<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>US-CERT Current Activity</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current"/>
<link rel="self" type="application/atom+xml" hreflang="en" href="http://www.us-cert.gov/current/index.atom"/>
<updated>2010-09-01T09:32:02-04:00</updated>
<author>
<name>US-CERT</name>
<email>info@us-cert.gov</email>
<uri>http://www.us-cert.gov</uri>
</author>
<id>http://www.us-cert.gov/</id>
<subtitle>The US-CERT Current Activity web
        page is a regularly updated summary of the most frequent, high-impact types of security
        incidents currently being reported to the US-CERT.</subtitle>
<rights>Copyright 2010 Carnegie Mellon University</rights>
<entry>
<title>Insecure Loading of Dynamic Link Libraries in Windows Applications</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#insecure_loading_of_dynamic_link"/>
<id>http://www.us-cert.gov/current/index.html#insecure_loading_of_dynamic_link</id>
<published>2010-08-25T12:01:23-04:00</published>
<updated>2010-09-01T10:27:26-04:00</updated>
<content type="html">          












US-CERT is aware of a class of vulnerabilities related to how some Windows applications may load external dynamic link libraries (DLLs). When an application loads a DLL without specifying a fully qualified path name, Windows will attempt to locate the DLL by searching a defined set of directories. If an application does not securely load DLL files, an attacker may be able to cause the affected application to load an arbitrary library.&lt;br&gt;&lt;br&gt;By convincing a user to open a file from a location that is under an attacker's control, such as a USB drive or network share, a remote attacker may be able to exploit this vulnerability. Exploitation of this vulnerability may result in the execution of arbitrary code.&lt;br&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br&gt;Additional information regarding this vulnerability can be found in US-CERT Vulnerability Note &lt;a href="http://www.kb.cert.org/vuls/id/707943" target="_self"&gt;VU#707943&lt;/a&gt;. US-CERT encourages users and administrators to review the vulnerability note and consider implementing the following workarounds until fixes are released by affected vendors&lt;br&gt;&lt;ul&gt;&lt;li&gt;disable loading libraries from WebDAV and remote network shares&lt;/li&gt;&lt;li&gt;disable the WebClient service&lt;/li&gt;&lt;li&gt;block outgoing SMB traffic&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Update:&lt;/span&gt; Microsoft has released 
Fix it tool 50522 to assist users in setting the registry key value 
introduced with Microsoft support article &lt;a href="http://support.microsoft.com/kb/2264107" target="_self"&gt;2264107&lt;/a&gt; to help reduce the risks posed by the DLL loading behavior described in &lt;a href="http://www.kb.cert.org/vuls/id/707943" target="_self"&gt;VU#707943&lt;/a&gt;. Users and administrators are encouraged to review Microsoft support article &lt;a href="http://support.microsoft.com/kb/2264107" target="_self"&gt;2264107&lt;/a&gt;, the Microsoft Security Research &amp;amp; Defense TechNet &lt;a href="http://blogs.technet.com/b/srd/archive/2010/08/31/an-update-on-the-dll-preloading-remote-attack-vector.aspx" target="_self"&gt;blog entry&lt;/a&gt;,
 and to consider using the Fix it tool to help reduce the risks. Users 
should be aware that setting the registry key value as described in the 
support article or via the Fix it tool may reduce the functionality of 
some third-party applications.&lt;br&gt;&lt;br&gt;US-CERT will provide updates when additional details become available.&lt;br&gt;















  </content>
</entry>
<entry>
<title>VMware Releases Updates for ESX Service Console Packages</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#vmware_releases_updates_for_esx"/>
<id>http://www.us-cert.gov/current/index.html#vmware_releases_updates_for_esx</id>
<published>2010-09-01T09:32:02-04:00</published>
<updated>2010-09-01T09:32:02-04:00</updated>
<content type="html">          




VMware has released security updates for multiple third party packages for the ESX Service Console. These updates address vulnerabilities in the perl, krb5, samba, tar, and cpio packages. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or bypass security restrictions.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review VMware security advisory &lt;a href="http://lists.vmware.com/pipermail/security-announce/2010/000103.html" target="_self"&gt;VMSA-2010-0013&lt;/a&gt; and apply any necessary updates to help mitigate the risks.&lt;br&gt;







  </content>
</entry>
<entry>
<title>Cisco Releases Security Advisory for IOS XR Software Border Gateway Protocol</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#cisco_releases_security_advisory_for20"/>
<id>http://www.us-cert.gov/current/index.html#cisco_releases_security_advisory_for20</id>
<published>2010-08-31T08:40:53-04:00</published>
<updated>2010-08-31T08:40:53-04:00</updated>
<content type="html">          




Cisco has released a security advisory to address a vulnerability in the Cisco IOS XR Software Border Gateway Protocol feature. Exploitation of this vulnerability may result in the continuous resetting of BGP peering sessions, which may cause a denial-of-service condition for affected networks.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Cisco security advisory &lt;a href="http://www.cisco.com/warp/public/707/cisco-sa-20100827-bgp.shtml" target="_self"&gt;cisco-sa-20100827-bgp&lt;/a&gt; and apply any necessary updates to help mitigate the risks.&lt;br&gt;







  </content>
</entry>
<entry>
<title>RealNetworks Releases Update to Address Vulnerabilities in RealPlayer</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#realnetworks_releases_update_to_address"/>
<id>http://www.us-cert.gov/current/index.html#realnetworks_releases_update_to_address</id>
<published>2010-08-31T08:23:36-04:00</published>
<updated>2010-08-31T08:23:36-04:00</updated>
<content type="html">          
RealNetworks, Inc. has released an update for RealPlayer to address multiple vulnerabilities. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code or obtain sensitive information. &lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the RealNetworks, Inc. &lt;a href="http://service.real.com/realplayer/security/08262010_player/en/" target="_self"&gt;security advisory&lt;/a&gt; for these vulnerabilities and apply any necessary updates to help mitigate the risks.&lt;br&gt;



  </content>
</entry>
<entry>
<title>Cisco Releases Advisories for Unified Communications Manager and Unified Presence</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#cisco_releases_advisories_for_unified"/>
<id>http://www.us-cert.gov/current/index.html#cisco_releases_advisories_for_unified</id>
<published>2010-08-25T13:53:24-04:00</published>
<updated>2010-08-25T13:53:24-04:00</updated>
<content type="html">          




Cisco has released security advisories to address multiple vulnerabilities affecting Unified Communications Manager and Unified Presence.&lt;br&gt;&lt;br&gt;These vulnerabilities affect the processing of Session Initiation Protocol (SIP) messages. Exploitation of these vulnerabilities may allow an attacker to cause a denial-of-service condition, which could cause an interruption of voice services. &lt;br&gt;&lt;br&gt;Cisco Unified Communications Manager users and administrators are encouraged to review Cisco security advisory &lt;a href="http://www.cisco.com/warp/public/707/cisco-sa-20100825-cucm.shtml" target="_self"&gt;cisco-sa-20100825-cucm&lt;/a&gt; and apply any necessary updates to help mitigate the risks. Cisco Unified Presence users and administrators are encouraged to review Cisco security advisory &lt;a href="http://www.cisco.com/warp/public/707/cisco-sa-20100825-cup.shtml" target="_self"&gt;cisco-sa-20100825-cup&lt;/a&gt; and apply any necessary updates to help mitigate the risks.&lt;br&gt;







  </content>
</entry>
<entry>
<title>APWG Fax Back Phishing Education Program</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#apwg_fax_back_phishing_education"/>
<id>http://www.us-cert.gov/current/index.html#apwg_fax_back_phishing_education</id>
<published>2010-08-25T13:16:42-04:00</published>
<updated>2010-08-25T13:16:42-04:00</updated>
<content type="html">          








In an effort to respond to a growing public threat by offline phishers that conduct various scams via fax, the Anti-phishing Working Group (APWG) has partnered with the Internal Revenue Service (IRS) to create the APWG Fax Back Phishing Education Program. This program is designed to provide telecommunications companies and Fax over Internet Protocol (FoIP) hosting firms with information that can be used to educate consumers about these types of scams. Offline phishing differs from traditional phishing in that it involves sending emails with attachments or direct faxes to individuals or businesses and is not done strictly online. Recipients of offline phishing scams are coerced to complete the fake documents and fax them back or be penalized.&lt;br&gt;&lt;br&gt;In conjunction with IRS's Online Fraud Detection and Prevention (OFDP) group, APWG created a fax coversheet that can be downloaded by carriers and used to notify victims of offline phishing. This fax coversheet also provides links to other APWG resources which allow the victims to submit a complaint directly to the appropriate clearinghouse.&lt;br&gt;&lt;br&gt;More information about the APWG Fax Back Phishing Education Program and the advisory fax coversheet can be found at the following&lt;br&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://education.apwg.org/faxback/index.html" target="_self"&gt;APWG Fax Back Phishing Education Program Page&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://education.apwg.org/faxback/faxbackpage.pdf" target="_self"&gt;Advisory Coversheet Page (PDF)&lt;br&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;











  </content>
</entry>
<entry>
<title>Adobe Releases Security Bulletin for Shockwave Player</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#adobe_releases_security_bulletin_for8"/>
<id>http://www.us-cert.gov/current/index.html#adobe_releases_security_bulletin_for8</id>
<published>2010-08-25T08:15:18-04:00</published>
<updated>2010-08-25T08:15:18-04:00</updated>
<content type="html">          

Adobe has released a security update to address multiple vulnerabilities affecting Shockwave Player 11.5.7.609 and earlier versions. These vulnerabilities may allow an attacker to execute arbitrary code.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Adobe security bulletin &lt;a href="http://www.adobe.com/support/security/bulletins/apsb10-20.html" target="_self"&gt;APSB10-20&lt;/a&gt; and upgrade to Adobe Shockwave Player 11.5.8.612 to help mitigate the risks.&lt;br&gt;




  </content>
</entry>
<entry>
<title>Apple Releases Security Update 2010-005</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#apple_releases_security_update_20104"/>
<id>http://www.us-cert.gov/current/index.html#apple_releases_security_update_20104</id>
<published>2010-08-25T08:15:12-04:00</published>
<updated>2010-08-25T08:15:12-04:00</updated>
<content type="html">          



Apple has released security update 2010-005 to address multiple vulnerabilities affecting the ATS, CFNetwork, ClamAV, CoreGraphics, libsecurity, PHP, and Samba applications. These vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, cause a denial-of-service condition, or impersonate hosts within a domain.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT4312" target="_self"&gt;HT4312&lt;/a&gt; and apply any necessary updates to help mitigate the risks.&lt;br&gt;






  </content>
</entry>
<entry>
<title>Microsoft Releases Security Advisory</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory5"/>
<id>http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory5</id>
<published>2010-08-24T11:42:18-04:00</published>
<updated>2010-08-24T11:42:18-04:00</updated>
<content type="html">          













Microsoft has released a &lt;a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx" target="_self"&gt;security advisory&lt;/a&gt; indicating that it is aware of a remote attack vector for a class of vulnerabilities related to how applications load external dynamic link libraries (DLLs). If an application does not &lt;a href="http://msdn.microsoft.com/en-us/library/ff919712%28VS.85%29.aspx" target="_self"&gt;securely load&lt;/a&gt; DLL files, an attacker may be able to cause the application to load an arbitrary library. By convincing a user to open a file from a location that is under an attacker's control, such as a USB drive or network share, a remote attacker may be able exploit this vulnerability. Exploitation of this vulnerability may result in the execution of arbitrary code or elevation of privileges.&lt;br&gt;&lt;br&gt;At this time, US-CERT is aware of reports of publicly available exploit code for this vulnerability.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review Microsoft security advisory &lt;a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx" target="_self"&gt;2269637&lt;/a&gt; and consider implementing the workarounds listed in the document. Please note that these workarounds may reduce the functionality of the affected systems. Workarounds include&lt;br&gt;&lt;ul&gt;&lt;li&gt;disabling the loading of libraries from WebDAV and remote network shares&lt;/li&gt;&lt;li&gt;disabling the WebClient service&lt;/li&gt;&lt;li&gt;blocking TCP ports 139 and 445 at the firewall&lt;/li&gt;&lt;/ul&gt;US-CERT will provide additional information as it becomes available.&lt;br&gt;
















  </content>
</entry>
<entry>
<title>VideoLAN Releases a Security Advisory for VLC Media Player</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#videolan_releases_a_security_update"/>
<id>http://www.us-cert.gov/current/index.html#videolan_releases_a_security_update</id>
<published>2010-08-20T10:47:03-04:00</published>
<updated>2010-08-20T10:47:03-04:00</updated>
<content type="html">          











VideoLAN has released a security advisory to address a vulnerability in VLC Media Player. This vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition. The updated release also addresses additional issues that could result in a denial-of-service attack.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review VideoLAN security advisory &lt;a href="http://www.videolan.org/security/sa1004.html" target="_self"&gt;VideoLAN-SA-1004&lt;/a&gt; and apply any necessary updates or workarounds to help mitigate the risks.&lt;br&gt;














  </content>
</entry>
</feed>
