Skip to content

customize
Current Activity Calendar
Left Arrow
July 2008
Right Arrow
Su M Tu W Th F Sa
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • July 18, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    July 18BlackBerry Security Advisory
    July 17Mozilla Releases Firefox 3.0.1
    July 16WordPress Releases Version 2.6
    July 16Mozilla Releases Firefox 2.0.0.16
    July 15Oracle Releases Critical Patch Update for July 2008
    July 14Zone Alarm Releases Security Advisory
    July 11Apple Releases Security Updates for iPhone and iPod touch
    July 11Oracle Critical Patch Update Pre-Release Announcement for July
    July 10Sun Releases Updates for Java SE
    July 9New Storm Worm Variant Spreading



    BlackBerry Security Advisory

    added July 16, 2008 at 10:46 am | updated July 18, 2008 at 10:06 am

    Research In Motion has released a Security Advisory to address a vulnerability in the BlackBerry Enterprise Server. This vulnerability is due to the improper processing of PDF files within the distiller component of the BlackBerry Attachment Service. By convincing a user to open a maliciously crafted PDF attachment on a BlackBerry smartphone, an attacker may be able to execute arbitrary code on the system running the BlackBerry Attachment Service.

    US-CERT encourages users to review BlackBerry Security Advisory KB15766 and apply the resolution or implement the workarounds listed in the document to help mitigate the risk.

    US-CERT will provide additional information as it becomes available.


    Mozilla Releases Firefox 3.0.1

    added July 17, 2008 at 08:16 am

    Mozilla has released Firefox 3.0.1 to address three vulnerabilities. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. One of these vulnerabilities may also affect Thunderbird and SeaMonkey. Two of these vulnerabilities were previously fixed in Firefox 2.0.0.16 as well; please see the US-CERT Current Activity entry Mozilla Releases Firefox 2.0.0.16 for additional information.

    US-CERT encourages users to review the following Mozilla Foundation Security Advisories and upgrade to Firefox 3.0.1 or implement the workarounds provided in the documents to help mitigate the risks:

    • MFSA 2008-34 : Remote code execution by overflowing CSS reference counter
    • MFSA 2008-35 : Command-line URLs launch multiple tabs when Firefox not running
    • MFSA 2008-36 : Crash with malformed GIF file on Mac OS X


    WordPress Releases Version 2.6

    added July 16, 2008 at 11:04 am

    WordPress has released version 2.6 to address approximately 194 bugs, some of which may be security related.

    US-CERT encourages users to review the WordPress Blog entry related to the release of version 2.6 and upgrade to WordPress version 2.6 to help mitigate any risks.


    Mozilla Releases Firefox 2.0.0.16

    added July 16, 2008 at 10:46 am

    Mozilla has released Firefox 2.0.0.16 to address two vulnerabilities. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. One of these vulnerabilities may also affect Thunderbird and SeaMonkey.

    US-CERT encourages users to review the following Mozilla Foundation Security Advisories and upgrade to a fixed version or implement the workarounds listed in the documents to help mitigate the risks.

    MFSA 2008-34 : Remote code execution by overflowing CSS reference counter
    MFSA 2008-35 : Command-line URLs launch multiple tabs when Firefox not running


    Oracle Releases Critical Patch Update for July 2008

    added July 15, 2008 at 04:38 pm

    Oracle has released their Critical Patch Update for July 2008 to address 45 vulnerabilities across several products. This update contains the following security fixes:

    • 11 updates for Oracle Database
    • 3 updates for Times Ten In-Memory Database
    • 9 updates for Oracle Application Server
    • 6 updates for Oracle E-Business Suite and Applications
    • 2 updates for Oracle Enterprise Manager
    • 7 updates for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne
    • 7 updates for BEA Product Suite
    US-CERT encourages users to review the July Critical Patch Update and apply any necessary updates.


    Zone Alarm Releases Security Advisory

    added July 14, 2008 at 01:58 pm

    Zone Alarm has released a Security Advisory indicating that version 7.0.483.0 has been released to address an issue in the way Microsoft Security Bulletin MS08-037 affects Zone Alarm.

    US-CERT encourages users to review the Security Advisory and apply the Recommended Actions listed in the document.


    Apple Releases Security Updates for iPhone and iPod touch

    added July 11, 2008 at 03:17 pm

    Apple has released iPhone v2.0 and iPod touch v2.0 to address multiple vulnerabilities. These vulnerabilities affect CFNetwork, Kernel, Safari, and WebKit. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, spoof websites, conduct cross-site scripting attacks or cause a denial-of-service condition.

    US-CERT encourages users to review Apple Article HT2351 and apply any necessary updates.


    Oracle Critical Patch Update Pre-Release Announcement for July

    added July 11, 2008 at 03:17 pm

    Oracle has issued a Critical Patch Update Pre-Release Announcement indicating that its July release cycle will contain 45 security fixes for multiple products including Oracle Database, TimesTen In-Memory Database, Application Server, E-Business Suite, Enterprise, PeopleSoft Enterprise and BEA. Release of these updates is scheduled for Tuesday, July 15.

    US-CERT will provide additional information as it becomes available.


    Sun Releases Updates for Java SE

    added July 10, 2008 at 08:30 am

    Sun has released updates for Java SE. These updates address multiple vulnerabilities in Java Runtime Environment (JRE), Java Web Start, Java Management Extensions (JMX), JDK, and Java Runtime Environment Virtual Machine. These vulnerabilities may allow a remote attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information or cause a denial-of-service condition.

    US-CERT encourages users to review the following Sun Alerts and apply any necessary updates:

    • Sun Alert 238628 - Security Vulnerabilities in the Java Runtime Environment related to the processing of XML Data
    • Sun Alert 238666 - A Security Vulnerability with the processing of fonts in the Java Runtime Environment may allow Elevation of Privileges
    • Sun Alert 238687 - Security Vulnerabilities in the Java Runtime Environment Scripting Language Support
    • Sun Alert 238905 - Multiple Security Vulnerabilities in Java Web Start may allow Privileges to be Elevated
    • Sun Alert 238965 - Security Vulnerability in Java Management Extensions (JMX)
    • Sun Alert 238966 - Security Vulnerability in JDK/JRE Secure Static Versioning
    • Sun Alert 238967 - Security Vulnerability in the Java Runtime Environment Virtual Machine may allow an untrusted Application or Applet to Elevate Privileges
    • Sun Alert 238968 - Security Vulnerabilities in the Java Runtime Environment may allow Same Origin Policy to be Bypassed
    US-CERT will provide additional information as it becomes available.


    New Storm Worm Variant Spreading

    added July 9, 2008 at 09:03 am

    US-CERT has received reports of new Storm Worm activity. The latest activity uses messages that refer to the conflict in the Middle East. This Trojan is spread via unsolicited email messages that contain a link to a malicious website. The website is noted as having the following malicious characteristics which may be used to infect the user's system with malicious code.

    • A video that, when opened, may run the executable file "iran_occupation.exe."
    • A banner add that, when clicked, may run the executable file "form.exe."
    • A hidden iframe linked to "ind.php."
    Reports, including a posting by Sophos, indicate that the following subject lines are being used. Please note that subject lines can change at any time.
    • 20000 US soldiers in Iran
    • Iran USA conflict developed into war
    • More than 10000 Iranians were murdered
    • Negotiations between USA and Iran ended in War
    • Occupation of Iran
    • Plans for Iran attack began
    • The Iran's Leader Mahmoud Ahmadinejad declared Jihad to USA
    • The World War III has already begun
    • The begining of The World War III
    • The military operation in Iran has begun
    • The secret war against Iran
    • Third War in Iran
    • Third World War has begun
    • US Army crossed Iran's borders
    • US Army invaded Iran
    • US army is about 20 kilometers from Tegeran
    • US soldiers occupied Iran
    • USA attacked Iran
    • USA declares war on Iran
    • USA occupeid Iran
    • USA unleashed war on Iran
    • War between USA&Iran
    • War with Iran is the reality now
    • Washington prefers to shoot first
    US-CERT encourages users and administrators to take the following preventative measures to help mitigate the security risks: