Office of HIPAA Privacy and Security

Security Alerts

Microsoft Releases Security Advisory 977544

November 16, 2009
Microsoft has released security advisory 977544 to address a vulnerability in the Server Message Block (SMB) protocol. This vulnerability may allow an attacker to cause a denial-of-service condition. This vulnerability only affects Windows 7 and Server 2008 software.

US-CERT encourages users and administrators to review Microsoft security advisory 977544 and apply the workarounds.

 

SSL and TLS Vulnerable to Man-in-the-middle Attacks

November 16, 2009
US-CERT is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream.

US-CERT encourages OpenSSL users and administrators to review the OpenSSL 0.9.8l release and apply any updates.

US-CERT has not received any reports of active exploitation and will continue to provide additional information as it becomes available.

 

Apple Releases Safari 4.0.4

November 12, 2009
Apple has released Safari 4.0.4 to address multiple vulnerabilities in a number of components. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct cross-site request forgery, or obtain sensitive information. These vulnerabilities affect Safari running on both the Mac OS X and Windows platforms.

US-CERT encourages users and administrators to review Apple article HT3949 and upgrade to Safari 4.0.4 to help mitigate the risks.

 

Microsoft Releases November Security Bulletin

November 10, 2009
Microsoft has released an update to address vulnerabilities in Microsoft Windows and Office as part of the Microsoft Security Bulletin Summary for November 2009. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or operate with escalated privileges.

US-CERT encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied. 

 

Apple Releases Mac OS X v10.6.2 and Security Update 2009-006

November 10, 2009
Apple has released Mac OS X v10.6.2 and Security Update 2009-006 to address multiple vulnerabilities in a number of applications. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct a man-in-the-middle attack, operate with escalated privileges, or obtain sensitive information.

US-CERT encourages users and administrators to review Apple article HT3937 and apply any necessary updates to help mitigate the risks.

 

Microsoft Releases Advance Notification for November Security Bulletin

November 5, 2009
Microsoft has issued a Security Bulletin Advance Notification indicating that its November release cycle will contain six bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows. There will also be three important bulletins for Microsoft Windows and Microsoft Office. Release of these bulletins is scheduled for Tuesday, November 10.

US-CERT will provide additional information as it becomes available.

 

BlackBerry Desktop Manager Vulnerability

November 5, 2009
Research in Motion has released Security Advisory KB19701 to address a vulnerability in BlackBerry Desktop Manager. This vulnerability may allow an attacker to execute arbitrary code.

US-CERT encourages users to review BlackBerry Security Advisory KB19701 and apply any necessary updates.

 

Sun Releases Update 17 for Java SE 6

November 4, 2009
Sun has released update 17 for Java SE JDK 6 and Java SE JRE 6 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, denial of service, and information disclosure.

US-CERT encourages users and administrators to review the Java the Java SE 6 Update 17 release notes and apply any necessary updates to help mitigate the risks.

 

Adobe Releases Update for Shockwave Player

November 4, 2009
Adobe has released Shockwave Player 11.5.2.602 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to run malicious code on the user's machine.

US-CERT encourages users and administrators to review Adobe security bulletin APSB09-16 and update to Shockwave Player 11.5.2.602 to help mitigate the risks.

 

Mozilla Releases Firefox 3.0.15 and Firefox 3.5.4

October 28, 2009
Mozilla has released Firefox 3.0.15 and Firefox 3.5.4 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, execute arbitrary JavaScript with chrome privileges, or cause a denial-of-service condition. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect SeaMonkey.

US-CERT encourages users to review the Mozilla Foundation security advisories for Firefox 3.0 and Firefox 3.5 and apply any necessary updates or workarounds to help mitigate the risks.