<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" version="2.0">
   <channel>
      <title>secfeeds_vulnheadlines</title>
      <description>Pipes Output</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=Yu2HGe7Y3BGbgnayy6ky6g</link>
      <atom:link rel="next" href="http://pipes.yahoo.com/pipes/pipe.run?_id=Yu2HGe7Y3BGbgnayy6ky6g&amp;_render=rss&amp;page=2" />
      <pubDate>Wed, 16 May 2012 09:48:17 +0000</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/notageek_secfeeds_vulnheadlines" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="notageek_secfeeds_vulnheadlines" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by/3.0/</creativeCommons:license><item>
         <title>Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability</title>
         <link>http://www.securityfocus.com/bid/51273</link>
         <description>Pligg CMS 'status' Parameter SQL Injection Vulnerability&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/HdmUPRdDHVA" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
         <pubDate>Sat, 29 Dec 2012 00:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Vuln: WordPress WP-FaceThumb 'pagination_wp_facethum' Parameter Cross Site Scripting Vulnerability</title>
         <link>http://www.securityfocus.com/bid/53497</link>
         <description>WordPress WP-FaceThumb 'pagination_wp_facethum' Parameter Cross Site Scripting Vulnerability&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/McwU0ppMACE" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
         <pubDate>Tue, 15 May 2012 00:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Vuln: Serendipity SQL Injection and Cross Site Scripting Vulnerabilities</title>
         <link>http://www.securityfocus.com/bid/53418</link>
         <description>Serendipity SQL Injection and Cross Site Scripting Vulnerabilities&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/wLe_NskS2dI" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
         <pubDate>Tue, 15 May 2012 00:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Vuln: RETIRED: Serendipity SQL Injection and Cross Site Scripting Vulnerabilities</title>
         <link>http://www.securityfocus.com/bid/53428</link>
         <description>RETIRED: Serendipity SQL Injection and Cross Site Scripting Vulnerabilities&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/GGFDiWMTrVc" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
         <pubDate>Tue, 15 May 2012 00:00:00 +0000</pubDate>
      </item>
      <item>
         <title>MS12-035 - Critical : Vulnerabilities in .NET Framework Could Allow Remote Code Execution (2693777) - Version: 2.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-035</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-035</guid>
         <pubDate>Fri, 11 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V2.0 (May 11, 2012): Added an entry to the update FAQ to communicate that security update KB2656353 addresses the vulnerabilities described in this bulletin for all supported systems running Microsoft .NET Framework 1.1 Service Pack 1, except when installed on Windows Server 2003 Service Pack 2. There were no changes to the security update files. Customers who have successfully installed the update do not need to take any action.<br />
          Summary: This security update resolves two privately reported vulnerabilities in the .NET Framework. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/s0DOpV6Kijg" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420) - Version: 1.4</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-100</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-100</guid>
         <pubDate>Fri, 11 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.4 (May 11, 2012): Added entry to the update FAQ to announce that KB2656353, offered in this bulletin, also addresses CVE-2012-0160 and CVE-2012-0161, which are documented in MS12-035.<br />
          Summary: This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft .NET Framework. The most severe of these vulnerabilities could allow elevation of privilege if an unauthenticated attacker sends a specially crafted web request to the target site. An attacker who successfully exploited this vulnerability could take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands. In order to exploit this vulnerability, an attacker must be able to register an account on the ASP.NET site, and must know an existing user name.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/4fGoMF7-uOw" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-029 - Critical : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-029</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-029</guid>
         <pubDate>Wed, 09 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.1 (May 9, 2012): Corrected update replacement information for Microsoft Office Compatibility Pack Service Pack 2. This is a bulletin change only. There were no changes to detection logic or security update files.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted RTF file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/aIJPwlidiwQ" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-129A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-129A.html</link>
         <description>Original release date: May 08, 2012 | Last revised: --

Systems Affected

Microsoft Windows
Microsoft .NET Framework
Microsoft Office
Microsoft Silverlight


Overview
Select Microsoft software products contain multiple vulnerabilities.  Microsoft has released updates to address these vulnerabilities.

Description
The Microsoft Security Bulletin Summary for May 2012 describes multiple vulnerabilities in Microsoft software. Microsoft has released updates to address the vulnerabilities.

Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.

Solution
Apply updates

Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for May 2012, which describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. In addition, administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS). Home users are encouraged to enable automatic updates.

References

Microsoft Security Bulletin Summary for May 2012 - 
Microsoft Windows Server Update Services - 
Microsoft Update - 
Microsoft Update Overview - 
Turn Automatic Updating On or Off - 


Revision History

May 08, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/XK8lLhLMN5k" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-129A.html</guid>
         <pubDate>Tue, 08 May 2012 21:01:03 +0000</pubDate>
      </item>
      <item>
         <title>MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-034</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-034</guid>
         <pubDate>Tue, 08 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (May 8, 2012): Bulletin published.<br />
          Summary: This security update resolves three publicly disclosed vulnerabilities and seven privately reported vulnerabilities in Microsoft Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/xha4Zcc_Yfo" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-033 - Important : Vulnerability in Windows Partition Manager Could Allow Elevation of Privilege (2690533) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-033</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-033</guid>
         <pubDate>Tue, 08 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (May 8, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Ul8uNoMREH0" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-032 - Important : Vulnerability in TCP/IP Could Allow Elevation of Privilege (2688338) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-032</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-032</guid>
         <pubDate>Tue, 08 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (May 8, 2012): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/zF828yi4e-Y" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-031 - Important : Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2597981) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-031</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-031</guid>
         <pubDate>Tue, 08 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (May 8, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/vpIUCP_Da7U" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-030 - Important : Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2663830) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-030</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-030</guid>
         <pubDate>Tue, 08 May 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (May 8, 2012): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed and five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/v0CWvXKrwJM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>VU#520827: PHP-CGI query string parameter vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/520827</link>
         <description>&lt;h1&gt;Vulnerability Note VU#520827&lt;/h1&gt;
		 &lt;h2&gt;PHP-CGI query string parameter vulnerability&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 03 May 2012 | Last revised: 08 May 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;PHP-CGI-based setups contain a vulnerability when parsing query string parameters from php files.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;According to PHP's &lt;a rel="nofollow" target="_blank" href="http://php.net/"&gt;website&lt;/a&gt;, &amp;quot;PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML.&amp;quot; When PHP is used in a CGI-based setup (such as Apache's &lt;tt&gt;mod_cgid&lt;/tt&gt;), the &lt;tt&gt;php-cgi&lt;/tt&gt; receives a processed query string parameter as command line arguments which allows command-line switches, such as &lt;tt&gt;-s, -d or -c&lt;/tt&gt; to be passed to the &lt;tt&gt;php-cgi&lt;/tt&gt; binary, which can be exploited to disclose source code and obtain arbitrary code execution.
&lt;p&gt;An example of the &lt;tt&gt;-s&lt;/tt&gt; command, allowing an attacker to view the source code of &lt;tt&gt;index.php&lt;/tt&gt; is below:
&lt;ul&gt;&lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://localhost/index.php?-s"&gt;http://localhost/index.php?-s&lt;/a&gt;&lt;/tt&gt;&lt;br&gt;
&lt;/ul&gt;
Additional information can be found in the vulnerability reporter's &lt;a rel="nofollow" target="_blank" href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/"&gt;blog post&lt;/a&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;A remote unauthenticated attacker could obtain sensitive information, cause a denial of service condition or may be able to execute arbitrary code with the privileges of the web server.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Apply update&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
PHP has released version &lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-08-1"&gt;5.4.3&lt;/a&gt; and &lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-08-1"&gt;5.3.13&lt;/a&gt; to address this vulnerability. PHP is recommending that users upgrade to the latest version of PHP.&lt;br&gt;
&lt;br&gt;
PHP has stated, &lt;i&gt;PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described in CVE-2012-1823. It has also come to our attention that some sites use an insecure cgiwrapper script to run PHP. These scripts will use $* instead of &amp;quot;$@&amp;quot; to pass parameters to php-cgi which causes a number of issues.&lt;/i&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Apply mod_rewrite rule&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
&lt;i&gt;PHP has &lt;/i&gt;&lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-03-1"&gt;&lt;i&gt;stated &lt;/i&gt;&lt;/a&gt;&lt;i&gt;an alternative is to configure your web server to not let these types of requests with query strings starting with a &amp;quot;-&amp;quot; and not containing a &amp;quot;=&amp;quot; through. Adding a rule like this should not break any sites. For Apache using mod_rewrite it would look like this&lt;/i&gt;:&lt;br&gt;

&lt;ul&gt;&lt;tt&gt;&amp;nbsp; &amp;nbsp; RewriteCond %{QUERY_STRING} ^[^=]*$&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&amp;nbsp; &amp;nbsp; RewriteCond %{QUERY_STRING} %2d|&amp;#92;- [NC]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&amp;nbsp; &amp;nbsp; RewriteRule .? - [F,L]&lt;/tt&gt;&lt;/ul&gt;
&lt;br&gt;
&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;&lt;br&gt;
According to PHP's &lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-03-1"&gt;website&lt;/a&gt; &lt;i&gt;Apache+mod_php and nginx+php-fpm are not affected.&lt;/i&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;The PHP Group&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;23 Feb 2012&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;08 May 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;9.0&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:N/AC:L/Au:N/C:C/I:P/A:P&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;8.5&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:F/RL:U/RC:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;8.7&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:L/TD:H/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.php.net/"&gt;http://www.php.net/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.php.net/manual/en/security.cgi-bin.php"&gt;http://www.php.net/manual/en/security.cgi-bin.php&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/"&gt;http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-03-1"&gt;http://www.php.net/archive/2012.php#id2012-05-03-1&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.php.net/archive/2012.php#id2012-05-08-1"&gt;http://www.php.net/archive/2012.php#id2012-05-08-1&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;Thanks to De Eindbazen for reporting this vulnerability.&lt;/p&gt;
&lt;p&gt;This document was written by Michael Orlando.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1823"&gt;CVE-2012-1823&lt;/a&gt;
&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2311"&gt;CVE-2012-2311&lt;/a&gt;&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;03 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;03 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;08 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;29&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23520827 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/FWAuE8GZGIg" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/520827</guid>
         <pubDate>Thu, 03 May 2012 19:29:56 +0000</pubDate>
      </item>
      <item>
         <title>VU#359816: Oracle database TNS listener vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/359816</link>
         <description>&lt;h1&gt;Vulnerability Note VU#359816&lt;/h1&gt;
		 &lt;h2&gt;Oracle database TNS listener vulnerability&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 01 May 2012 | Last revised: 01 May 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;The Oracle database component contains a vulnerability in the TNS listener service that may be exploited to sniff database traffic and run arbitrary database commands.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;The Oracle database component contains a vulnerability in the TNS listener service that has been referred to as (TNS Poison) in public discussions.  The TNS listener service accepts unauthenticated remote registrations with the appropriate connect packet (&lt;tt&gt;COMMAND=SERVICE_REGISTER_NSGR&lt;/tt&gt;).  Joxean Koret's &lt;a rel="nofollow" target="_blank" href="http://seclists.org/fulldisclosure/2012/Apr/204"&gt;email to the Full Disclosure mailing list &lt;/a&gt;contains additional details.  &lt;a rel="nofollow" target="_blank" href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html"&gt;Oracle Security Alert for CVE-2012-1675&lt;/a&gt; also contains more information.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;An unauthenticated attacker may be able to register a client using an already registered database's instance name to perform a man-in-the-middle attack that allows the attack to sniff database traffic and inject database commands to the server.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;We are currently unaware of a practical solution to this problem.  Please consider the following workarounds provided by Oracle.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://support.oracle.com/CSP/main/article?cmd=show&amp;amp;type=NOT&amp;amp;id=1453883.1"&gt;Using Class of Secure Transport (COST) to Restrict Instance Registration&lt;/a&gt;
&lt;ul&gt;
&lt;p&gt;&lt;i&gt;&amp;quot;To demonstrate how the COST parameter &amp;quot;SECURE_REGISTER_listener_name = (IPC)&amp;quot; is used to restrict instance registration with database listeners. With this COST restriction in place only local instances will be allowed to register. These instructions can be used to address the issues published in Oracle Security Alert CVE-2012-1675 by using COST to restrict connections to only local instances.&amp;quot;&lt;/i&gt;&lt;/ul&gt;
&lt;br&gt;
&lt;a rel="nofollow" target="_blank" href="http://support.oracle.com/CSP/main/article?cmd=show&amp;amp;type=NOT&amp;amp;id=1340831.1"&gt;Using Class of Secure Transport (COST) to Restrict Instance Registration in Oracle RAC&lt;/a&gt;
&lt;ul&gt;&lt;i&gt;&amp;quot;&lt;/i&gt;&lt;i&gt;To demonstrate how the COST parameter &amp;quot;SECURE_REGISTER_&lt;/i&gt;&lt;i&gt;listener_name&lt;/i&gt;&lt;i&gt; = &amp;quot; is used to restrict instance registration with local node and SCAN listeners in an 11.2. RAC environment. With COST restrictions in place only local and authorized instances having appropriate credentials will be allowed to register. These instructions can be used to address the issues published in Oracle Security Alert CVE-2012-1675 by using COST to restrict connections to only those instances having appropriate credentials.&amp;quot;&lt;/i&gt;&lt;/ul&gt;
&lt;br&gt;
Additional information may be found at the links above.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;-&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;01 May 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;7.5&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:N/AC:L/Au:N/C:P/I:P/A:P&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;5.9&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:POC/RL:OF/RC:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;5.9&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:ND/TD:H/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html"&gt;http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1340831.1"&gt;http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1340831.1&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1453883.1"&gt;http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1453883.1&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://seclists.org/fulldisclosure/2012/Apr/204"&gt;http://seclists.org/fulldisclosure/2012/Apr/204&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://seclists.org/fulldisclosure/2012/Apr/343"&gt;http://seclists.org/fulldisclosure/2012/Apr/343&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html"&gt;http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;This vulnerability was discovered by Joxean Koret.&lt;/p&gt;
&lt;p&gt;This document was written by Jared Allar.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1675"&gt;CVE-2012-1675&lt;/a&gt;&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;27 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;01 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;01 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;15&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23359816 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/hQTJtv_sXrE" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/359816</guid>
         <pubDate>Tue, 01 May 2012 18:43:31 +0000</pubDate>
      </item>
      <item>
         <title>MS12-027 - Critical : Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2664258) - Version: 2.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-027</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-027</guid>
         <pubDate>Thu, 26 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V2.0 (April 26, 2012): Added Service Pack 1 versions of SQL Server 2008 R2 to the Affected Software and added an entry to the update FAQ to explain which SQL Server 2000 update to use based on version ranges. These are informational changes only. There were no changes to the security update files or detection logic. For a complete list of changes, see the entry to the section, Frequently Asked Questions (FAQ) Related to This Security Update.<br />
          Summary: This security update resolves a privately disclosed vulnerability in Windows common controls. The vulnerability could allow remote code execution if a user visits a website containing specially crafted content designed to exploit the vulnerability. In all cases, however, an attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website. The malicious file could be sent as an email attachment as well, but the attacker would have to convince the user to open the attachment in order to exploit the vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/HxjCZGQN1SI" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-028 - Important : Vulnerability in Microsoft Office Could Allow Remote Code Execution (2639185) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-028</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-028</guid>
         <pubDate>Wed, 25 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (April 25, 2012): Added an entry to the update FAQ to explain why this update is offered to customers running Microsoft Office 2007 Service Pack 3.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office and Microsoft Works. The vulnerability could allow remote code execution if a user opens a specially crafted Works file. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/ELg0pLWzfsU" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>VU#889195: RuggedCom Rugged Operating System (ROS) contains hard-coded user account with predictable password</title>
         <link>http://www.kb.cert.org/vuls/id/889195</link>
         <description>&lt;h1&gt;Vulnerability Note VU#889195&lt;/h1&gt;
		 &lt;h2&gt;RuggedCom Rugged Operating System (ROS) contains hard-coded user account with predictable password&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 24 Apr 2012 | Last revised: 01 May 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;RuggedCom Rugged Operating System (ROS) contains a hard-coded user account with a predictable password.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/support/software/index.php"&gt;RuggedCom Rugged Operating System&lt;/a&gt; (ROS), used in RuggedCom &lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/products/index.php"&gt;&lt;font color="#0000FF"&gt;network infrastructure devices&lt;/font&gt;&lt;/a&gt;, contains a hard-coded user account named &amp;quot;&lt;tt&gt;factory&lt;/tt&gt;&amp;quot; that cannot be disabled. The password for this account is based on the device's MAC address and can be reverse engineered easily (&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/261.html"&gt;CWE-261&lt;/a&gt;: Weak Cryptography for Passwords).
&lt;p&gt;ROS also supports HTTP(S) and &lt;tt&gt;ssh&lt;/tt&gt; services. In ROS 3.3.x, these services do not use the &lt;tt&gt;factory&lt;/tt&gt; account. ROS does not appear to log successful or unsuccessful login attempts for the &lt;tt&gt;factory&lt;/tt&gt; account.&lt;br&gt;
&lt;br&gt;
More information is available in &amp;quot;&lt;a rel="nofollow" target="_blank" href="http://seclists.org/fulldisclosure/2012/Apr/277"&gt;Undocumented Backdoor Access to RuggedCom Devices&lt;/a&gt;&amp;quot; and RuggedCom's &lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/productbulletin/ros-security-page/"&gt;security bulletin&lt;/a&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;An attacker with knowledge of an ROS device's MAC address may be able to gain complete administrative control of the device. The MAC address is &lt;a rel="nofollow" target="_blank" href="http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars"&gt;displayed&lt;/a&gt; in the pre-authentication banner.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;We are currently unaware of a practical solution to this problem.&lt;br&gt;
&lt;br&gt;
According to RuggedCom's &lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/productbulletin/ros-security-page/"&gt;security bulletin&lt;/a&gt;, &amp;quot;In the next few weeks, RuggedCom will be releasing new versions of ROS firmware that removes the undocumented factory account. RuggedCom plans to have all the above-mentioned upgrades to ROS firmware and RuggedExplorer available through our customer support channel within the next few weeks and will issue another bulletin containing further details at that time.&amp;quot;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Workarounds&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
ROS 3.3.x allows users to disable the &lt;tt&gt;rsh&lt;/tt&gt; service and set the number of allowed &lt;tt&gt;telnet&lt;/tt&gt; connections to 0. ROS 3.2.x does not alllow the &lt;tt&gt;rsh&lt;/tt&gt; or &lt;tt&gt;telnet&lt;/tt&gt; services to be disabled.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;RuggedCom&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;10 Feb 2012&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;01 May 2012&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Siemens&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;-&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;01 May 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;8.5&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:N/AC:M/Au:S/C:C/I:C/A:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;7.3&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:POC/RL:W/RC:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;1.8&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:ND/TD:L/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://seclists.org/fulldisclosure/2012/Apr/277"&gt;http://seclists.org/fulldisclosure/2012/Apr/277&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01.pdf"&gt;http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01.pdf&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars"&gt;http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/"&gt;http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/products/index.php"&gt;http://www.ruggedcom.com/products/index.php&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/support/software/index.php"&gt;http://www.ruggedcom.com/support/software/index.php&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/261.html"&gt;http://cwe.mitre.org/data/definitions/261.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.ruggedcom.com/productbulletin/ros-security-page/"&gt;http://www.ruggedcom.com/productbulletin/ros-security-page/&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;Thanks to Justin W. Clarke, an independent security researcher in San Francisco, California, for reporting this vulnerability.&lt;/p&gt;
&lt;p&gt;This document was written by Michael Orlando and Art Manion.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1803"&gt;CVE-2012-1803&lt;/a&gt;&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;23 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;24 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;01 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;45&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23889195 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Up2u_lJ1ZFU" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/889195</guid>
         <pubDate>Tue, 24 Apr 2012 19:43:31 +0000</pubDate>
      </item>
      <item>
         <title>MS12-026 - Important : Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Information Disclosure (2663860) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-026</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-026</guid>
         <pubDate>Wed, 18 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (April 18, 2012): Corrected the bulletin replacement information for Microsoft Forefront Unified Access Gateway 2010 Service Pack 1. This is a bulletin change only. There were no changes to the detection or security update files.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Forefront Unified Access Gateway (UAG). The more severe of the vulnerabilities could allow information disclosure if an attacker sends a specially crafted query to the UAG server.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/MrN7PtTMTyM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-017 - Important : Vulnerability in DNS Server Could Allow Denial of Service (2647170) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-017</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-017</guid>
         <pubDate>Wed, 18 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (April 18, 2012): Added a link to Microsoft Knowledge Base Article 2647170 under Known Issues in the Executive Summary and corrected the bulletin replacement information for Windows Server 2003 Service Pack 2, Windows Server 2003 x64 Edition Service Pack 2, and Windows Server 2003 with SP2 for Itanium-based Systems. This is a bulletin change only. There were no changes to the detection.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a remote unauthenticated attacker sends a specially crafted DNS query to the target DNS server.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/44_DVL8ziIg" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-025 - Critical : Vulnerability in .NET Framework Could Allow Remote Code Execution (2671605) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-025</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-025</guid>
         <pubDate>Fri, 13 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.1 (April 13, 2012): Added a link to Microsoft Knowledge Base Article 2671605 under Known Issues<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. In a web browsing attack scenario, an attacker could host a website that contains a webpage that is used to exploit this vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these websites. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker's website.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/QjEAYW9d1e0" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-101B.html</link>
         <description>Original release date: April 10, 2012 | Last revised: --

Systems Affected

Adobe Reader X (10.1.2) and earlier 10.x versions for Windows and Macintosh
Adobe Reader 9.5 and earlier 9.x versions for Windows, Macintosh, and UNIX
Adobe Acrobat X (10.1.2) and earlier 10.x versions for Windows and Macintosh
Adobe Acrobat 9.5 and earlier 9.x versions for Windows and Macintosh


Overview
Adobe has released Security Bulletin APSB12-08, which describes multiple vulnerabilities affecting Adobe Reader and Acrobat. As part of this update, Adobe Reader and Acrobat 9.x will use the system-wide Flash Player browser plug-in instead of the Authplay component. In addition, Reader and Acrobat now disable the rendering of 3D content by default.

Description
Adobe Security Bulletin APSB12-08 describes a number of vulnerabilities affecting Adobe Reader and Acrobat. These vulnerabilities affect Adobe Reader and Acrobat versions 9.x through 9.5, and Reader X and Acrobat X versions prior to 10.1.3.
The Adobe ASSET blog provides additional details on new security architecture changes to Adobe Reader and Acrobat. Adobe Reader and Acrobat 9.5.1 will use the Adobe Flash Player plug-in version installed on the user’s system rather than the Authplay component that ships with Adobe Reader and Acrobat. This change helps limit the number of out-of-date, vulnerable Flash runtimes available to an attacker. Adobe Reader and Acrobat 9.5.1 also now disable rendering of 3D content by default because the 3D rendering components have a history of vulnerabilities.
US-CERT recommends that Flash users upgrade to the latest version of Adobe Flash Player and turn on automatic updates.
An attacker could exploit these vulnerabilities by convincing a user to open a specially crafted PDF file. This can happen automatically as the result of viewing a webpage.

Impact
These vulnerabilities could allow a remote attacker to execute arbitrary code, write arbitrary files or folders to the file system, escalate local privileges, or cause a denial of service on an affected system as the result of a user opening a malicious PDF file.

Solution
Update Reader
Adobe has released updates to address this issue. Users are encouraged to read Adobe Security Bulletin APSB12-08 and update vulnerable versions of Adobe Reader and Acrobat.
In addition to updating, please consider the following mitigations.
Disable JavaScript in Adobe Reader and Acrobat
Disabling JavaScript may prevent some exploits from resulting in code execution. You can disable Acrobat JavaScript using the Preferences menu (Edit -&amp;gt; Preferences -&amp;gt; JavaScript; uncheck Enable Acrobat JavaScript).
Adobe provides a framework to blacklist specific JavaScipt APIs. If JavaScript must be enabled, this framework may be useful when specific APIs are known to be vulnerable or used in attacks.

Prevent Internet Explorer from automatically opening PDF files

The installer for Adobe Reader and Acrobat configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to a safer option that prompts the user by importing the following as a .REG file:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT&amp;#92;AcroExch.Document.7]
"EditFlags"=hex:00,00,00,00
Disable the display of PDF files in the web browser

Preventing PDF files from opening inside a web browser will partially mitigate this vulnerability. Applying this workaround may also mitigate future vulnerabilities.

To prevent PDF files from automatically being opened in a web browser, do the following:

1. Open Adobe Acrobat Reader.
2. Open the Edit menu.
3. Choose the Preferences option.
4. Choose the Internet section.
5. Uncheck the "Display PDF in browser" checkbox.
Do not access PDF files from untrusted sources

Do not open unfamiliar or unexpected PDF files, particularly those hosted on websites or delivered as email attachments. Please see Cyber Security Tip ST04-010.

References

Security update available for Adobe Reader and Acrobat - 
Adobe Reader and Acrobat JavaScript Blacklist Framework - 
Background on Security Bulletin APSB12-08 - 
Adobe Flash Player - 
Adobe Flash vulnerability affects Flash Player and other Adobe products - 
Vulnerability Notes with advice to disable 3D rendering - 


Revision History

April 10, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/VMayqoGkYvU" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-101B.html</guid>
         <pubDate>Tue, 10 Apr 2012 22:02:05 +0000</pubDate>
      </item>
      <item>
         <title>TA12-101A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-101A.html</link>
         <description>Original release date: April 10, 2012 | Last revised: --

Systems Affected

Microsoft Windows
Microsoft Internet Explorer
Microsoft .NET Framework
Microsoft Office
Microsoft Server Software
Microsoft SQL Server
Microsoft Developer Tools
Microsoft Forefront United Access Gateway


Overview
There are multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Microsoft Server Software, Microsoft SQL Server, Microsoft Developer Tools, and Microsoft Forefront United Access Gateway.  Microsoft has released updates to address these vulnerabilities.

Description
The Microsoft Security Bulletin Summary for April 2012 describes multiple vulnerabilities in Microsoft software. Microsoft has released updates to address the vulnerabilities.

Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.

Solution
Apply updates

Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for April 2012, which describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. In addition, administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS). Home users are encouraged to enable automatic updates.

References

Microsoft Security Bulletin Summary for April 2012 - 
Microsoft Windows Server Update Services - 
Microsoft Update - 
Microsoft Update Overview - 
Turn Automatic Updating On or Off - 


Revision History

April 10, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/oId9pSu4gDM" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-101A.html</guid>
         <pubDate>Tue, 10 Apr 2012 18:37:12 +0000</pubDate>
      </item>
      <item>
         <title>VU#400619: Pluck SiteLife software multiple XSS vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/400619</link>
         <description>&lt;h1&gt;Vulnerability Note VU#400619&lt;/h1&gt;
		 &lt;h2&gt;Pluck SiteLife software multiple XSS vulnerabilities&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 10 Apr 2012 | Last revised: 12 Apr 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;Pluck SiteLife software contains multiple XSS vulnerabilities.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;According to DemandMedia's &lt;a rel="nofollow" target="_blank" href="http://www.pluck.com/products/"&gt;website&lt;/a&gt; Pluck SiteLife software is an integrated community platform architected for brands. Pluck SiteLife software contains multiple cross site scripting (XSS) vulnerabilities. 
&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/79.html"&gt;CWE-79&lt;/a&gt;: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')&lt;br&gt;

&lt;ul&gt;&lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://sitelife.example.host/ver1.0/Direct/Process?referrerURL=x&amp;jsonRequest="&gt;http://sitelife.example.host/ver1.0/Direct/Process?referrerURL=x&amp;amp;jsonRequest=&lt;/a&gt;&lt;/tt&gt;&lt;tt&gt;&amp;lt;body%20onload=alert(1)//&amp;gt;&lt;br&gt;
&lt;/tt&gt;&lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://sitelife.example.host/ver1.0/Direct/jsonp.htm?r="&gt;http://sitelife.example.host/ver1.0/Direct/jsonp.htm?r=&lt;/a&gt;&lt;/tt&gt;&lt;tt&gt;&amp;lt;img%20src=x%20onerror=alert(2)//&amp;gt;&amp;amp;cb=&amp;lt;body%20onload=alert(1)//&amp;gt;&lt;br&gt;
&lt;/tt&gt;&lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://sitelife.example.host/ver1.0/sys/jsonp.app/.htm?cb="&gt;http://sitelife.example.host/ver1.0/sys/jsonp.app/.htm?cb=&lt;/a&gt;&lt;/tt&gt;&lt;tt&gt;&amp;lt;img%20src=x%20onerror=alert(1)&amp;gt;&amp;amp;widget_path=pluck%2fuser%2fpersona%wffirstperson%2fprofile.app&lt;/tt&gt;&lt;br&gt;
&lt;/ul&gt;
It has also has been reported that the &lt;tt&gt;cv&lt;/tt&gt;, &lt;tt&gt;jsonRequest&lt;/tt&gt;, &lt;tt&gt;r&lt;/tt&gt; and &lt;tt&gt;ctk&lt;/tt&gt; parameter could be vulnerable in some instances. &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;An attacker with access to the Pluck SiteLife software can conduct a cross site scripting attack, which could be used to result in information leakage, privilege escalation, and/or denial of service.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Apply an Update&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Pluck has stated that all affected customers have already been notified via email in regards to the new release and changelog documentation is available for customers who login to the &lt;a rel="nofollow" target="_blank" href="http://connect.pluck.com/"&gt;Pluck Connect portal&lt;/a&gt;. Users are advised to upgrade to release 5.0.13 or later.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Restrict access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
As a general good security practice, only allow connections from trusted hosts and networks. Note that restricting access does not prevent XSS or CSRF attacks since the attack comes as an HTTP request from a legitimate user's host. Restricting access would prevent an attacker from accessing a Pluck SiteLife software using stolen credentials from a blocked network location.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Pluck&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;03 Jan 2012&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;12 Apr 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;6.0&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:N/AC:M/Au:S/C:P/I:P/A:P&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;5.0&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:F/RL:OF/RC:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;3.8&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:N/TD:M/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.demandmedia.com/solutions/pluck/"&gt;http://www.demandmedia.com/solutions/pluck/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.pluck.com/products/"&gt;http://www.pluck.com/products/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://connect.pluck.com/"&gt;http://connect.pluck.com/&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/79.html"&gt;http://cwe.mitre.org/data/definitions/79.html&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;Thanks to Phil Purviance for reporting this vulnerability.&lt;/p&gt;
&lt;p&gt;This document was written by Michael Orlando.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0253"&gt;CVE-2012-0253&lt;/a&gt;&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;10 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;10 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;12 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;21&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23400619 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Z_wZNpyV1Aw" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/400619</guid>
         <pubDate>Tue, 10 Apr 2012 15:21:12 +0000</pubDate>
      </item>
      <item>
         <title>MS12-024 - Critical : Vulnerability in Windows Could Allow Remote Code Execution (2653956) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-024</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-024</guid>
         <pubDate>Tue, 10 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (April 10, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user or application runs or installs a specially crafted, signed portable executable (PE) file on an affected system.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/PGb6ugAEQHE" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-023 - Critical : Cumulative Security Update for Internet Explorer (2675157) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-023</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-023</guid>
         <pubDate>Tue, 10 Apr 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (April 10, 2012): Bulletin published.<br />
          Summary: This security update resolves five privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/u-jrvQOHIvk" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>VU#232979: Multiple vulnerabilities in Intuit QuickBooks</title>
         <link>http://www.kb.cert.org/vuls/id/232979</link>
         <description>&lt;h1&gt;Vulnerability Note VU#232979&lt;/h1&gt;
		 &lt;h2&gt;Multiple vulnerabilities in Intuit QuickBooks&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 02 Apr 2012 | Last revised: 08 May 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;Intuit QuickBooks 2009 through 2012 have been reported to contain a file disclosure and heap corruption vulnerability.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Derek Soeder's vulnerability report states the following:
&lt;ul&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://www.securityfocus.com/archive/1/522139"&gt;&lt;b&gt;&lt;i&gt;Intuit Help System Protocol File Retrieval&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;br&gt;
&lt;i&gt;The vulnerability described in this document can be exploited by malicious HTML and Javascript to retrieve a file from a ZIP archive to which the user viewing the HTML has local or network file system access. The attacker must know or guess the path and file name of the target ZIP archive and the target file it contains. A further significant limitation is that files in subdirectories inside of ZIP archives have proven inaccessible, based on a sampling of Windows ZIPs, Microsoft Office 2007 documents, JARs, and APKs.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
&lt;a rel="nofollow" target="_blank" href="http://www.securityfocus.com/archive/1/522138"&gt;&lt;b&gt;&lt;i&gt;Intuit Help System Protocol URL Heap Corruption and Memory Leak&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;br&gt;
&lt;i&gt;The vulnerability described in this document can potentially be exploited by malicious HTML and/or Javascript to execute arbitrary code as the user viewing the malicious content.&lt;/i&gt;&lt;br&gt;
&lt;/ul&gt;
Additional details may be found in the full advisories linked above.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;An attacker may be able to retrieve sensitive files or run arbitrary code.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;We are currently unaware of a practical solution to this problem.  Please consider the following workaround.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Disable the Intuit Help System protocol&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Delete, rename, or restrict read access to the registry key:&lt;br&gt;

&lt;ul&gt;&lt;tt&gt;HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;[Wow6432Node]&amp;#92;Classes&amp;#92;PROTOCOLS&amp;#92;Handler&amp;#92;intu-help-qb#&lt;/tt&gt;&lt;/ul&gt;
&lt;br&gt;
Where '#' is a digit from 1 to 5, or delete, rename, or restrict execute access to the &amp;quot;HelpAsyncPluggableProtocol.dll&amp;quot; file in the QuickBooks installation directory, and then restart Internet Explorer and any application that uses it as an embedded Web browser. Note that disabling the protocol will prevent QuickBooks from displaying help pages.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Intuit, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;23 Mar 2012&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;08 May 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;5.0&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:A/AC:--/Au:N/C:C/I:C/A:P&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;3.6&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:U/RL:W/RC:UC&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;3.6&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.securityfocus.com/archive/1/522138"&gt;http://www.securityfocus.com/archive/1/522138&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.securityfocus.com/archive/1/522139"&gt;http://www.securityfocus.com/archive/1/522139&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;Thanks to Derek Soeder for reporting this vulnerability.&lt;/p&gt;
&lt;p&gt;This document was written by Jared Allar.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;Unknown&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;30 Mar 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;02 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;08 May 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;12&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23232979 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/98sujXS9y7c" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/232979</guid>
         <pubDate>Mon, 02 Apr 2012 18:59:56 +0000</pubDate>
      </item>
      <item>
         <title>VU#928795: Netgear FVS318N router default remote management vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/928795</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/PLugk458fiU" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/928795</guid>
         <pubDate>Mon, 02 Apr 2012 15:42:13 +0000</pubDate>
      </item>
      <item>
         <title>VU#834723: TP-Link 8840T DSL router default remote management vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/834723</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/n3J9oIq8ptM" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/834723</guid>
         <pubDate>Mon, 02 Apr 2012 14:12:13 +0000</pubDate>
      </item>
      <item>
         <title>VU#551715: Quagga contains multiple vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/551715</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/dmnWSIMIlXk" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/551715</guid>
         <pubDate>Fri, 23 Mar 2012 12:10:13 +0000</pubDate>
      </item>
      <item>
         <title>Zend Server Multiple HTML Injection Vulnerabilities</title>
         <link>http://www.net-security.org/vuln.php?id=16279</link>
         <guid isPermaLink="false" />
         <pubDate>Fri, 23 Mar 2012 07:08:47 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/PzVYqNY_fyw" height="1" width="1"/&gt;</description></item>
      <item>
         <title>EJBCA "issuer" Parameter Cross-Site Scripting</title>
         <link>http://www.net-security.org/vuln.php?id=16278</link>
         <guid isPermaLink="false" />
         <pubDate>Fri, 23 Mar 2012 07:08:32 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/7Un0_IBwL0o" height="1" width="1"/&gt;</description></item>
      <item>
         <title>OpenLDAP LDAP Search Request Remote Denial of Service</title>
         <link>http://www.net-security.org/vuln.php?id=16277</link>
         <guid isPermaLink="false" />
         <pubDate>Fri, 23 Mar 2012 07:08:17 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/ykbqM5hQPEI" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Vegas Movie Studio HD "CFHDDecoder.dll" DLL Loading Arbitrary Code Execution</title>
         <link>http://www.net-security.org/vuln.php?id=16276</link>
         <guid isPermaLink="false" />
         <pubDate>Fri, 23 Mar 2012 07:08:00 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/kWljF3PH2wM" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Microsoft Expression "wintab32.dll" DLL Loading Arbitrary Code Execution</title>
         <link>http://www.net-security.org/vuln.php?id=16275</link>
         <guid isPermaLink="false" />
         <pubDate>Fri, 23 Mar 2012 07:07:38 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/VjBsmTJXDKg" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Jenkins Multiple Cross-Site Scripting and Directory Traversal Vulnerabilities</title>
         <link>http://www.net-security.org/vuln.php?id=16274</link>
         <guid isPermaLink="false" />
         <pubDate>Thu, 22 Mar 2012 13:19:48 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/5OvK1iEyI-4" height="1" width="1"/&gt;</description></item>
      <item>
         <title>SquirrelMail Autocomplete Plugin Email Addresses Cross-Site Scripting</title>
         <link>http://www.net-security.org/vuln.php?id=16273</link>
         <guid isPermaLink="false" />
         <pubDate>Thu, 22 Mar 2012 13:19:35 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/jVgmMIRx35w" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Google Chrome Remote Code Execution</title>
         <link>http://www.net-security.org/vuln.php?id=16272</link>
         <guid isPermaLink="false" />
         <pubDate>Thu, 22 Mar 2012 13:19:23 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/OXBiQTr2994" height="1" width="1"/&gt;</description></item>
      <item>
         <title>XnView Multiple Buffer Overflow Vulnerabilities</title>
         <link>http://www.net-security.org/vuln.php?id=16271</link>
         <guid isPermaLink="false" />
         <pubDate>Thu, 22 Mar 2012 13:19:10 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/7bwRyM1NPHM" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Microsoft Windows "DirectWrite" API Denial of Service</title>
         <link>http://www.net-security.org/vuln.php?id=16270</link>
         <guid isPermaLink="false" />
         <pubDate>Thu, 22 Mar 2012 13:18:52 +0000</pubDate>
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/NySUw5LEFWk" height="1" width="1"/&gt;</description></item>
      <item>
         <title>VU#743555: @Mail Open webmail client contains multiple vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/743555</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/tvLq6O-id_8" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/743555</guid>
         <pubDate>Thu, 22 Mar 2012 12:40:14 +0000</pubDate>
      </item>
      <item>
         <title>VU#523027: LG-Nortel ELO GS24M Switch contains multiple vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/523027</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/JfCItBNRF4E" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/523027</guid>
         <pubDate>Wed, 21 Mar 2012 12:40:14 +0000</pubDate>
      </item>
      <item>
         <title>VU#364363: WebGlimpse command injection vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/364363</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/mFRyXJBHIa0" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/364363</guid>
         <pubDate>Tue, 20 Mar 2012 20:35:13 +0000</pubDate>
      </item>
      <item>
         <title>VU#212651: InspIRCd heap corruption vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/212651</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/kPb3_AdQOeQ" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/212651</guid>
         <pubDate>Mon, 19 Mar 2012 20:33:49 +0000</pubDate>
      </item>
      <item>
         <title>VU#913483: Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries web interface and preconfigured password vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/913483</link>
         <description>&lt;h1&gt;Vulnerability Note VU#913483&lt;/h1&gt;
		 &lt;h2&gt;Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries web interface and preconfigured password vulnerabilities&lt;/h2&gt;
		 &lt;p class="meta-text"&gt;Original Release date: 19 Mar 2012 | Last revised: 13 Apr 2012&lt;/p&gt;

	 &lt;div id="vulnerability-note-content"&gt;
		 &lt;a rel="nofollow" name="overview"&gt;&lt;/a&gt;
		 &lt;h3&gt;Overview&lt;/h3&gt;
		&lt;p&gt;Cross scripting and preconfigured password vulnerabilities have been reported to exist in the Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries.&lt;/p&gt;
		 &lt;a rel="nofollow" name="description"&gt;&lt;/a&gt;
		 &lt;h3&gt;Description&lt;/h3&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Quantum Scalar i500, Dell ML6000 and IBM TS3310 enterprise tape libraries contain multiple web interface and preconfigured account password vulnerabilities. 
&lt;p&gt;The Quantum Scalar i500 and Dell ML6000 tape libraries contain the following web interface vulnerabilities.&lt;br&gt;

&lt;ul type="disc"&gt;
&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/552.html"&gt;CWE-552: Files or Directories Accessible to External Parties&lt;/a&gt;&lt;br&gt;
The web interface allows an unauthenticated remote user to view any file on the web server, for example &lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://device/logShow.htm?file=/etc/shadow"&gt;http://device/logShow.htm?file=/etc/shadow&lt;/a&gt;&lt;/tt&gt; (CVE-2012-1841).&lt;br&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/200.html"&gt;CWE-200: Information Exposure&lt;/a&gt;&lt;br&gt;
A cross-site scripting vulnerability in &lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://device/checkQKMProg.htm"&gt;http://device/checkQKMProg.htm&lt;/a&gt;&lt;/tt&gt; allows compromise of active session ids (CVE-2012-1842).&lt;br&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/352.html"&gt;CWE-352: Cross-Site Request Forgery (CSRF)&lt;/a&gt;&lt;br&gt;
A command-injection vulnerability in &lt;tt&gt;&lt;a rel="nofollow" target="_blank" href="http://device/saveRestore.htm"&gt;http://device/saveRestore.htm&lt;/a&gt;&lt;/tt&gt; (via the &lt;tt&gt;fileName&lt;/tt&gt; POST parameter) allows execution of arbitrary commands as the root user, by an authenticated remote web user (CVE-2012-1843).&lt;/ul&gt;

&lt;ul type="disc"&gt;
&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/259.html"&gt;CWE-259: Use of Hard-coded Password&lt;/a&gt;&lt;br&gt;
The Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries also contain preconfigured passwords for certain accounts which are considered to be weak and could be exploited allowing an attacker user access (CVE-2012-1844).&lt;/ul&gt;
&lt;br&gt;
The CVSS metrics below apply to &lt;a rel="nofollow" target="_blank" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1844"&gt;&lt;u&gt;&lt;font color="#0000FF"&gt;CVE-2012-1844&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="impact"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Impact&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;An attacker with access to a local user account or via malicious URL can execute arbitrary code or commands on the vulnerable system.  It has been reported to us that customer data residing on the tapes within the libraries are not affected.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
 		 &lt;a rel="nofollow" name="solution"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Solution&lt;/h3&gt;
 		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Upgrade firmware&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Quantum has released a firmware update &lt;a rel="nofollow" target="_blank" href="http://www.quantum.com/ServiceandSupport/SoftwareandDocumentationDownloads/SI500/Index.aspx"&gt;i7.0.3 (604G.GS00100&lt;/a&gt;) or greater will correct these issues.&lt;br&gt;
&lt;br&gt;
Dell firmware update &lt;a rel="nofollow" target="_blank" href="http://support.dell.com/"&gt;A20-00 (590G.GS00100)&lt;/a&gt; or greater will correct these issues.&lt;br&gt;
&lt;br&gt;
IBM firmware update &lt;a rel="nofollow" target="_blank" href="http://www-933.ibm.com/support/fixcentral/"&gt;R6C (606G.GS001)&lt;/a&gt; or greater will correct these issues.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
		 &lt;table cellspacing="0" cellpadding="0" border="0" class="wrapper-table" style="padding-top:15px;"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Restrict access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
As a general good security practice, only allow connections from trusted hosts and networks. Note that restricting access does not prevent XSS or CSRF attacks since the attack comes as an HTTP request from a legitimate user's host. Restricting access would prevent an attacker from accessing a Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries using stolen credentials from a blocked network location.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

		 &lt;a rel="nofollow" name="vendors"&gt;&lt;/a&gt;&lt;a rel="nofollow" name="systems"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Vendor Information&lt;/h3&gt;


&lt;table id="vendor-info2" style="margin:10px 0 10px 0;"&gt;&lt;tr&gt;&lt;th style="width:250px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Vendor&lt;/th&gt;&lt;th style="width:110px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Status&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Date Notified&lt;/th&gt;&lt;th style="width:125px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;margin:0;"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Dell Computer Corporation, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;16 Nov 2011&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;13 Apr 2012&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;23 Nov 2011&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;13 Apr 2012&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="vendor" style="width:250px;text-align:left;padding:5px 10px;margin:0;"&gt;&lt;a rel="nofollow" title="View Vendor Information"&gt;Quantum&lt;/a&gt;&lt;/td&gt;&lt;td class="status" style="width:110px;text-align:center;padding:5px 10px;margin:0;"&gt;Affected&lt;/td&gt;&lt;td class="notified" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;23 Nov 2011&lt;/td&gt;&lt;td class="updated" style="width:125px;text-align:center;padding:5px 10px;margin:0;"&gt;13 Apr 2012&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;a rel="nofollow" name="cvss"&gt;&lt;/a&gt;
&lt;h3&gt;CVSS Metrics &lt;span class="learn-more"&gt;(&lt;a rel="nofollow"&gt;Learn More&lt;/a&gt;)&lt;/span&gt;&lt;/h3&gt;

&lt;table id="cvss-score" style="margin:10px 0 10px 0;"&gt;
   &lt;tr&gt;
      &lt;th style="width:100px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-right:none;padding:5px 10px;margin:0;"&gt;Group&lt;/th&gt;
      &lt;th style="width:100px;text-align:center;padding:5px 10px;background-color:#EBEBEB;border-top:1px solid #d5d7da;border-bottom:1px solid #d5d7da;margin:0;"&gt;Score&lt;/th&gt;
      &lt;th style="width:470px;text-align:left;background-color:#EBEBEB;border:1px solid #d5d7da;border-left:none;padding:5px 10px;margin:0;"&gt;Vector&lt;/th&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Base&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;text-align:center;padding:5px 10px;"&gt;6.8&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;AV:N/AC:M/Au:N/C:P/I:P/A:P&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Temporal&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;5.3&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;E:POC/RL:OF/RC:C&lt;/td&gt;
   &lt;/tr&gt;
   &lt;tr&gt;
      &lt;td class="cvss-metric-group" style="width:100px;text-align:left;padding:5px 10px;margin:0;"&gt;Environmental&lt;/td&gt;
      &lt;td class="cvss-score" style="width:100px;padding:5px 10px;text-align:center;"&gt;5.3&lt;/td&gt;
      &lt;td class="cvss-vector" style="width:470px;text-align:left;padding:5px 10px;margin:0;"&gt;CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND&lt;/td&gt;
   &lt;/tr&gt;
&lt;/table&gt;

 		 &lt;a rel="nofollow" name="references"&gt;&lt;/a&gt;
 		 &lt;h3&gt;References&lt;/h3&gt;

 		 &lt;ul&gt;

&lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/552.html"&gt;http://cwe.mitre.org/data/definitions/552.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/200.html"&gt;http://cwe.mitre.org/data/definitions/200.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/352.html"&gt;http://cwe.mitre.org/data/definitions/352.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://cwe.mitre.org/data/definitions/259.html"&gt;http://cwe.mitre.org/data/definitions/259.html&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www.quantum.com/ServiceandSupport/SoftwareandDocumentationDownloads/SI500/Index.aspx"&gt;http://www.quantum.com/ServiceandSupport/SoftwareandDocumentationDownloads/SI500/Index.aspx&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://support.dell.com"&gt;http://support.dell.com&lt;/a&gt;&lt;/li&gt;
 &lt;li&gt;&lt;a rel="nofollow" target="_blank" href="http://www-933.ibm.com/support/fixcentral/"&gt;http://www-933.ibm.com/support/fixcentral/&lt;/a&gt;&lt;/li&gt;


		&lt;/ul&gt;

 		 &lt;a rel="nofollow" name="credit"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Credit&lt;/h3&gt;

&lt;p&gt;Thanks to NOAA CIRT for reporting this vulnerability.&lt;/p&gt;
&lt;p&gt;This document was written by Michael Orlando.&lt;/p&gt;
 		 &lt;a rel="nofollow" name="other"&gt;&lt;/a&gt;
 		 &lt;h3&gt;Other Information&lt;/h3&gt;
 		 &lt;ul id="other-info"&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;CVE IDs:&lt;/span&gt;
 		 		 &lt;span&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1844"&gt;CVE-2012-1844&lt;/a&gt;
&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1843"&gt;CVE-2012-1843&lt;/a&gt;
&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1842"&gt;CVE-2012-1842&lt;/a&gt;
&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1841"&gt;CVE-2012-1841&lt;/a&gt;&lt;/span&gt;
	 		 &lt;/li&gt;




	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Public:&lt;/span&gt;
 		 		 &lt;span&gt;19 Mar 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date First Published:&lt;/span&gt;
 		 		 &lt;span&gt;19 Mar 2012&lt;/span&gt;
	 		 &lt;/li&gt;
	 		 &lt;li&gt;
 		 		 &lt;span class="field-title"&gt;Date Last Updated:&lt;/span&gt;
 		 		 &lt;span&gt;13 Apr 2012&lt;/span&gt;
	 		 &lt;/li&gt;
 
 
	 		 &lt;li&gt;
		 		 &lt;span class="field-title"&gt;Document Revision:&lt;/span&gt;
 		 		 &lt;span&gt;41&lt;/span&gt;
	 		 &lt;/li&gt;
 		 &lt;/ul&gt;
&lt;div id="provide-feedback"&gt;
 &lt;h3&gt;Feedback&lt;/h3&gt;&lt;p&gt;If you have feedback, comments, or additional information about this vulnerability, please send us &lt;a rel="nofollow" target="_blank" href="mailto:cert@cert.org?Subject=VU%23913483 Feedback"&gt;email&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
	 &lt;/div&gt;
&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/RhbmQq-N9uc" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/913483</guid>
         <pubDate>Mon, 19 Mar 2012 19:00:12 +0000</pubDate>
      </item>
      <item>
         <title>VU#624051: Microsoft Remote Desktop Protocol (RDP) insecurely deallocates memory</title>
         <link>http://www.kb.cert.org/vuls/id/624051</link>
         <description>&amp;nbsp;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Y_LX9CfR3og" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/624051</guid>
         <pubDate>Thu, 15 Mar 2012 19:05:13 +0000</pubDate>
      </item>
      <item>
         <title>VU#339177: Cisco AnyConnect Clientless SSL VPN Portforwarder ActiveX control buffer overflow</title>
         <link>http://www.kb.cert.org/vuls/id/339177</link>
         <description>&lt;h1&gt;Vulnerability Note VU#339177&lt;/h1&gt;
&lt;h2&gt;Cisco AnyConnect Clientless SSL VPN Portforwarder ActiveX control buffer overflow&lt;/h2&gt;
&lt;a rel="nofollow" NAME="overview"&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Cisco AnyConnect ActiveX control contains a buffer overflow vulnerability, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
&lt;a rel="nofollow" NAME="description"&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Cisco AnyConnect is an SSL VPN solution that is commonly initiated through use of a web browser. When Internet Explorer is used, the AnyConnect VPN server provides an ActiveX control that downloads and installs the AnyConnect client software. One of the components provided by Cisco AnyConnect for use with Internet Explorer is an ActiveX control called the &amp;quot;CISCO Portforwarder Control.&amp;quot; This ActiveX control is provided by the file &lt;tt&gt;ciscopf.ocx&lt;/tt&gt;. The Cisco Portforwarder ActiveX control contains a buffer overflow in its initialization parameters. We have confirmed that version 1.0.1.8 of the Portforwarder control is vulnerable. Previous versions may also be affected.&lt;a rel="nofollow" NAME="impact"&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code. &lt;a rel="nofollow" NAME="solution"&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in Cisco Security Advisory&lt;a rel="nofollow" target="_blank" href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asaclient"&gt; cisco-sa-20120314-asaclient&lt;/a&gt;. Please note that updating a Cisco ASA device with the fixed software will not protect systems that have already downloaded the vulnerable control. Please also consider the following workarounds:&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable the Cisco AnyConnect Portforwarder ActiveX control in Internet Explorer&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The vulnerable Cisco AnyConnect Portforwarder ActiveX control can be disabled in Internet Explorer by setting the kill bit for the following CLSID:&lt;br&gt;
 
&lt;ul&gt;&lt;tt&gt;{B8E73359-3422-4384-8D27-4EA1B4C01232}&lt;/tt&gt;&lt;/ul&gt;
More information about how to set the kill bit is available in &lt;a rel="nofollow" target="_blank" href="http://support.microsoft.com/kb/240797"&gt;&lt;font color="#0000FF"&gt;Microsoft Support Document 240797&lt;/font&gt;&lt;/a&gt;.  Alternatively, the following text can be saved as a &lt;tt&gt;.REG&lt;/tt&gt; file and imported to set the kill bit for this control:&lt;br&gt;

&lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;&lt;/tt&gt;&lt;tt&gt;{B8E73359-3422-4384-8D27-4EA1B4C01232}&lt;/tt&gt;&lt;tt&gt;]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&amp;quot;Compatibility Flags&amp;quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Wow6432Node&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;&lt;/tt&gt;&lt;tt&gt;{B8E73359-3422-4384-8D27-4EA1B4C01232}&lt;/tt&gt;&lt;tt&gt;]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&amp;quot;Compatibility Flags&amp;quot;=dword:00000400&lt;/tt&gt;&lt;/ul&gt;

&lt;a rel="nofollow" NAME="systems"&gt;&lt;a rel="nofollow" NAME="vendors"&gt;&lt;h3&gt;Vendor Information&lt;/h3&gt;&lt;/a&gt;&lt;/a&gt;

&lt;table&gt;
&lt;tr&gt;&lt;th ALIGN="LEFT"&gt;Vendor&lt;/th&gt;&lt;th ALIGN="LEFT"&gt;Status&lt;/th&gt;&lt;th ALIGN="LEFT"&gt;Date Notified&lt;/th&gt;&lt;th ALIGN="LEFT"&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel="nofollow"&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Affected&lt;/td&gt;&lt;td&gt;2011-06-16&lt;/td&gt;&lt;td&gt;2012-03-14&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;

&lt;a rel="nofollow" NAME="references"&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_blank" href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asaclient"&gt;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asaclient&lt;/a&gt;&lt;br&gt;
&lt;a rel="nofollow" target="_blank" href="http://www.cisco.com/en/US/products/ps8411/tsd_products_support_series_home.html"&gt;http://www.cisco.com/en/US/products/ps8411/tsd_products_support_series_home.html&lt;/a&gt;&lt;br&gt;
&lt;a rel="nofollow" target="_blank" href="http://support.microsoft.com/kb/240797"&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;&lt;br&gt;
&lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/reading_room/securing_browser/"&gt;http://www.us-cert.gov/reading_room/securing_browser/&lt;/a&gt;

&lt;a rel="nofollow" NAME="credit"&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by Will Dormann of the CERT/CC
&lt;p&gt;This document was written by Will Dormann.

&lt;a rel="nofollow" NAME="other"&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt;

&lt;table&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;Date Public:&lt;/td&gt;&lt;td&gt;2012-03-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2012-03-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2012-03-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel="nofollow" target="_blank" HREF="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0358"&gt;CVE-2012-0358&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel="nofollow" target="_blank" HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0358"&gt;CVE-2012-0358&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;Severity Metric:&lt;/td&gt;&lt;td&gt;&lt;a rel="nofollow"&gt;11.03&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN="LEFT"&gt;Document Revision:&lt;/td&gt;&lt;td&gt;18&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p class="disclaimer"&gt;&lt;hr /&gt;

This product is provided subject to the Notification as indicated here: &lt;a rel="nofollow" target="_blank" href="http://www.us-cert.gov/legal.html#notify"&gt; http://www.us-cert.gov/legal.html#notify&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/pIPlWwS9XCQ" height="1" width="1"/&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/339177</guid>
         <pubDate>Wed, 14 Mar 2012 18:17:27 +0000</pubDate>
      </item>
      <item>
         <title>MS12-022 - Important : Vulnerability in Expression Design Could Allow Remote Code Execution (2651018) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-022</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-022</guid>
         <pubDate>Wed, 14 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (March 14, 2012): Removed erroneous installation switch option descriptions from the Security Update Deployment tables for all supported releases. This is an informational change only. There were no changes to the detection logic or the update files.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Expression Design. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .xpr or .DESIGN file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Microsoft Expression Design could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .xpr or .DESIGN file) from this location that is then loaded by a vulnerable application.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Ksuu5xX-dSA" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-073A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-073A.html</link>
         <description>Original release date: March 13, 2012
Last revised: --
Source: US-CERT


Systems Affected
Microsoft WindowsMicrosoft Visual StudioMicrosoft
Expression Design



Overview
There are multiple vulnerabilities in Microsoft Windows, Microsoft Visual
Studio, and Microsoft Expression Design. Microsoft has released updates to
address these vulnerabilities.



I. Description
The Microsoft
Security Bulletin Summary for March 2012 describes multiple vulnerabilities
in Microsoft Windows, Microsoft Visual Studio, and Microsoft Expression Design.
Microsoft has released updates to address the vulnerabilities.



II. Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a
denial of service, or gain unauthorized access to your files or system.



III. Solution
Apply updatesMicrosoft has provided updates for
these vulnerabilities in the Microsoft
Security Bulletin Summary for March 2012, which describes any known issues
related to the updates. Administrators are encouraged to note these issues and
test for any potentially adverse effects. In addition, administrators should
consider using an automated update distribution system such as Windows Server
Update Services (WSUS). Home users are encouraged to enable automatic
updates.



IV. References
Microsoft Security Bulletin Summary for March 2012 - Microsoft
Windows Server Update Services - Microsoft
Update - Microsoft
Update Overview - Turn
Automatic Updating On or Off - 

   


                               
Feedback can be directed to US-CERT.


Produced 2012 by US-CERT, a government organization. Terms of use

Revision History
March 13, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/YxlkoOx2GmM" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-073A.html</guid>
         <pubDate>Tue, 13 Mar 2012 18:34:31 +0000</pubDate>
      </item>
      <item>
         <title>MS12-021 - Important : Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-021</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-021</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (March 13, 2012): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in Visual Studio. The vulnerability could allow elevation of privilege if an attacker places a specially crafted add-in in the path used by Visual Studio and convinces a user with higher privileges to start Visual Studio. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/tOMrBlONmGM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-020</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-020</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (March 13, 2012): Bulletin published.<br />
          Summary: This security update resolves two privately reported vulnerabilities in the Remote Desktop Protocol. The more severe of these vulnerabilities could allow remote code execution if an attacker sends a sequence of specially crafted RDP packets to an affected system. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system. Systems that do not have RDP enabled are not at risk.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/2irK9bpekj8" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-019 - Moderate : Vulnerability in DirectWrite Could Allow Denial of Service (2665364) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-019</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-019</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Moderate<br />
            Revision Note: V1.0 (March 13, 2012): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Windows DirectWrite. In an Instant Messenger-based attack scenario, the vulnerability could allow denial of service if an attacker sends a specially crafted sequence of Unicode characters directly to an Instant Messenger client. The target application could become unresponsive when DirectWrite renders the specially crafted sequence of Unicode characters.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/vg3VKpHDQKc" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-018 - Important : Vulnerability in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2641653) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-018</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-018</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (March 13, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/zCt0R9yryKA" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-067 - Important : Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-067</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-067</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (March 13, 2012): Added an entry to the update FAQ to announce a detection change for KB2548826 to correct an installation issue. This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Report Viewer. The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/95YjBt1pKxE" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-030 - Critical : Vulnerability in DNS Resolution Could Allow Remote Code Execution (2509553) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-030</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-030</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.1 (March 13, 2012): Added a link to Microsoft Knowledge Base Article 2509553 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows DNS resolution. The vulnerability could allow remote code execution if an attacker gained access to the network and then created a custom program to send specially crafted LLMNR broadcast queries to the target systems. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the LLMNR ports should be blocked from the Internet.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/sOUnqF2s7R4" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-025 - Important : Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212) - Version: 4.3</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-025</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-025</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V4.3 (March 13, 2012): Added an entry to the update FAQ to announce a detection change for KB2565063 and KB2565057 to correct an installation issue. This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in certain applications built using the Microsoft Foundation Class (MFC) Library. The vulnerability could allow remote code execution if a user opens a legitimate file associated with such an affected application, and the file is located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by the affected application.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/vIbVBsMNemk" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS10-058 - Important : Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886) - Version: 2.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms10-058</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms10-058</guid>
         <pubDate>Tue, 13 Mar 2012 07:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V2.0 (March 13, 2012): Revised bulletin to announce a detection change that removes MS10-029 as the replaced bulletin for all supported editions of Windows Vista and Windows Server 2008. For more information, see the related entry in the update FAQ.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege due to an error in the processing of a specific input buffer. An attacker who is able to log on to the target system could exploit this vulnerability and run arbitrary code with system-level privileges. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/M-aaP3HARns" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-014 - Important : Vulnerability in Indeo Codec Could Allow Remote Code Execution (2661637) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-014</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-014</guid>
         <pubDate>Wed, 22 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (February 22, 2012): Added a link to Microsoft Knowledge Base Article 2661637 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .avi file) that is located in the same directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could run arbitrary code as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/IE5i42qs2lo" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-001 - Important : Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-001</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-001</guid>
         <pubDate>Wed, 22 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (February 22, 2012): Added a link to Microsoft Knowledge Base Article 2644615 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/N92MqOGO8aM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-089 - Important : Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602) - Version: 1.2</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-089</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-089</guid>
         <pubDate>Wed, 22 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.2 (February 22, 2012): Revised the bulletin to identify the update package KB numbers for the following non-affected software that this update applies to: Microsoft Visio (KB2553374), Microsoft Visio Viewer (KB2553353), Microsoft Office Web Application Companions (WAC) (KB2553153), and Microsoft SharePoint Server 2010 (KB2553132). See the update FAQ for details.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/G8zYlEjsxzc" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-088 - Important : Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Privilege (2652016) - Version: 1.2</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-088</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-088</guid>
         <pubDate>Wed, 22 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.2 (February 22, 2012): Clarified product support status for Microsoft Office Pinyin SimpleFast Style 2010 and Microsoft Office Pinyin New Experience Style 2010. These versions of Microsoft Office Pinyin are no longer supported. Microsoft recommends that all customers of these versions upgrade to the latest version of Microsoft Pinyin IME 2010 available through Microsoft Office 2010. See update FAQ for details.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user performed specific actions on a system where an affected version of the Microsoft Pinyin (MSPY) Input Method Editor (IME) for Simplified Chinese is installed. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights. Only implementations of Microsoft Pinyin IME 2010 are affected by this vulnerability. Other versions of Simplified Chinese IME and other implementations of IME are not affected.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/_r9zg4HwdRk" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-016 - Critical : Vulnerabilities in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2651026) - Version: 1.2</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-016</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-016</guid>
         <pubDate>Wed, 15 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.2 (February 15, 2012): Removed erroneous reference to known issues from the Executive Summary.<br />
          Summary: This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted web page using a web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/_70H7wIc6E0" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-049 - Important : Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893) - Version: 2.4</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-049</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-049</guid>
         <pubDate>Wed, 15 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V2.4 (February 15, 2012): Corrected the SQL Server Version Range for SQL Server 2008 R2 in the update FAQ.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft XML Editor. The vulnerability could allow information disclosure if a user opened a specially crafted Web Service Discovery (.disco) file with one of the affected software listed in this bulletin. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/M5bHM881RtA" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-045A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-045A.html</link>
         <description>Original release date: February 14, 2012
Last revised: --
Source: US-CERT


Systems Affected
Microsoft WindowsMicrosoft Internet ExplorerMicrosoft
.NET FrameworkMicrosoft SilverlightMicrosoft
OfficeMicrosoft Server Software



Overview
There are multiple vulnerabilities in Microsoft Windows, Internet Explorer,
Microsoft .NET Framework, Silverlight, Office, and Microsoft Server Software.
Microsoft has released updates to address these vulnerabilities.



I. Description
The Microsoft
Security Bulletin Summary for February 2012 describes multiple
vulnerabilities in Microsoft Windows. Microsoft has released updates to address
the vulnerabilities.



II. Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a
denial of service, or gain unauthorized access to your files or system.



III. Solution
Apply updatesMicrosoft has provided updates for
these vulnerabilities in the Microsoft
Security Bulletin Summary for February 2012, which describes any known
issues related to the updates. Administrators are encouraged to note these
issues and test for any potentially adverse effects. In addition, administrators
should consider using an automated update distribution system such as Windows Server
Update Services (WSUS). Home users are encouraged to enable automatic
updates.



IV. References
Microsoft Security Bulletin Summary for February 2012 - Microsoft
Windows Server Update Services - Microsoft
Update - Microsoft
Update Overview - Turn
Automatic Updating On or Off - 

   


                               
Feedback can be directed to US-CERT.


Produced 2012 by US-CERT, a government organization. Terms of use

Revision History
February 14, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/WCfchtYIpik" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-045A.html</guid>
         <pubDate>Tue, 14 Feb 2012 18:37:26 +0000</pubDate>
      </item>
      <item>
         <title>MS12-015 - Important : Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2663510) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-015</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-015</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/BuBGG6fc_2s" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-013 - Critical : Vulnerability in C Run-Time Library Could Allow Remote Code Execution (2654428) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-013</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-013</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted media file that is hosted on a website or sent as an email attachment. An attacker who successfully exploited the vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/sYhJXJHdAuA" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-012 - Important : Vulnerability in Color Control Panel Could Allow Remote Code Execution (2643719) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-012</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-012</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .icm or .icc file) that is located in the same directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/GRcDpyjOatM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-011 - Important : Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2663841) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-011</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-011</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves three privately reported vulnerabilities in Microsoft SharePoint and Microsoft SharePoint Foundation. These vulnerabilities could allow elevation of privilege or information disclosure if a user clicked a specially crafted URL.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/g1mSeg5ZbTw" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-010 - Critical : Cumulative Security Update for Internet Explorer (2647516) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-010</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-010</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/kFCCrYGsX28" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-009 - Important : Vulnerabilities in Ancillary Function Driver Could Allow Elevation of Privilege (2645640) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-009</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-009</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/1EPg09iXNeQ" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-008 - Critical : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2660465) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-008</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-008</guid>
         <pubDate>Tue, 14 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.0 (February 14, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow remote code execution if a user visits a website containing specially crafted content or if a specially crafted application is run locally. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/2jRAA7LDTCM" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-098 - Important : Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-098</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-098</guid>
         <pubDate>Wed, 01 Feb 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (February 1, 2012): Added a link to Microsoft Knowledge Base Article 2633171 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/vcoNhUyWiqk" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-004 - Critical : Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) - Version: 1.2</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-004</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-004</guid>
         <pubDate>Fri, 27 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Critical<br />
            Revision Note: V1.2 (January 27, 2012): Corrected the aggregate severity rating for the KB2631813 update package in the Affected Software table for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This is a bulletin change only. There were no changes to the security update files or detection logic. Customers should apply all update packages offered for the software installed on their systems. See the update FAQ for details.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/EVU_02rObT4" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-024A: "Anonymous" DDoS Activity</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-024A.html</link>
         <description>Original release date: January 24, 2012
Last revised: --
Source: US-CERT



Overview
US-CERT has received information from multiple sources about coordinated
distributed denial-of-service (DDoS) attacks with targets that included
U.S. government agency and entertainment industry websites. The loosely
affiliated collective "Anonymous" allegedly promoted the attacks in
response to the shutdown of the file hosting site MegaUpload and in protest of
proposed U.S. legislation concerning online trafficking in rightsed
intellectual property and counterfeit goods (Stop Online Piracy Act, or SOPA,
and Preventing Real Online Threats to Economic Creativity and Theft of
Intellectual Property Act, or PIPA).



I. Description
US-CERT has evidence of two types of DDoS attacks: One using HTTP GET
requests and another using a simple UDP flood.The Low Orbit Ion Cannon
(LOIC) is a denial-of-service attack tool associated with previous Anonymous
activity. US-CERT has reviewed at least two implementations of LOIC. One variant
is written in JavaScript and is designed to be used from a web browser. An
attacker can access this variant of LOIC on a website and select targets,
specify an optional message, throttle attack traffic, and monitor attack
progress. A binary variant of LOIC includes the ability to join a botnet to
allow nodes to be controlled via IRC or RSS command channels (the
"HiveMind" feature).The following is a sample of LOIC traffic
recorded in a web server log:"GET
/?id=1327014400570&amp;msg=We%20Are%20Legion! HTTP/1.1" 200 99406
"hxxp://pastehtml.com/view/blafp1ly1.html" "Mozilla/5.0 (Windows
NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"The
following sites have been identified in HTTP referrer headers of suspected LOIC
traffic. This list may not be complete. Please do not visit any of the links as
they may still host functioning LOIC or other malicious code."hxxp://3g.bamatea.com/loic.html""hxxp://anonymouse.org/cgi-bin/anon-www.cgi/""hxxp://chatimpacto.org/Loic/""hxxp://cybercrime.hostzi.com/Ym90bmV0/loic/""hxxp://event.seeho.co.kr/loic.html""hxxp://pastehtml.com/view/bl3weewxq.html""hxxp://pastehtml.com/view/bl7qhhp5c.html""hxxp://pastehtml.com/view/blafp1ly1.html""hxxp://pastehtml.com/view/blakyjwbi.html""hxxp://pastehtml.com/view/blal5t64j.html""hxxp://pastehtml.com/view/blaoyp0qs.html""hxxp://www.lcnongjipeijian.com/loic.html""hxxp://www.rotterproxy.info/browse.php/704521df/ccc21Oi8/vY3liZXJ/jcmltZS5/ob3N0emk/uY29tL1l/tOTBibVY/wL2xvaWM/v/b5/fnorefer""hxxp://www.tandycollection.co.kr/loic.html""hxxp://www.zgon.cn/loic.html""hxxp://zgon.cn/loic.html""hxxp://www.turbytoy.com.ar/admin/archivos/hive.html"The
following are the A records for the referrer sites as of January, 20,
2012:3g[.]bamatea[.]com               
A    218[.]5[.]113[.]218cybercrime[.]hostzi[.]com        
A    31[.]170[.]161[.]36event[.]seeho[.]co[.]kr          
A    210[.]207[.]87[.]195chatimpacto[.]org                
A    66[.]96[.]160[.]151  anonymouse[.]org                 
A    193[.]200[.]150[.]125pastehtml[.]com                  
A    88[.]90[.]29[.]58lcnongjipeijian[.]com            
A    49[.]247[.]252[.]105www[.]rotterproxy[.]info         
A    208[.]94[.]245[.]131www[.]tandycollection[.]co[.]kr   A   
121[.]254[.]168[.]87www[.]zgon[.]cn                  
A    59[.]54[.]54[.]204www[.]turbytoy[.]com[.]ar        
A    190[.]228[.]29[.]84The HTTP requests
contained an "id" value based on UNIX time and user-defined
"msg" value, for example:GET
/?id=1327014189930&amp;msg=%C2%A1%C2%A1NO%20NOS%20GUSTA%20LA%20Other
"msg" examples:msg=%C2%A1%C2%A1NO%20NOS%20GUSTA%20LA%20msg=:)msg=:Dmsg=Somos%20Legion!!!msg=Somos%20legi%C3%B3n!msg=Stop%20S.O.P.A%20:)%20%E2%99%AB%E2%99%AB HTTP/1.1" 200 99406
"http://pastehtml.com/view/bl7qhhp5c.html"msg=We%20Are%20Legion!msg=ghmsg=open%20megauploadmsg=que%20sepan%20los%20nacidos%20y%20los%20que%20van%20a%20nacer%20que%20nacimos%20para%20vencer%20y%20no%20para%20ser%20vencidosmsg=stop%20SOPA!!msg=We%20are%20Anonymous.%20We%20are%20Legion.%20We%20do%20not%20forgive.%20We%20do%20not%20forget.%20Expect%20us!The
"msg" field can be arbitrarily set by the attacker.As of
January 20, 20012, US-CERT has observed another attack that consists of UDP
packets on ports 25 and 80. The packets contained a message followed by variable
amounts of padding, for example:66:6c:6f:6f:64:00:00:00:00:00:00:00:00:00 |
flood.........Target selection, timing, and other attack activity
is often coordinated through social media sites or online forums.US-CERT
is continuing research efforts and will provide additional data as it becomes
available.




III. Solution
There are a number of mitigation strategies available for dealing with DDoS
attacks, depending on the type of attack as well as the target network
infrastructure. In general, the best practice defense for mitigating DDoS
attacks involves advanced preparation.Develop a checklist or
Standard Operating Procedure (SOP) to follow in the event of a DDoS attack. One
critical point in a checklist or SOP is to have contact information for your ISP
and hosting providers. Identify who should be contacted during a DDoS, what
processes should be followed, what information is needed, and what actions will
be taken during the attack with each entity.The ISP or hosting provider
may provide DDoS mitigation services. Ensure your staff is aware of the
provisions of your service level agreement (SLA).Maintain contact
information for firewall teams, IDS teams, network teams and ensure that it is
current and readily available.Identify critical services that must be
maintained during an attack as well as their priority. Services should be
prioritized beforehand to identify what resources can be turned off or blocked
as needed to limit the effects of the attack. Also, ensure that critical systems
have sufficient capacity to withstand a DDoS attack.Have current
network diagrams, IT infrastructure details, and asset inventories. This will
assist in determining actions and priorities as the attack
progresses.Understand your current environment and have a baseline of
daily network traffic volume, type, and performance. This will allow staff to
better identify the type of attack, the point of attack, and the attack vector
used. Also, identify any existing bottlenecks and remediation actions if
required.Harden the configuration settings of your network, operating
systems, and applications by disabling services and applications not required
for a system to perform its intended function. Implement a bogon block list at the
network boundary.Employ service screening on edge routers wherever
possible in order to decrease the load on stateful security devices such as
firewalls.Separate or compartmentalize critical
services:Separate public and private servicesSeparate intranet,
extranet, and internet servicesCreate single purpose servers for each
service such as HTTP, FTP, and DNSReview the US-CERT Cyber
Security Tip Understanding
Denial-of-Service Attacks.



IV. References
Cyber Security Tip ST04-015 - Anonymous's
response to the seizure of MegaUpload according to CNN - The
Internet Strikes Back #OpMegaupload - Twitter
Post from the author of the JavaScript based LOIC code - Anonymous
Operations tweets on Twitter - @Megaupload
Tweets on Twitter - LOIC
DDoS Analysis and Detection - Impact
of Operation Payback according to CNN - OperationPayback
messages on YouTube - The
Bogon Reference - Team Cymru - 

   


                               
Feedback can be directed to US-CERT.


Produced 2012 by US-CERT, a government organization. Terms of use

Revision History
January 24, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/oEMgiDzcO7g" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-024A.html</guid>
         <pubDate>Wed, 25 Jan 2012 03:53:23 +0000</pubDate>
      </item>
      <item>
         <title>MS12-006 - Important : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-006</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-006</guid>
         <pubDate>Wed, 18 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (January 18, 2012): Added MS10-085 as a bulletin replaced by the KB2585542 update for Windows 7 for 32-bit Systems, Windows 7 for x64-based Systems, Windows Server 2008 R2 for x64-based Systems, and Windows Server 2008 R2 for Itanium-based Systems. This is an informational change only. There were no changes to the detection logic or the update files.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/7SFZ2dzVuXs" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-007 - Important : Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) - Version: 2.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-007</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-007</guid>
         <pubDate>Mon, 16 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V2.1 (January 16, 2012): Added a link to Microsoft Knowledge Base Article 2607664 under Known Issues in the Executive Summary. Also, revised entry in the update FAQ to clarify why the upgrade to AntiXSS Library version 4.2.1 is only available from the Microsoft Download Center.<br />
          Summary: This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depends on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/Hi_qXK40BnQ" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-010A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-010A.html</link>
         <description>Original release date: January 10, 2012
Last revised: --
Source: US-CERT


Systems Affected
Microsoft WindowsMicrosoft Developer Tools and
Software



Overview
There are multiple vulnerabilities in Microsoft Windows and Microsoft
Developer Tools and Software. Microsoft has released updates to address these
vulnerabilities.



I. Description
The Microsoft
Security Bulletin Summary for January 2012 describes multiple
vulnerabilities in Microsoft Windows. Microsoft has released updates to address
the vulnerabilities.



II. Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a
denial of service, or gain unauthorized access to your files or system.



III. Solution
Apply updatesMicrosoft has provided updates for
these vulnerabilities in the Microsoft
Security Bulletin Summary for January 2012. That bulletin describes any
known issues related to the updates. Administrators are encouraged to note these
issues and test for any potentially adverse effects. In addition, administrators
should consider using an automated update distribution system such as Windows Server
Update Services (WSUS).



IV. References
Microsoft Security Bulletin Summary for January 2012 - Microsoft
Windows Server Update Services - 

   


                               
Feedback can be directed to US-CERT.


Produced 2012 by US-CERT, a government organization. Terms of use

Revision History
January 10, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/WfrcRy_Ce7s" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-010A.html</guid>
         <pubDate>Tue, 10 Jan 2012 19:11:29 +0000</pubDate>
      </item>
      <item>
         <title>MS12-005 - Important : Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-005</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-005</guid>
         <pubDate>Tue, 10 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (January 10, 2012): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/3FVfIJz3x1I" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-003 - Important : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-003</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-003</guid>
         <pubDate>Tue, 10 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (January 10, 2012): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker successfully exploited this vulnerability. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. Only systems configured with a Chinese, Japanese, or Korean system locale are affected.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/2jgqte0CYQQ" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS12-002 - Important : Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms12-002</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms12-002</guid>
         <pubDate>Tue, 10 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (January 10, 2012): Bulletin published.<br />
          Summary:  This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/ZQP4E0vEZPw" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-099 - Important : Cumulative Security Update for Internet Explorer (2618444) - Version: 1.2</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-099</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-099</guid>
         <pubDate>Tue, 10 Jan 2012 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.2 (January 10, 2012): Announced that this update, MS11-099, enables the protections provided in the Vulnerability in SSL/TLS Could Allow Information Disclosure update, MS12-006, for Internet Explorer. For more information, see the Update FAQ.<br />
          Summary: This security update resolves three privately reported vulnerabilities in Internet Explorer. The most severe vulnerability could allow remote code execution if a user opens a legitimate HyperText Markup Language (HTML) file that is located in the same directory as a specially crafted dynamic link library (DLL) file.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/xjuz8CZ8Mm8" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA12-006A: Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA12-006A.html</link>
         <description>Original release date: January 06, 2012
Last revised: --
Source: US-CERT


Systems Affected
Most Wi-Fi access points that support Wi-Fi Protected Setup (WPS) are
affected.



Overview
Wi-Fi Protected Setup (WPS) provides simplified mechanisms to configure
secure wireless networks. The external registrar PIN exchange mechanism is
susceptible to brute force attacks that could allow an attacker to gain access
to an encrypted Wi-Fi network.



I. Description
WPS uses a PIN as a shared secret to authenticate an access point and a
client and provide connection information such as WEP and WPA passwords and
keys. In the external registrar exchange method, a client needs to provide the
correct PIN to the access point.An attacking client can try to guess the
correct PIN. A design vulnerability reduces the effective PIN space sufficiently
to allow practical brute force attacks. Freely available attack tools can
recover a WPS PIN in 4-10 hours.For further details, please see
Vulnerability Note VU#723755
and further documentation by Stefan
Viehbock and Tactical
Network Solutions.



II. Impact
An attacker within radio range can brute-force the WPS PIN for a vulnerable
access point. The attacker can then obtain WEP or WPA passwords and likely gain
access to the Wi-Fi network. Once on the network, the attacker can monitor
traffic and mount further attacks.



III. Solution
Update FirmwareCheck your access point vendor's
support website for updated firmware that addresses this vulnerability. Further
information may be available in the Vendor Information
section of VU#723755 and in a Google spreadsheet called WPS
Vulnerability Testing.Disable WPSDepending on
the access point, it may be possible to disable WPS. Note that some access
points may not actually disable WPS when the web management interface indicates
that WPS is disabled.



IV. References
Vulnerability Note VU#723755 - Wi-Fi
Protected Setup PIN brute force vulnerability - Cracking
WiFi Protected Setup with Reaver - WPS
Vulnerability Testing - 

   


                               
Feedback can be directed to US-CERT.


Produced 2012 by US-CERT, a government organization. Terms of use

Revision History
January 06, 2012: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/aLljAkWIUxg" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA12-006A.html</guid>
         <pubDate>Fri, 06 Jan 2012 20:49:39 +0000</pubDate>
      </item>
      <item>
         <title>MS11-096 - Important : Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-096</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-096</guid>
         <pubDate>Wed, 21 Dec 2011 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (December 21, 2011): Added Microsoft Office Compatibility Pack Service Pack 3 to the Non-Affected Software table. This is an informational change only. There were no changes to the detection logic or the update files.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-3403.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/UEHjdcOaGAI" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-094 - Important : Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142) - Version: 1.1</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-094</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-094</guid>
         <pubDate>Wed, 21 Dec 2011 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.1 (December 21, 2011): Added an entry to the Update FAQ to explain why this update is offered to customers running PowerPoint 2010 Service Pack 1.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of the vulnerabilities could take complete control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/3nQtmKnDjoY" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>TA11-350A: Adobe Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA11-350A.html</link>
         <description>Original release date: December 16, 2011
Last revised: --
Source: US-CERT


Systems Affected
Adobe Reader X (10.1.1) and earlier 10.x versions for Windows and
MacintoshAdobe Reader 9.4.6 and earlier 9.x versions for Windows,
Macintosh, and UNIXAdobe Acrobat X (10.1.1) and earlier 10.x versions
for Windows and MacintoshAdobe Acrobat 9.4.6 and earlier 9.x versions
for Windows and Macintosh



Overview
Adobe has released Security Bulletin APSB11-30,
which describes multiple vulnerabilities affecting Adobe Reader and Acrobat.



I. Description
Adobe Security Bulletin APSB11-30
and Adobe Security Advisory APSA11-04
describe a number of vulnerabilities affecting Adobe Reader and Acrobat.
These vulnerabilities affect Reader and Acrobat 9.4.6 and earlier 9.x versions.
These vulnerabilities also affect Reader X and Acrobat X 10.1.1 and earlier 10.x
versions.An attacker could exploit these vulnerabilities by convincing a
user to open a specially crafted PDF file. The Adobe Reader browser plug-in,
which can automatically open PDF documents hosted on a website, is available for
multiple web browsers and operating systems.Adobe Reader X and Adobe
Acrobat X will be patched in the next quarterly update scheduled for January 10,
2012.Additional details for the U3D memory corruption vulnerability can
be found in US-CERT
Vulnerability Note VU#759307.



II. Impact
These vulnerabilities could allow a remote attacker to execute arbitrary
code, write arbitrary files or folders to the file system, escalate local
privileges, or cause a denial of service on an affected system as the result of
a user opening a malicious PDF file.



III. Solution
Update ReaderAdobe has released updates to address
this issue. Users are encouraged to read Adobe Security Bulletin APSB11-30
and update vulnerable versions of Adobe Reader and Acrobat.In
addition to updating, please consider the following
mitigations.Disable Flash in Adobe Reader and
AcrobatDisabling Flash in Adobe Reader will mitigate attacks
that rely on Flash content embedded in a PDF file. Disabling 3D &amp; Multimedia
support does not directly address the vulnerability, but it does provide
additional mitigation and results in a more user-friendly error message instead
of a crash. To disable Flash and 3D &amp; Multimedia support in Adobe Reader 9,
delete, rename, or remove access to these files:Microsoft Windows"%ProgramFiles%&amp;#92;Adobe&amp;#92;Reader
9.0&amp;#92;Reader&amp;#92;authplay.dll""%ProgramFiles%&amp;#92;Adobe&amp;#92;Reader
9.0&amp;#92;Reader&amp;#92;rt3d.dll"Apple Mac OS
X"/Applications/Adobe Reader 9/Adobe
Reader.app/Contents/Frameworks/AuthPlayLib.bundle""/Applications/Adobe Reader 9/Adobe
Reader.app/Contents/Frameworks/Adobe3D.framework"GNU/Linux (locations may vary among distributions)"/opt/Adobe/Reader9/Reader/intellinux/lib/libauthplay.so""/opt/Adobe/Reader9/Reader/intellinux/lib/librt3d.so"File
locations may be different for Adobe Acrobat or other Adobe products that
include Flash and 3D &amp; Multimedia support. Disabling these plugins will
reduce functionality and will not protect against Flash content that is hosted
on websites. Depending on the update schedule for products other than Flash
Player, consider leaving Flash and 3D &amp; Multimedia support disabled unless
they are absolutely required.Disable JavaScript in Adobe Reader and
AcrobatDisabling JavaScript may prevent some exploits from resulting
in code execution. Acrobat JavaScript can be disabled using the Preferences menu
(Edit -&amp;gt; Preferences -&amp;gt; JavaScript; uncheck
Enable Acrobat JavaScript).Adobe provides a framework to blacklist specific
JavaScipt APIs. If JavaScript must be enabled, this framework may be useful
when specific APIs are known to be vulnerable or used in attacks.Prevent Internet Explorer from automatically opening PDF filesThe installer for Adobe Reader and Acrobat configures Internet Explorer to
automatically open PDF files without any user interaction. This behavior can be
reverted to a safer option that prompts the user by importing the following as a
.REG file:Windows Registry Editor Version
5.00[HKEY_CLASSES_ROOT&amp;#92;AcroExch.Document.7]"EditFlags"=hex:00,00,00,00Disable the display of PDF
files in the web browserPreventing PDF files from opening inside
a web browser will partially mitigate this vulnerability. If this workaround is
applied, it may also mitigate future vulnerabilities.To prevent PDF
files from automatically being opened in a web browser, do the following:1. Open Adobe Acrobat Reader.2. Open the Edit menu.3. Choose the Preferences option.4. Choose the
Internet section.5. Uncheck the "Display PDF in
browser" checkbox.Remove or restrict access to
3difr.x3dBy removing or restricting access to the 3difr.x3d
file, Adobe Reader and Acrobat will fail to render U3D content, which helps to
mitigate this vulnerability. PDF documents that use the PRC format for 3D
content will continue to function on Windows and Linux platforms.To
disable U3D support in Adobe Reader 9 on Microsoft Windows, delete or rename
this file:    "%ProgramFiles%&amp;#92;Adobe&amp;#92;Reader
9.0&amp;#92;Reader&amp;#92;plug_ins3d&amp;#92;3difr.x3d"For Apple Mac OS X, delete or
rename this directory:    "/Applications/Adobe
Reader 9/Adobe
Reader.app/Contents/Frameworks/Adobe3D.framework"For
GNU/Linux, delete or rename this file (locations may vary among
distributions):   
"/opt/Adobe/Reader9/Reader/intellinux/plug_ins3d/3difr.x3d"File
locations may be different for Adobe Acrobat or other Adobe products or
versions.Do not access PDF files from untrusted sourcesDo not open unfamiliar or unexpected PDF files, particularly those hosted on
websites or delivered as email attachments. Please see Cyber Security Tip ST04-010.



IV. References
Security update available for Adobe Reader and Acrobat - Adobe
Reader and Acrobat JavaScript Blacklist Framework - Adobe
Acrobat and Reader U3D memory corruption vulnerability - Security
Advisory for Adobe Reader and Acrobat - 

   


                               
Feedback can be directed to US-CERT.


Produced 2011 by US-CERT, a government organization. Terms of use

Revision History
December 16, 2011: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/RGgirOtZRb0" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA11-350A.html</guid>
         <pubDate>Fri, 16 Dec 2011 19:19:11 +0000</pubDate>
      </item>
      <item>
         <title>TA11-347A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA11-347A.html</link>
         <description>Original release date: December 13, 2011
Last revised: --
Source: US-CERT


Systems Affected
Microsoft WindowsMicrosoft OfficeInternet
Explorer



Overview
There are multiple vulnerabilities in Microsoft Windows, Office, and Internet
Explorer. Microsoft has released updates to address these vulnerabilities.



I. Description
The Microsoft
Security Bulletin Summary for December 2011 describes multiple
vulnerabilities in Microsoft Windows. Microsoft has released updates to address
the vulnerabilities. Additional details for MS11-091 can be found in US-CERT vulnerability note
VU#361441.



II. Impact
A remote, unauthenticated attacker could execute arbitrary code, cause a
denial of service, or gain unauthorized access to your files or system.



III. Solution
Apply updatesMicrosoft has provided updates for
these vulnerabilities in the Microsoft
Security Bulletin Summary for December 2011. That bulletin describes any
known issues related to the updates. Administrators are encouraged to note these
issues and test for any potentially adverse effects. In addition, administrators
should consider using an automated update distribution system such as Windows Server
Update Services (WSUS).



IV. References
Microsoft Security Bulletin Summary for December 2011 - Microsoft
Windows Server Update Services - US-CERT
Vulnerability Note VU#361441 - 

   


                               
Feedback can be directed to US-CERT.


Produced 2011 by US-CERT, a government organization. Terms of use

Revision History
December 13, 2011: Initial release&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/dmH8NXluBmI" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false">http://www.us-cert.gov/cas/techalerts/TA11-347A.html</guid>
         <pubDate>Tue, 13 Dec 2011 20:47:45 +0000</pubDate>
      </item>
      <item>
         <title>MS11-097 - Important : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-097</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-097</guid>
         <pubDate>Tue, 13 Dec 2011 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (December 13, 2011): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/5CymxkBC2Uc" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-095 - Important : Vulnerability in Active Directory Could Allow Remote Code Execution (2640045) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-095</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-095</guid>
         <pubDate>Tue, 13 Dec 2011 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (December 13, 2011): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/HMU2_xi4HX4" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>MS11-093 - Important : Vulnerability in OLE Could Allow Remote Code Execution (2624667) - Version: 1.0</title>
         <link>http://technet.microsoft.com/en-us/security/bulletin/ms11-093</link>
         <guid isPermaLink="false">http://technet.microsoft.com/en-us/security/bulletin/ms11-093</guid>
         <pubDate>Tue, 13 Dec 2011 08:00:00 +0000</pubDate>
         <content:encoded><![CDATA[Severity Rating: Important<br />
            Revision Note: V1.0 (December 13, 2011): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability. For more information, see the subsection, Affected and Non-Affected Software, in this section. The vulnerability could allow remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/epz2S8JxoLo" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Bugtraq: Re: rssh security announcement</title>
         <link>http://www.securityfocus.com/archive/1/522716</link>
         <description>Re: rssh security announcement&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/2SaQ9NBcPEw" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
      </item>
      <item>
         <title>Bugtraq: [ MDVSA-2012:076 ] ffmpeg</title>
         <link>http://www.securityfocus.com/archive/1/522715</link>
         <description>[ MDVSA-2012:076 ] ffmpeg&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/EPzhoCLKL6g" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
      </item>
      <item>
         <title>Bugtraq: [ MDVSA-2012:075 ] ffmpeg</title>
         <link>http://www.securityfocus.com/archive/1/522730</link>
         <description>[ MDVSA-2012:075 ] ffmpeg&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/YfVh_Be3pf0" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
      </item>
      <item>
         <title>Bugtraq: Trigerring Java code from a SVG image</title>
         <link>http://www.securityfocus.com/archive/1/522720</link>
         <description>Trigerring Java code from a SVG image&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/nhB6Ve1kFH4" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
      </item>
      <item>
         <title>More rss feeds from SecurityFocus</title>
         <link>http://www.securityfocus.com/rss/index.shtml</link>
         <description>News, Infocus, Columns, Vulnerabilities, Bugtraq ...&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/hJefXOl57uM" height="1" width="1"/&gt;</description>
         <guid isPermaLink="false" />
      </item>
      <item>
         <title>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
         <link>http://www.securitytracker.com/id/1027067</link>
         <guid isPermaLink="false" />
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/9Ym8l9Tv2UQ" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
         <link>http://www.securitytracker.com/id/1027065</link>
         <guid isPermaLink="false" />
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/W-xeShbb24c" height="1" width="1"/&gt;</description></item>
      <item>
         <title>socat Buffer Overflow in xioscan_readline() Lets Local Users Gain Elevated Privileges</title>
         <link>http://www.securitytracker.com/id/1027064</link>
         <guid isPermaLink="false" />
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/cUgccE7chz4" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Adobe Photoshop Stack Overflow in 'U3D.B8I' Library Lets Remote Users Execute Arbitrary Code</title>
         <link>http://www.securitytracker.com/id/1027063</link>
         <guid isPermaLink="false" />
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/S3E2Pf4k1QQ" height="1" width="1"/&gt;</description></item>
      <item>
         <title>Smarty Input Validation Flaw in {html_options} Function Plugin Permits Cross-Site Scripting Attacks</title>
         <link>http://www.securitytracker.com/id/1027061</link>
         <guid isPermaLink="false" />
      <description>&lt;img src="http://feeds.feedburner.com/~r/notageek_secfeeds_vulnheadlines/~4/y4kJUBGj4Z4" height="1" width="1"/&gt;</description></item>
   </channel>
</rss><!-- fe11.pipes.sp1.yahoo.com compressed/chunked Wed May 16 09:48:15 UTC 2012 -->

