, 2008 at 10:07 am

    Cisco has released a Security Advisory to address multiple vulnerabilities in the PIX and ASA security appliances. These vulnerabilities include the following:

    • An unspecified error in the processing of TCP ACK packets that may allow an attacker to cause a denial-of-service condition.
    • An unspecified error in the handling of the TLS protocol that may allow an attacker to cause a denial-of-service condition.
    • An unspecified error in the Instant Messaging Inspection that may allow an attacker to cause a denial-of-service condition.
    • An unspecified error that occurs during vulnerability scanning against  TCP port 443 may allow an attacker to cause a denial-of-service condition.
    • An unspecified error in the Control-plane Access List may allow an attacker to bypass security restrictions.
    US-CERT encourages users to review Cisco Security Advisory cisco-sa-20080604-asa and upgrade or apply the workarounds as defined in the advisory.


    HP Instant Support ActiveX Control Vulnerabilities

    added June 4, 2008 at 02:37 pm

    HP has released a support document to address multiple vulnerabilities in the Instant Support ActiveX control (HPISDataManager.dll). These vulnerabilities may allow a remote attacker to execute arbitrary code.

    US-CERT encourages users to review the HP Support Document and upgrade to Instant Support v1.0.0.24 or apply the workarounds listed in the Support Document.


    Sun Releases Java ASP Server 4.0.3

    added June 4, 2008 at 02:12 pm

    Sun has released Java ASP Server 4.0.3 to address multiple vulnerabilities. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the root user or the user running the Sun Java ASP server, obtain sensitive information, or bypass security restrictions.

    US-CERT encourages users to review Sun Alert 238184 and upgrade to Java ASP Server 4.0.3 or apply the workarounds listed in the Sun Alert.


    United States Tax Court Phishing Attack

    added May 15, 2008 at 03:15 pm | updated June 4, 2008 at 01:10 pm

    US-CERT is aware of public reports of a phishing attack circulating via email messages that claim to be petitions from the US Tax Court. These messages appear to be legitimate because they may contain very specific information about the message recipient. The message requests that the user follow a link to download additional information or documents. If a user clicks on this link, the website attempts to use JavaScript to install a bogus root certificate that is supposedly issued by "VeriSign Trust Network." The user will normally receive several warnings when the JavaScript code attempts to install the certificate.

    If the certificate installs successfully, the browser is redirected to another page that attempts to install an ActiveX control. The user may be prompted to allow the installation, and because the control is signed, it will appear to be legitimate. However, it is signed by a fake certificate for "Adobe Systems Incorporated," which is trusted by the bogus root certificate previously installed. The ActiveX control is a Browser Helper Object (BHO) that functions as an information stealer. Upon execution, it will attempt to download an update to itself and will then begin reading client certificates, stored passwords, cookies, browsing history, posted form data, and other information.

    Public reports indicate that the attack messages have the following attributes:

    • Messages appear to come from the "United State Tax Court." (Note the missing "s" on "State.")
    • The URL within the message appears to link to the "ustax-courts.com" domain.
    US-CERT encourages users to do the following to help mitigate the risk:
    • Review the alert posted by the United States Tax Court regarding this issue.
    • Do not follow unsolicited web links received in email messages.
    • Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
    • Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
    • Install anti-virus software and keep virus signature files up to date.
    • Pay close attention to warning messages and prompts.


    Microsoft Releases Security Advisory

    added June 2, 2008 at 11:47 am

    Microsoft has released Security Advisory 953818 to address reports of a blended threat that affects Windows users who have installed Apple's Safari web browser. According to the advisory, by convincing a user to visit a specially crafted website, an attacker may be able to execute arbitrary code on an affected system due to Safari's default file downloading behavior and the way that Windows Internet Explorer handles the downloaded files.

    US-CERT encourages users to review Microsoft Security Advisory 953818. Please note that the advisory indicates that the workaround does not correct the vulnerability, but it may help mitigate risk against known attack vectors.

    US-CERT will provide additional information as it becomes available.