<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DarkFiber Consulting - IT Managed Services &#187; Risk</title>
	<atom:link href="http://www.darkfiberla.com/tag/risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darkfiberla.com</link>
	<description>DarkFiber Consulting offers managed services for the SMB market. Some of the services we offer include network administration, server management, desktop support, smartphone and blackbery configuration, voip, and asterisk based pbx phone systems.</description>
	<lastBuildDate>Fri, 06 Aug 2010 19:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Mozilla Foundation Releases Firefox 3.0.10</title>
		<link>http://www.darkfiberla.com/security-alerts/mozilla-foundation-releases-firefox-3010/</link>
		<comments>http://www.darkfiberla.com/security-alerts/mozilla-foundation-releases-firefox-3010/#comments</comments>
		<pubDate>Sun, 10 May 2009 06:23:29 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Memory Corruption]]></category>
		<category><![CDATA[Mfsa]]></category>
		<category><![CDATA[Mozilla Foundation Security Advisory]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Vulnerability Exploitation]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/mozilla-foundation-releases-firefox-3010/</guid>
		<description><![CDATA[Mozilla Foundation has released Firefox 3.0.10 to address a memory corruption vulnerability. Exploitation of this vulnerability may result in a denial-of-service condition. DarkFiber Consulting encourages users and administrators to review Mozilla Foundation Security Advisory MFSA 2009-23 and update to Firefox 3.0.10 to help mitigate the risk. Tags: Address, Denial Of Service, Memory Corruption, Mfsa, Mozilla [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla Foundation has released <a href="http://www.mozilla.com/" target="_self">Firefox 3.0.10</a> to address a memory corruption vulnerability. Exploitation of this vulnerability may result in a denial-of-service condition.</p>
<p>DarkFiber Consulting encourages users and administrators to review Mozilla Foundation Security Advisory <a href="http://www.mozilla.org/security/announce/2009/mfsa2009-23.html" target="_self">MFSA 2009-23</a> and update to <a href="http://www.mozilla.com/" target="_self">Firefox 3.0.10</a> to help mitigate the risk.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/address/" title="Address" rel="tag">Address</a>, <a href="http://www.darkfiberla.com/tag/denial-of-service/" title="Denial Of Service" rel="tag">Denial Of Service</a>, <a href="http://www.darkfiberla.com/tag/memory-corruption/" title="Memory Corruption" rel="tag">Memory Corruption</a>, <a href="http://www.darkfiberla.com/tag/mfsa/" title="Mfsa" rel="tag">Mfsa</a>, <a href="http://www.darkfiberla.com/tag/mozilla-foundation-security-advisory/" title="Mozilla Foundation Security Advisory" rel="tag">Mozilla Foundation Security Advisory</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/vulnerability-exploitation/" title="Vulnerability Exploitation" rel="tag">Vulnerability Exploitation</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/mozilla-foundation-releases-firefox-3010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Reader and Acrobat JavaScript Vulnerabilities</title>
		<link>http://www.darkfiberla.com/security-alerts/adobe-reader-and-acrobat-javascript-vulnerabilities/</link>
		<comments>http://www.darkfiberla.com/security-alerts/adobe-reader-and-acrobat-javascript-vulnerabilities/#comments</comments>
		<pubDate>Sun, 10 May 2009 06:23:29 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Acrobat Javascript]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Help]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Enable Javascript]]></category>
		<category><![CDATA[Javascript Check]]></category>
		<category><![CDATA[Javascript Help]]></category>
		<category><![CDATA[Javascript Methods]]></category>
		<category><![CDATA[Menu Javascript]]></category>
		<category><![CDATA[Reader Acrobat]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Vulnerability Notes Database]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/adobe-reader-and-acrobat-javascript-vulnerabilities/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of two vulnerabilities affecting Adobe Reader and Acrobat. The JavaScript methods customDictionaryOpen() and getAnnots() do not safely handle specially crafted arguments and can be manipulated to execute arbitrary code. DarkFiber Consulting encourages users and administrators to disable JavaScript in Adobe Reader to help mitigate the risk: Open the [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of public reports of two vulnerabilities affecting Adobe Reader and Acrobat. The JavaScript methods customDictionaryOpen() and getAnnots() do not safely handle specially crafted arguments and can be manipulated to execute arbitrary code.</p>
<p>DarkFiber Consulting encourages users and administrators to disable JavaScript in Adobe Reader to help mitigate the risk:
<ol>
<li>Open the General Preferences dialog box</li>
<li>From the Edit menu, select Preferences and then choose JavaScript</li>
<li>Un-check Enable Acrobat JavaScript</li>
</ol>
<p>Additional information regarding these vulnerabilities can be found in the Adobe PSIRT <a href="http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html" target="_self">blog entry</a> and in the <a href="http://www.kb.cert.org/vuls/id/970180" target="_self">Vulnerability Notes Database</a>. DarkFiber Consulting will provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/acrobat-javascript/" title="Acrobat Javascript" rel="tag">Acrobat Javascript</a>, <a href="http://www.darkfiberla.com/tag/adobe-acrobat/" title="Adobe Acrobat" rel="tag">Adobe Acrobat</a>, <a href="http://www.darkfiberla.com/tag/adobe-help/" title="Adobe Help" rel="tag">Adobe Help</a>, <a href="http://www.darkfiberla.com/tag/adobe-reader/" title="Adobe Reader" rel="tag">Adobe Reader</a>, <a href="http://www.darkfiberla.com/tag/arbitrary-code/" title="Arbitrary Code" rel="tag">Arbitrary Code</a>, <a href="http://www.darkfiberla.com/tag/blog/" title="Blog" rel="tag">Blog</a>, <a href="http://www.darkfiberla.com/tag/enable-javascript/" title="Enable Javascript" rel="tag">Enable Javascript</a>, <a href="http://www.darkfiberla.com/tag/javascript-check/" title="Javascript Check" rel="tag">Javascript Check</a>, <a href="http://www.darkfiberla.com/tag/javascript-help/" title="Javascript Help" rel="tag">Javascript Help</a>, <a href="http://www.darkfiberla.com/tag/javascript-methods/" title="Javascript Methods" rel="tag">Javascript Methods</a>, <a href="http://www.darkfiberla.com/tag/menu-javascript/" title="Menu Javascript" rel="tag">Menu Javascript</a>, <a href="http://www.darkfiberla.com/tag/reader-acrobat/" title="Reader Acrobat" rel="tag">Reader Acrobat</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/vulnerability-notes-database/" title="Vulnerability Notes Database" rel="tag">Vulnerability Notes Database</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/adobe-reader-and-acrobat-javascript-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Reader Exploit Circulating</title>
		<link>http://www.darkfiberla.com/security-alerts/adobe-reader-exploit-circulating/</link>
		<comments>http://www.darkfiberla.com/security-alerts/adobe-reader-exploit-circulating/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 20:19:18 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Antivirus Applications]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Buffer Overflow Vulnerability]]></category>
		<category><![CDATA[Caution]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Virus Signatures]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/adobe-reader-exploit-circulating/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of active exploitation of a recent Adobe Reader vulnerability. This exploit appears to arrive in the form of a maliciously crafted PDF file and leverages the JavaScript buffer overflow vulnerability addressed in Adobe Security Bulletin APSB08-19. Successful exploitation may allow an attacker to execute arbitrary code or cause [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="http://isc.sans.org/diary.html?storyid=5312" target="_self">public reports</a> of active exploitation of a recent Adobe Reader vulnerability. This exploit appears to arrive in the form of a maliciously crafted PDF file and leverages the JavaScript buffer overflow vulnerability addressed in Adobe <a href="http://www.adobe.com/support/security/bulletins/apsb08-19.html" target="_self">Security Bulletin APSB08-19</a>. Successful exploitation may allow an attacker to execute arbitrary code or cause a denial-of-service condition. Additionally, the reports indicate that this exploit is currently undetectable by common antivirus applications. </p>
<p>DarkFiber Consulting encourages users and administrators to do the following to help mitigate the risk:
<ul>
<li>Review Adobe <a href="http://www.adobe.com/support/security/bulletins/apsb08-19.html" target="_self">Security Bulletin APS08-19</a> and update to Adobe Reader 9.</li>
<li>Use caution when opening untrusted files.</li>
<li>Install antivirus software and keep the virus signatures up to date.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/adobe-reader/" title="Adobe Reader" rel="tag">Adobe Reader</a>, <a href="http://www.darkfiberla.com/tag/antivirus-applications/" title="Antivirus Applications" rel="tag">Antivirus Applications</a>, <a href="http://www.darkfiberla.com/tag/arbitrary-code/" title="Arbitrary Code" rel="tag">Arbitrary Code</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/buffer-overflow-vulnerability/" title="Buffer Overflow Vulnerability" rel="tag">Buffer Overflow Vulnerability</a>, <a href="http://www.darkfiberla.com/tag/caution/" title="Caution" rel="tag">Caution</a>, <a href="http://www.darkfiberla.com/tag/denial-of-service/" title="Denial Of Service" rel="tag">Denial Of Service</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/security-bulletin/" title="Security Bulletin" rel="tag">Security Bulletin</a>, <a href="http://www.darkfiberla.com/tag/virus-signatures/" title="Virus Signatures" rel="tag">Virus Signatures</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/adobe-reader-exploit-circulating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH Key-based Attacks</title>
		<link>http://www.darkfiberla.com/security-alerts/ssh-key-based-attacks/</link>
		<comments>http://www.darkfiberla.com/security-alerts/ssh-key-based-attacks/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 19:41:54 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Affected Systems]]></category>
		<category><![CDATA[Attackers]]></category>
		<category><![CDATA[Automated Processes]]></category>
		<category><![CDATA[Computing]]></category>
		<category><![CDATA[Derivative]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hidden Processes]]></category>
		<category><![CDATA[Kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Passphrase]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Phalanx]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Shm]]></category>
		<category><![CDATA[Ssh Authentication]]></category>
		<category><![CDATA[Support Scripts]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/ssh-key-based-attacks/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as &#8220;phalanx2&#8243; is installed. Phalanx2 appears [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as &#8220;phalanx2&#8243; is installed.</p>
<p>Phalanx2 appears to be a derivative of an older rootkit named &#8220;phalanx&#8221;. Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.</p>
<p>Detection of phalanx2 as used in this attack may be performed as follows:
<ul>
<li>&#8220;ls&#8221; does not show a directory &#8220;/etc/khubd.p2/&#8221;, but it can be entered with &#8220;cd /etc/khubd.p2&#8243;.</li>
<li>&#8220;/dev/shm/&#8221; may contain files from the attack.</li>
<li>Any directory named &#8220;khubd.p2&#8243; is hidden from &#8220;ls&#8221;, but may be entered by using &#8220;cd&#8221;.</li>
<li>Changes in the configuration of the rootkit might change the attack indicators listed above. Other detection methods may include searching for hidden processes and checking the reference count in &#8220;/etc&#8221; against the number of directories shown by &#8220;ls&#8221;.</li>
</ul>
<p>DarkFiber Consulting encourages administrators to perform the following actions to help mitigate the risks:
<ul>
<li>Proactively identify and examine systems where SSH keys are used as part of automated processes. These keys will typically not have passphrases or passwords.</li>
<li>Encourage users to use the keys with passphrase or passwords to reduce the risk if a key is compromised.</li>
<li>Review access paths to internet facing systems and ensure that systems are fully patched.</li>
</ul>
<p>If a compromise is confirmed, DarkFiber Consulting recommends the following actions:
<ul>
<li>Disable key-based SSH authentication on the affected systems, where possible.</li>
<li>Perform an audit of all SSH keys on the affected systems.</li>
<li>Notify all key owners of the potential compromise of their keys.</li>
</ul>
<p>DarkFiber Consulting will provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/affected-systems/" title="Affected Systems" rel="tag">Affected Systems</a>, <a href="http://www.darkfiberla.com/tag/attackers/" title="Attackers" rel="tag">Attackers</a>, <a href="http://www.darkfiberla.com/tag/automated-processes/" title="Automated Processes" rel="tag">Automated Processes</a>, <a href="http://www.darkfiberla.com/tag/computing/" title="Computing" rel="tag">Computing</a>, <a href="http://www.darkfiberla.com/tag/derivative/" title="Derivative" rel="tag">Derivative</a>, <a href="http://www.darkfiberla.com/tag/exploits/" title="Exploits" rel="tag">Exploits</a>, <a href="http://www.darkfiberla.com/tag/hidden-processes/" title="Hidden Processes" rel="tag">Hidden Processes</a>, <a href="http://www.darkfiberla.com/tag/kernel/" title="Kernel" rel="tag">Kernel</a>, <a href="http://www.darkfiberla.com/tag/linux/" title="Linux" rel="tag">Linux</a>, <a href="http://www.darkfiberla.com/tag/passphrase/" title="Passphrase" rel="tag">Passphrase</a>, <a href="http://www.darkfiberla.com/tag/passwords/" title="Passwords" rel="tag">Passwords</a>, <a href="http://www.darkfiberla.com/tag/phalanx/" title="Phalanx" rel="tag">Phalanx</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/rootkit/" title="Rootkit" rel="tag">Rootkit</a>, <a href="http://www.darkfiberla.com/tag/shm/" title="Shm" rel="tag">Shm</a>, <a href="http://www.darkfiberla.com/tag/ssh-authentication/" title="Ssh Authentication" rel="tag">Ssh Authentication</a>, <a href="http://www.darkfiberla.com/tag/support-scripts/" title="Support Scripts" rel="tag">Support Scripts</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/ssh-key-based-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RealPlayer Releases Update</title>
		<link>http://www.darkfiberla.com/security-alerts/realplayer-releases-update/</link>
		<comments>http://www.darkfiberla.com/security-alerts/realplayer-releases-update/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 04:24:00 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Activex Controls]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Based Buffer Overflow]]></category>
		<category><![CDATA[Heap Memory]]></category>
		<category><![CDATA[Import Method]]></category>
		<category><![CDATA[Memory Corruption]]></category>
		<category><![CDATA[Realnetworks]]></category>
		<category><![CDATA[Realplayer Update]]></category>
		<category><![CDATA[Resource Reference]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Swf File]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/realplayer-releases-update/</guid>
		<description><![CDATA[RealNetworks has released an update to address multiple vulnerabilities in RealPlayer. These vulnerabilities may allow an attacker to execute arbitrary code or obtain sensitive information. RealNetworks identifies the vulnerabilities as the following: RealPlayer ActiveX controls property heap memory corruption. Local resource reference vulnerability in RealPlayer. RealPlayer SWF file heap-based buffer overflow. RealPlayer ActiveX import method [...]]]></description>
			<content:encoded><![CDATA[<p>RealNetworks has released an update to address multiple vulnerabilities in RealPlayer. These vulnerabilities may allow an attacker to execute arbitrary code or obtain sensitive information. RealNetworks identifies the vulnerabilities as the following:
<ul>
<li>RealPlayer ActiveX controls property heap memory corruption.</li>
<li>Local resource reference vulnerability in RealPlayer.</li>
<li>RealPlayer SWF file heap-based buffer overflow.</li>
<li>RealPlayer ActiveX import method buffer overflow.</li>
</ul>
<p>DarkFiber Consulting encourages users to review the RealNetworks <a href="http://service.real.com/realplayer/security/07252008_player/en/" target="_self">advisory</a> and apply the appropriate updates to help mitigate the risk.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/activex-controls/" title="Activex Controls" rel="tag">Activex Controls</a>, <a href="http://www.darkfiberla.com/tag/address/" title="Address" rel="tag">Address</a>, <a href="http://www.darkfiberla.com/tag/arbitrary-code/" title="Arbitrary Code" rel="tag">Arbitrary Code</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/based-buffer-overflow/" title="Based Buffer Overflow" rel="tag">Based Buffer Overflow</a>, <a href="http://www.darkfiberla.com/tag/heap-memory/" title="Heap Memory" rel="tag">Heap Memory</a>, <a href="http://www.darkfiberla.com/tag/import-method/" title="Import Method" rel="tag">Import Method</a>, <a href="http://www.darkfiberla.com/tag/memory-corruption/" title="Memory Corruption" rel="tag">Memory Corruption</a>, <a href="http://www.darkfiberla.com/tag/realnetworks/" title="Realnetworks" rel="tag">Realnetworks</a>, <a href="http://www.darkfiberla.com/tag/realplayer-update/" title="Realplayer Update" rel="tag">Realplayer Update</a>, <a href="http://www.darkfiberla.com/tag/resource-reference/" title="Resource Reference" rel="tag">Resource Reference</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/swf-file/" title="Swf File" rel="tag">Swf File</a>, <a href="http://www.darkfiberla.com/tag/vulnerabilities/" title="Vulnerabilities" rel="tag">Vulnerabilities</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/realplayer-releases-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackBerry Security Advisory</title>
		<link>http://www.darkfiberla.com/security-alerts/blackberry-security-advisory/</link>
		<comments>http://www.darkfiberla.com/security-alerts/blackberry-security-advisory/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 19:52:43 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Blackberry Server]]></category>
		<category><![CDATA[Distiller]]></category>
		<category><![CDATA[Enterprise Server]]></category>
		<category><![CDATA[Pdf Files]]></category>
		<category><![CDATA[Research In Motion]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Running]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Workarounds]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/blackberry-security-advisory/</guid>
		<description><![CDATA[Research In Motion has released a Security Advisory to address a vulnerability in the BlackBerry Enterprise Server. This vulnerability is due to the improper processing of PDF files within the distiller component of the BlackBerry Attachment Service. By convincing a user to open a maliciously crafted PDF attachment on a BlackBerry smartphone, an attacker may [...]]]></description>
			<content:encoded><![CDATA[<p>Research In Motion has released a <a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB15766" target="_self">Security Advisory</a> to address a vulnerability in the BlackBerry Enterprise Server. This vulnerability is due to the improper processing of PDF files within the distiller component of the BlackBerry Attachment Service. By convincing a user to open a maliciously crafted PDF attachment on a BlackBerry smartphone, an attacker may be able to execute arbitrary code on the system running the BlackBerry Attachment Service.</p>
<p>DarkFiber Consulting encourages users to review BlackBerry Security Advisory <a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB15766" target="_self">KB15766</a> and apply the resolution or implement the workarounds listed in the document to help mitigate the risk.</p>
<p>DarkFiber Consulting will provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/address/" title="Address" rel="tag">Address</a>, <a href="http://www.darkfiberla.com/tag/arbitrary-code/" title="Arbitrary Code" rel="tag">Arbitrary Code</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/blackberry-server/" title="Blackberry Server" rel="tag">Blackberry Server</a>, <a href="http://www.darkfiberla.com/tag/distiller/" title="Distiller" rel="tag">Distiller</a>, <a href="http://www.darkfiberla.com/tag/enterprise-server/" title="Enterprise Server" rel="tag">Enterprise Server</a>, <a href="http://www.darkfiberla.com/tag/pdf-files/" title="Pdf Files" rel="tag">Pdf Files</a>, <a href="http://www.darkfiberla.com/tag/research-in-motion/" title="Research In Motion" rel="tag">Research In Motion</a>, <a href="http://www.darkfiberla.com/tag/risk/" title="Risk" rel="tag">Risk</a>, <a href="http://www.darkfiberla.com/tag/running/" title="Running" rel="tag">Running</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a>, <a href="http://www.darkfiberla.com/tag/workarounds/" title="Workarounds" rel="tag">Workarounds</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/blackberry-security-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
