May 9th, 2009 . by DarkFiber Consulting
Microsoft has issued a Security Bulletin Advance Notification indicating that the May release cycle will contain one bulletin with a maximum severity rating of Critical. The notification states that the Critical bulletin is for Microsoft PowerPoint. The release is scheduled for Tuesday, May 12.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Advance Notification • Maximum • Microsoft • Microsoft Powerpoint • Microsoft Security • Security Bulletin • Severity Rating
May 9th, 2009 . by DarkFiber Consulting
Adobe has released Security Bulletin APSB09-05 to address a potential vulnerability in versions of Flash Media Server up to and including version 3.5.1.
This vulnerability may allow an attacker to “execute remote procedures within a server side ActionScript file running on a Flash Media Server.” According to Adobe, this issue affects versions of Flash Media Interactive Server and Flash Media Streaming Server.
DarkFiber Consulting encourages users to review Adobe Security Bulletin APSB09-05 and upgrade to the most current version of Flash Media Server.
Posted in Security Alerts | No Comments »
Tagged With: Adobe • Attacker • Current Version • Flash Media • Interactive Flash • Interactive Media • Interactive Server • Media Server • Media Streaming Server • Running • Security Bulletin • Server Security • Server Side • Vulnerability
May 9th, 2009 . by DarkFiber Consulting
Symantec has released three security advisories to address multiple vulnerabilities in Symantec Alert Management System, Log Viewer, and Reporting Server. These vulnerabilities may allow an attacker to execute arbitrary code, bypass security mechanisms, or leverage phishing attacks.
DarkFiber Consulting encourages users and administrators to review the following Symantec Security Advisories and apply any necessary updates or workarounds to help mitigate the risks:
DarkFiber Consulting also encourages users to continue following the best practices provided in the advisories to minimize future risks.
Posted in Security Alerts | No Comments »
Tagged With: Address • Alert Management • Arbitrary Code • Attacker • Best Practices • Javascript • Leverage • Log Viewer • Management System • Necessary Updates • Security Advisories • Security Mechanisms • Symantec • Symantec Security • Vulnerabilities • Workarounds
May 9th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of two vulnerabilities affecting Adobe Reader and Acrobat. The JavaScript methods customDictionaryOpen() and getAnnots() do not safely handle specially crafted arguments and can be manipulated to execute arbitrary code.
DarkFiber Consulting encourages users and administrators to disable JavaScript in Adobe Reader to help mitigate the risk:
- Open the General Preferences dialog box
- From the Edit menu, select Preferences and then choose JavaScript
- Un-check Enable Acrobat JavaScript
Additional information regarding these vulnerabilities can be found in the Adobe PSIRT blog entry and in the Vulnerability Notes Database. DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Javascript • Adobe Acrobat • Adobe Help • Adobe Reader • Arbitrary Code • Blog • Enable Javascript • Javascript Check • Javascript Help • Javascript Methods • Menu Javascript • Reader Acrobat • Risk • Vulnerability Notes Database
May 9th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.
DarkFiber Consulting encourages users to take the following measures to protect themselves:
UPDATE: Due to these potential phishing attacks and email scams, DarkFiber Consulting encourages users to visit the Center for Disease Control (CDC) website for trusted information regarding the Swine Flu.
Posted in Security Alerts | No Comments »
Tagged With: Attachments • Cdc • Cdc Website • Center For Disease Control • Email Messages • Email Scams • Exposed • Flu • Malicious Code • Measures • Phishing Attacks • Social Engineering • Subject Line • Swine Flu • Unsolicited Email
May 9th, 2009 . by DarkFiber Consulting
Mozilla Foundation has released Firefox 3.0.10 to address a memory corruption vulnerability. Exploitation of this vulnerability may result in a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review Mozilla Foundation Security Advisory MFSA 2009-23 and update to Firefox 3.0.10 to help mitigate the risk.
Posted in Security Alerts | No Comments »
Tagged With: Address • Denial Of Service • Memory Corruption • Mfsa • Mozilla Foundation Security Advisory • Risk • Vulnerability Exploitation
May 9th, 2009 . by DarkFiber Consulting
Mozilla Foundation has released Firefox 3.0.9 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, leverage additional attacks, or obtain sensitive information. The Mozilla Foundation security advisories indicate that many of these vulnerabilities also affect SeaMonkey and Thunderbird.
DarkFiber Consulting encourages users and administrators to review the Mozilla Foundation Security Advisories website for more information about the vulnerabilities and upgrade to Firefox 3.0.9 to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Information Security • Leverage • Mozilla Foundation Security Advisories • Seamonkey • Thunderbird
May 9th, 2009 . by DarkFiber Consulting
Research In Motion has released a security advisory to address multiple vulnerabilities in the PDF distiller of some released versions of the BlackBerry Attachment Service. The advisory lists the affected versions as BlackBerry Enterprise Server 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4. By convincing a user to view a specially crafted PDF file, an attacker may be able to execute arbitrary code on the system that hosts the Blackberry Attachment Service.
DarkFiber Consulting encourages users to review BlackBerry security advisory KB17953 and apply any necessary updates.
Additional information is available in the Vulnerability Notes Database.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Blackberry Server • Blackberry Software • Enterprise Server • Nbsp • Necessary Updates • Pdf Distiller • Pdf File • Professional Software • Research In Motion • Vulnerability Notes Database
May 9th, 2009 . by DarkFiber Consulting
Oracle has released their Critical Patch Update for April 2009 to address 43 vulnerabilities across several products. This update contains the following security fixes:
- 16 updates for Oracle Database Server
- 12 updates for Oracle Application Server
- 3 updates for Oracle Applications
- 4 updates for Oracle PeopleSoft and JDEdwards Suite
- 8 updates for BEA Products Suite
DarkFiber Consulting encourages users and administrators to review the April Critical Patch Update and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Address • April • Bea • Critical Patch • Jdedwards • Necessary Updates • Oracle • Oracle Application Server • Oracle Applications • Oracle Database Server • Oracle Peoplesoft • Oracle Server • Security Fixes • Server Applications • Vulnerabilities
May 9th, 2009 . by DarkFiber Consulting
In the past, DarkFiber Consulting has received reports of an increased number of phishing scams that take advantage of the United States tax season. Due to the upcoming tax deadline, DarkFiber Consulting would like to remind users to remain cautious when receiving unsolicited email that could be a potential phishing scam.
Phishing scams may appear as a tax refund, an offer to assist in filing for a refund, or contain details about fake e-file websites. These messages may appear to be from the IRS and directly ask users for personal information. These messages may also contain a link and instruct the user to follow the link to a website that requests personal information or contains malicious code.
DarkFiber Consulting encourages users to take the following measures to protect themselves from this type of phishing scam:
Posted in Security Alerts | No Comments »
Tagged With: Advantage • E File • Email Messages • Email Scams • Irs • Malicious Code • Measures • Phishing Attacks • Phishing Scam • Phishing Scams • Social Engineering • Tax Deadline • Tax Refund • United States • Unsolicited Email