Subscribe: US-CERT Technical Alerts and Bulletins
http://www.us-cert.gov/channels/techdocs.rdf
Preview: US-CERT Technical Alerts and Bulletins

US-CERT: The United States Computer Emergency Readiness Team





 



Apple Releases Security Update for iTunes

Fri, 24 Mar 2017 18:07:23 +0000

Original release date: March 24, 2017

Apple has released a security update for Apple iTunes to address multiple vulnerabilities. Exploitation of some of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.

Users and administrators are encouraged to review information on iTunes 12.6 and apply the necessary update.


This product is provided subject to this Notification and this Privacy & Use policy.





Aviation Phishing Scams

Thu, 23 Mar 2017 20:27:05 +0000

Original release date: March 23, 2017

US-CERT has received reports of email-based phishing campaigns targeting airline consumers. Systems infected through phishing campaigns act as an entry point for attackers to gain access to sensitive business or personal information.

US-CERT encourages users and administrators to review an airline Security Advisory and US-CERT's Security Tip ST04-014 for more information on phishing attacks.


This product is provided subject to this Notification and this Privacy & Use policy.





Cisco Releases Security Updates

Wed, 22 Mar 2017 22:02:41 +0000

Original release date: March 22, 2017

Cisco has released security updates to address vulnerabilities in its IOS, IOS XE, and IOx Software. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system or cause a denial-of-service condition.

Users and administrators are encouraged to review the following Cisco Security Advisories and apply the necessary updates:

 


This product is provided subject to this Notification and this Privacy & Use policy.





Vulnerabilities Identified in Network Time Protocol Daemon (ntpd)

Wed, 22 Mar 2017 17:20:27 +0000

Original release date: March 22, 2017

The Network Time Foundation's NTP Project has has released version ntp-4.2.8p10 to address multiple vulnerabilities in ntpd. Exploitation of some of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.

US-CERT encourages users and administrators to review the NTP Security Notice Page for vulnerability and mitigation details.


This product is provided subject to this Notification and this Privacy & Use policy.





Cisco Releases Security Updates

Tue, 21 Mar 2017 15:57:06 +0000

Original release date: March 21, 2017

Cisco has released security updates to address vulnerabilities in its IOS and IOS XE Software. Exploitation of one of these vulnerabilities could allow a remote attacker to cause a denial of service condition.

Users and administrators are encouraged to review the following Cisco Security Advisories and apply the necessary updates:


This product is provided subject to this Notification and this Privacy & Use policy.





SB17-079: Vulnerability Summary for the Week of March 13, 2017

Mon, 20 Mar 2017 13:37:11 +0000

Original release date: March 20, 2017 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.  High VulnerabilitiesPrimaryVendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infoadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-2997BIDCONFIRMadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-2998BIDCONFIRMadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-2999BIDCONFIRMadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-3001BIDCONFIRMadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability in the ActionScript2 TextField object related to the variable property. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-3002BIDCONFIRMadobe -- flash_playerAdobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code execution.2017-03-1410.0CVE-2017-3003BIDCONFIRMalienvault -- ossimThe logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.2017-03-157.5CVE-2016-7955BUGTRAQMISCCONFIRMapache -- strutsThe Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote att[...]



IRS Warns of Last-Minute Tax Scams

Sat, 18 Mar 2017 03:21:10 +0000

Original release date: March 17, 2017

The Internal Revenue Service (IRS) has released an alert warning of phishing email scams targeting last-minute tax filers. The alert describes common features of these cyber crimes and includes recommendations to protect against them: strengthen passwords, recognize phishing attempts, and forward suspicious emails to phishing@irs.gov.

Tax payers and tax professionals are encouraged to review the IRS alert and US-CERT's advice on Avoiding Social Engineering and Phishing Attacks.


This product is provided subject to this Notification and this Privacy & Use policy.





Mozilla Releases Security Updates

Sat, 18 Mar 2017 00:54:28 +0000

Original release date: March 17, 2017

Mozilla has released security updates to address a vulnerability in Firefox and Firefox ESR. Exploitation of this vulnerability may allow an attacker to take control of an affected system.

US-CERT encourages users and administrators to review the Mozilla Security Advisory for Firefox and Firefox ESR and apply the necessary updates.


This product is provided subject to this Notification and this Privacy & Use policy.





Microsoft Ending Support for Windows Vista

Fri, 17 Mar 2017 04:45:45 +0000

Original release date: March 17, 2017

All software products have a lifecycle. After April 11, 2017, Microsoft is ending support for the Windows Vista operating system. After this date, this product will no longer receive:

  • Security updates,
  • Non-security hotfixes,
  • Free or paid assisted support options, or
  • Online technical content updates from Microsoft.

Computers running the Windows Vista operating system will continue to work even after support ends. However, using unsupported software may increase the risks of viruses and other security threats.

Users and administrators are encouraged to upgrade to a currently supported operating system. For more information, see Microsoft's Vista support and product lifecycle articles.

US-CERT does not endorse or support any particular product or vendor.


This product is provided subject to this Notification and this Privacy & Use policy.





Microsoft SMBv1 Vulnerability

Thu, 16 Mar 2017 22:12:41 +0000

Original release date: March 16, 2017

Microsoft has released a security update to address a vulnerability in implementations of Server Message Block 1.0 (SMBv1). Exploitation of this vulnerability could allow a remote attacker to take control of an affected system.

US-CERT encourages users and administrators to review Microsoft Security Bulletin MS17-010 and apply the update. For more information, see the Information Assurance Advisory and US-CERT's SMB Security Best Practices guidance.


This product is provided subject to this Notification and this Privacy & Use policy.