<?xml version="1.0" encoding="ISO-8859-1" ?><rss version="2.0">
    <channel>
        <title>XRamp Security Advisories</title>
        <link>http://www.xramp.com/securityalerts/</link>
        <description>The latest XRamp Security Advisories are free at http://www.xramp.com/securityalerts/</description>
        <pubDate>Fri, 04 Jul 2008 19:01:37 -0500</pubDate>
        <category>Security Alerts</category>
        <docs>http://blogs.law.harvard.edu/tech/rss</docs>
        <ttl>30</ttl>
        <language>eng</language>
        <item>
            <title>Symantec Warns Users of New Drive-By Pharming Attack</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: Symantec Warns Users of New Drive-By Pharming Attack&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
In an &lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2007/02/driveby_pharming_how_clicking_1.html&quot; &gt;announcement&lt;/a&gt; made yesterday, security researchers at Symantec and Indiana University School of Informatics revealed that they had uncovered a serious new security threat targeting home broadband routers. The attack, dubbed Drive-By Pharming, allows an attacker to change the configuration of a home router when a user unknowingly visits a malicious website. The website employs malicious JavaScript code that allows an attacker to log into many types of home routers if the default password has not been changed. Once logged in, the attacker is able to change the configuration of the home router, including the Domain Name Server (DNS) server settings.
&lt;/dd&gt;

&lt;dd&gt;
This type of attack is particularly concerning for a few reasons:
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;Simply viewing the malicious webpage is all that is required for a user to fall victim to this attack.&lt;/li&gt;
		&lt;li&gt;Many home users fail to change the default password on their broadband routers. The Symantec report indicates that 50% of all users could fall into this category.&lt;/li&gt;
		&lt;li&gt;Changing the Domain Name Server (DNS) server settings allow an attacker to redirect the home user to a DNS server of their choice. This includes a malicious server set up by the attacker to direct users to other malicious websites, where information such as financial account numbers, passwords, and other sensitive data can be stolen. &lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
Symantec notes that the best defense against this type of attack is for home users to change their default password. The following links provide support resources for three of the more common home router vendors:
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;a href=&quot;http://support.dlink.com/faq/view.asp?prod_id=1997&amp;question=password+change&quot; &gt;D-Link&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=3976&quot; &gt;Linksys&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://kbserver.netgear.com/inquira/default.asp?ui_mode=answer&amp;prior_transaction_id=2584754&amp;action_code=5&amp;highlight_info=16777268,114,118&amp;turl=http://kbserver.netgear.com/kb_web_files/N101475.asp&amp;answer_id=65745448#__highlight&quot; &gt;NETGEATR&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
US-CERT cautions users to avoid clicking on links sent in unsolicited emails. Users should also remain cautious when browsing the web and avoid visiting untrusted sites. More information can be found in &lt;a href=&quot;http://www.cert.org/tech_tips/securing_browser/#Mozilla_Firefox&quot; &gt;Securing Your Web Browser&lt;/a&gt; document.
&lt;/dd&gt;
&lt;dd&gt;
To learn more, or to view a flash-animation of the attack, visit &lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2007/02/driveby_pharming_how_clicking_1.html&quot; &gt;Security Response Weblog.&lt;/a&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Adobe Acrobat Reader Unspecified Heap Corruption Vulnerability</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/SecurityFocus SECURITY NOTICE: Adobe Acrobat Reader Unspecified Heap Corruption Vulnerability
&lt;br/&gt;
&lt;/h4&gt;

&lt;dl&gt;
		
	&lt;dt&gt;I. Description&lt;/dt&gt;

&lt;dd&gt;
Adobe Acrobat Reader is prone to a heap-based buffer-overflow vulnerability because the application fails to properly bounds-check malicious PDF files, resulting in a heap-based buffer overflow.
&lt;/dd&gt;
&lt;dd&gt;
Successfully exploiting this issue may allow a remote attacker to execute arbitrary code in the context of the victim user running the affected application.  Failed exploit attempts will likely result in denial-of-service conditions.
&lt;/dd&gt;
&lt;dd&gt;
An attacker could exploit this issue by enticing a victim to open a malicious PDF file.
&lt;/dd&gt;

	&lt;dt&gt;II. Exploit&lt;/dt&gt;

	&lt;dd&gt;
Currently we are not aware of any exploits for this issue..
&lt;/dd&gt;
	
	&lt;dt&gt;III. Solution&lt;/dt&gt;
	
	&lt;dd&gt;
The vendor has released an advisory along with fixes to address this issue.  Please see the referenced advisory for information on obtaining and applying fixes.
&lt;/dd&gt;
&lt;dd&gt;
			Adobe Acrobat Reader 7.0

			&lt;ul&gt;				
			&lt;li&gt;
					Turbolinux AdobeReader_enu-7.0.9-1TL1.i686.rpm&lt;br/&gt;
					&lt;a href=&quot;ftp://ftp.turbolinux.co.jp/pub/TurboLinux/&quot;&gt;ftp://ftp.turbolinux.co.jp/pub/TurboLinux/&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
			&lt;/dd&gt;
		
&lt;/dl&gt;
	&lt;h4&gt;References&lt;/h4&gt;
&lt;dl&gt;
&lt;dd&gt;
&lt;ul&gt;					&lt;li&gt;&lt;a href=&quot;http://www.adobe.com/&quot;&gt;Adobe Home Page&lt;/a&gt; (Adobe)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.adobe.com/go/getreader&quot;&gt;Adobe Reader Download Page&lt;/a&gt; (Adobe)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb07-01.html&quot;&gt;Adobe Security Advisory APSB07-01&lt;/a&gt; (Adobe)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.adobe.com/&quot;&gt;Adobe Reader Remote Heap Memory Corruption - Subroutine Pointer Overwrite&lt;/a&gt; (Piotr Bania)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.piotrbania.com/all/adv/adobe-acrobat-adv.txt&quot;&gt;Adobe Reader Remote Heap Memory Corruption-Subroutine Pointer Overwrite&lt;/a&gt; (Piotr Bania)&lt;/li&gt;
											
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Anomalous DNS Activity</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description> &lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: Anomalous DNS Activity&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
US-CERT was made aware of anomalous Domain Name Server (DNS) traffic that began on 6 Feb 2007.  It is not confirmed whether this is a DDOS attempt or an incidental effect of something else, however it is likely that the traffic is Distributed Denial of Service (DDOS) related.
&lt;/dd&gt;
&lt;dd&gt;
At approximately 0001 GMT on 6 Feb 2007, several root-level DNS servers began receiving a large volume of malformed DNS queries.  This initial attack appears to have been a warm-up for a much larger attack that began at 1000 GMT.
&lt;/dd&gt;
&lt;dd&gt;
DNS servers G (U.S. DOD Network Information Center), L (Internet Corporation for Assigned Names and Numbers), and M (WIDE project) appear to have been the most severely impacted although none were ever unreachable.  The servers were operational and reachable even with the high volume attack.
&lt;/dd&gt;
&lt;dd&gt;
US-CERT has been in contact with various groups affected to ensure that appropriate actions are being taken.
&lt;/dd&gt;
&lt;dd&gt;
US-CERT will continue to investigate and provide additional information as needed.
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/SecurityFocus SECURITY NOTICE: Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness
&lt;br/&gt;
&lt;/h4&gt;

&lt;dl&gt;
		
	&lt;dt&gt;I. Description&lt;/dt&gt;

&lt;dd&gt;
Mozilla Firefox is prone to a cross-zone security-bypass weakness.  This issue allows attackers to open 'file://' URIs from remote websites.
&lt;/dd&gt;
&lt;dd&gt;
By exploiting this issue in conjunction with other weaknesses or vulnerabilities, attackers may be able to execute arbitrary script code with the elevated privileges that are granted to scripts when they are executed from local sources.
&lt;/dd&gt;
&lt;dd&gt;
Mozilla Firefox 1.5.0.9 is affected by this issue; other versions may be affected as well.
&lt;/dd&gt;

	&lt;dt&gt;II. Exploit&lt;/dt&gt;

	&lt;dd&gt;
Attackers use standard web development and server applications to exploit this issue.
&lt;/dd&gt;
	
	&lt;dt&gt;III. Solution&lt;/dt&gt;
	
	&lt;dd&gt;
Currently we are not aware of any vendor-supplied patches for this issue.
&lt;/dd&gt;
		
&lt;/dl&gt;
	&lt;h4&gt;References&lt;/h4&gt;
&lt;dl&gt;
&lt;dd&gt;
&lt;ul&gt;					&lt;li&gt;&lt;a href=&quot;http://www.mozilla.org/products/firefox/&quot;&gt;Mozilla Firefox Home Page&lt;/a&gt; (Mozilla)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/459162&quot;&gt;Firefox + popup blocker + XMLHttpRequest + srand() = oops&lt;/a&gt; (Michal Zalewski)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/459171&quot;&gt;Re: Firefox + popup blocker + XMLHttpRequest + srand () = oops&lt;/a&gt; (Michal Zalewski)&lt;/li&gt;
											
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Microsoft Releases Security Advisory for Unpatched Vulnerability in Office involving Excel</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description> &lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: Microsoft Releases Security Advisory for Unpatched Vulnerability in Office involving Excel&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
Microsoft has released Security Advisory &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/932553.mspx&quot; &gt;932553&lt;/a&gt; to address a new vulnerability that affects multiple versions of Microsoft Office.  When Office applications improperly process a malformed string, a corruption in system memory occurs.
By persuading a user to open a specially crafted Office document from an email attachment or web site, a remote attacker may be able to execute arbirtary code with privileges of the user.
&lt;/dd&gt;
&lt;dd&gt;
The Securiry Advisory states that the following Office versions are vulnerable: Microsoft Office 2000, Microsoft Office XP, Microsoft Office 2003, and Microsoft Office 2004 for Mac.
&lt;/dd&gt;
&lt;dd&gt;
According to the Microsoft Security Response Center &lt;a href=&quot;http://blogs.technet.com/msrc/archive/2007/02/02/microsoft-security-advisory-932553-posted.aspx&quot; &gt;Blog&lt;/a&gt;, there are very limited, targeted attacks attempting to use Excel documents as an attack vector to exploit this vulnerability in Microsoft Office.  However, the issue can also affect all Office documents.
&lt;/dd&gt;
&lt;dd&gt;
Until Microsoft provides a security update, or more important becomes available, US-CERT recommends the following actions to help mitigate the security risk:
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;strong&gt;Do not open untrusted Word documents &lt;/strong&gt;or attachments from unsolicited email messages.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Disable automatic opening &lt;/strong&gt; of Microsoft Office documents, as specified in the  Office Document Open Confirmation Tool document for Office 2000.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Do not rely on file name extensions &lt;/strong&gt;as a way to securely filter against malicious files.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Limit user privileges &lt;/strong&gt;to no administrator rights.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Review&lt;/strong&gt; Microsoft Security Advisory &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/932553.mspx&quot; &gt;932553&lt;/a&gt; for additional workarounds.&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
US-CERT will continue to investigate and provide additional information as it becomes available.
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Cisco Releases Security Advisories for Multiple Vulnerabilities in IOS</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description> &lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: Cisco Releases Security Advisories for Multiple Vulnerabilities in IOS&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
Cisco has released three Security Advisories to address severly rated vulnerabilities in their Internetwork Operating System Software
&lt;/dd&gt;

&lt;dd&gt;
&lt;a href=&quot;http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml&quot;&gt;Cisco Security Advisory: Crafted IP Option Vulnerability&lt;/a&gt; addresses a remotely exploitable denial-of-service vulnerability that may potentially
allow for arbitrary code execution.  This vulnerability may be exploited when an affected device processes a crafted packet that meets all of the following conditions: 
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;The packet contains a specific crafted IP option.&lt;/li&gt;
		&lt;li&gt;The packet is one of the following protocols:&lt;/li&gt;
		&lt;li&gt;&lt;ul&gt;
			&lt;li&gt;ICMP - Echo Request (Type 8)&lt;/li&gt;
			&lt;li&gt;ICMP - Timestamp (Type 13)&lt;/li&gt;
			&lt;li&gt;ICMP - Information Request (Type 15)&lt;/li&gt;
			&lt;li&gt;ICMP - Address Mask Request (Type 17)&lt;/li&gt;
			&lt;li&gt;PIMv2 - IP protocol 103&lt;/li&gt;
			&lt;li&gt;PGM - IP protocol 113&lt;/li&gt;
			&lt;li&gt;URD - TCP Port 465&lt;/li&gt;
		&lt;/ul&gt;&lt;/li&gt;
		&lt;li&gt;The packet is sent to a physical or virtual IPv4 address configured on the affected device.&lt;/li&gt;
		&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
&lt;a href=&quot;http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-tcp.shtml&quot;&gt;Cisco Security Advisory: Crafted TCP Packet Can Cause Denial of Service&lt;/a&gt; addresses a denial-of-service vulnerability in the Transmission Control Protocol
listener.  Crafted packets may cause the device to leak a small amount of memory.  Over time, such a memory leak may lead to memory exhaustion and a denial-of-service condition.
&lt;/dd&gt;
&lt;dd&gt;
&lt;a href=&quot;http://www.cisco.com/warp/public/707/cisco-sa-20070124-IOS-IPv6.shtml&quot;&gt;Cisco Security Advisory: IPv6 Routing Header Vulnerability&lt;/a&gt; addresses a remotely exploitable denial-of-service vulnerability in the IPv6 Type 0 Routing
header handling.  This vulnerability can be triggered by a packet containing crafted IPv6 Type 0 Routing headers.
&lt;/dd&gt;
&lt;dd&gt;
More information about these vulnerabilities can be found in the Vulnerability Notes Database.
&lt;/dd&gt;
&lt;dd&gt;
US-CERT encourages users to apply the fixes and workarounds described in the Cisco Security Advisories and Vulnerability Notes, and will continue to investigate and provide additional information as it becomes available.
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/SecurityFocus SECURITY NOTICE: Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities
&lt;br/&gt;
&lt;/h4&gt;

&lt;dl&gt;
		
	&lt;dt&gt;I. Description&lt;/dt&gt;

&lt;dd&gt;
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities because the application fails to handle exceptional conditions.
&lt;/dd&gt;
&lt;dd&gt;
These issues are triggered when an attacker entices a victim user to visit a malicious website.
&lt;/dd&gt;
&lt;dd&gt;
Remote attackers may exploit these issues to crash Internet Explorer, effictively denying service to legitimate users.
&lt;/dd&gt;

	&lt;dt&gt;II. Exploit&lt;/dt&gt;

	&lt;dd&gt;
An attacker may exploit this issue by enticing victims into viewing malicious HTML content.
&lt;/dd&gt;
&lt;dd&gt;
An proof of concept has been provided:&lt;/dd&gt;

&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/data/vulnerabilities/exploits/ie_ax_dos&quot;&gt;/data/vulnerabilities/exploits/ie_ax_dos&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
	
	&lt;dt&gt;III. Solution&lt;/dt&gt;
	
	&lt;dd&gt;
Currently we are not aware of any vendor-supplied patches for this issue.
&lt;/dd&gt;
		
&lt;/dl&gt;
	&lt;h4&gt;References&lt;/h4&gt;
&lt;dl&gt;
&lt;dd&gt;
&lt;ul&gt;					&lt;li&gt;&lt;a href=&quot;http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html&quot;&gt;Internet Explorer ActiveX bgColor Property Denial of Service&lt;/a&gt; (Determina Security Research)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.microsoft.com/windows/ie/&quot;&gt;Internet Explorer Home Page&lt;/a&gt; (Microsoft)&lt;/li&gt;
											
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>New Unpatched Vulnerability in Microsoft Word</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description> &lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: New Unpatched Vulnerability in Microsoft Word&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
US-CERT is investigating reports of new Microsoft Word vulnerability affecting Word 2000 and Word 2003/XP.  Earlier today, Symantec published an alert indicating that the vulnerability
could be exploited to allow an attacker to execute arbitrary code in the context of the user who is logged in.  Details of the vulnerability are not yet clear; however, the alert indicated that exploitatin is occuring in the wild.
&lt;/dd&gt;

&lt;dd&gt;
Until more information becomes available, US-CERT recommends the following actions to help mitigate the security risk:
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;strong&gt;Do not open untrusted Word documents &lt;/strong&gt;or attachments from unsolicited email messages.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Disable automatic opening &lt;/strong&gt; of Microsoft Office documents.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Do not rely on file name extensions &lt;/strong&gt;as a way to securely filter against malicious files.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Install anti-virus software &lt;/strong&gt;and keep its virus signature files up-to-date.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Save and scan &lt;/strong&gt;any attachments before opening them.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Limit user privileges &lt;/strong&gt;to no administrator rights.&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
US-CERT will continue to investigate and provide additional information as it becomes available.
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Microsoft Outlook Malformed Email Header Remote Denial of Service Vulnerability</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/SecurityFocus SECURITY NOTICE: Microsoft Outlook Malformed Email Header Remote Denial of Service Vulnerability
&lt;br/&gt;
&lt;/h4&gt;

&lt;dl&gt;
		
	&lt;dt&gt;I. Description&lt;/dt&gt;

&lt;dd&gt;
Microsoft Outlook is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed email messages.&lt;/dd&gt;
&lt;dd&gt;
A remote attacker can exploit this issue to crash affected email clients.  This issue will persist as long as the email message resides on the mail server, creating a prolonged denial-of-service condition.
&lt;/dd&gt;

	&lt;dt&gt;II. Exploit&lt;/dt&gt;

	&lt;dd&gt;
Attackers exploit this issue by using standard email clients or readily available network utilities.
&lt;/dd&gt;
	
	&lt;dt&gt;III. Solution&lt;/dt&gt;
	
	&lt;dd&gt;
Microsoft has released an advisory and fixes to address this issue.  Please see the references for more information.
	&lt;/dd&gt;
	
		&lt;dd&gt;
			Microsoft Outlook 2000 0

			&lt;ul&gt;				
			&lt;li&gt;
					Microsoft Security Update for Outlook 2000 (KB921593)&lt;br/&gt;
					&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
			&lt;/dd&gt;
			
		&lt;dd&gt;
			Microsoft Outlook 2002 0
			&lt;ul&gt;
			&lt;li&gt;
					Microsoft Security Update for Outlook 2002 (KB921594)&lt;br/&gt;
					&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
		
		&lt;dd&gt;
			Microsoft Outlook 2002 SP1
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2002 (KB921594)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
		&lt;dd&gt;
			Microsoft Outlook 2000 SR1
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2000 (KB921593)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
			&lt;dd&gt;
			Microsoft Outlook 2003 0
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2003 (KB924085)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=9E4DD8AE-2564-4176-AC2E-E3760058CB56&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
				&lt;dd&gt;
			Microsoft Outlook 2000 SP3
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2000 (KB921593)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
					&lt;dd&gt;
			Microsoft Outlook 2000 SP2
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2000 (KB921593)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=97CE0B32-C6AF-4C6C-ABF1-838ED89062EB&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
					&lt;dd&gt;
			Microsoft Outlook 2002 SP2
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2002 (KB921594)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
					&lt;dd&gt;
			Microsoft Outlook 2002 SP3
			&lt;ul&gt;
				&lt;li&gt;
				Microsoft Security Update for Outlook 2002 (KB921594)&lt;br/&gt;
				&lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&quot;&gt;http://www.microsoft.com/downloads/details.aspx?familyid=1D1991C5-3DE3-4258-9120-058FFD62B4F5&lt;/a&gt;&lt;/li&gt;
			&lt;/ul&gt;
		&lt;/dd&gt;
				
&lt;/dl&gt;
	&lt;h4&gt;References&lt;/h4&gt;
&lt;dl&gt;
&lt;dd&gt;
&lt;ul&gt;					
					&lt;li&gt;&lt;a href=&quot;http://office.microsoft.com/en-us/outlook/default.aspx&quot;&gt;Microsoft Outlook Home Page&lt;/a&gt; (Microsoft)&lt;/li&gt;
					&lt;li&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx&quot;&gt;Microsoft Security Bulletin MS07-003&lt;/a&gt; (Microsoft)&lt;/li&gt;
					
					
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
        <item>
            <title>Apple Releases Security Update for Vulnerability in QuickTime</title>
            <link>http://www.xramp.com/securityalerts/</link>
            <description>&lt;h4&gt;XRAMP/US-Cert SECURITY NOTICE: Apple Releases Security Update for Vulnerability in QuickTime&lt;br/&gt;&lt;/h4&gt;

&lt;dl&gt;
&lt;dd&gt;
Apple has released Security Update &lt;a href=&quot;http://docs.info.apple.com/article.html?artnum=304989&quot;&gt;2007-001&lt;/a&gt; to correct a buffer overflow vulnerability in Apple QuickTime.  The flaw is in the way that QuickTime handles
Real Time Streaming Protocol (RTSP) URL strings.  By persuading a user to access a specially crafted QuickTime file, a remote attacker may be able to 
execute arbitrary code or cause a denial of service on a vulnerable system.  US-CERT is also aware of publicly available proof-of-concept code that exploits this vulnerability.
&lt;/dd&gt;
&lt;dd&gt;
Additionally, the Month of Apple Bugs &lt;a href=&quot;http://projects.info-pull.com/moab/MOAB-01-01-2007.html&quot;&gt;MOAB-01-01-2007&lt;/a&gt; website states that an attacker may also submit a specially crafted HTML document (e.g., a webpage or an HTML email message)
or Javascript code to cause a buffer overflow and compromise a vulnerable system.
&lt;/dd&gt;
&lt;dd&gt;
More information about this vulnerability is located in the following:
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
	&lt;li&gt;Vulnerability Note &lt;a href=&quot;http://www.kb.cert.org/vuls/id/442497&quot;&gt;VU#442497&lt;/a&gt; - Apple QuickTime RTSP buffer overflow&lt;/li&gt;
	&lt;li&gt;Technical Cyber Security Alert &lt;a href=&quot;http://www.us-cert.gov/cas/techalerts/TA07-005A.html&quot;&gt;TA07-005A&lt;/a&gt; - Apple QuickTime RTSP buffer overflow&lt;/li&gt;
	&lt;li&gt;Apple Security Update &lt;a href=&quot;http://docs.info.apple.com/article.html?artnum=304989&quot;&gt;2007-001&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;Month of Apple Bugs&lt;a href=&quot;http://projects.info-pull.com/moab/MOAB-01-01-2007.html&quot;&gt;MOAB-01-01-2007&lt;/a&gt; - Apple QuickTime rtsp URL Handler Stack-based Buffer Overflow&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;dd&gt;
US-CERT encourages users to apply the appropriate updates as specified in Apple Security Update &lt;a href=&quot;http://docs.info.apple.com/article.html?artnum=304989&quot;&gt;2007-001&lt;/a&gt; as soon as possible.
&lt;/dd&gt;
&lt;dd&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;strong&gt;Disable the QuickTime ActiveX controls &lt;/strong&gt;in Internet Explorer as specified in Microsoft Support Document &lt;a href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;240797&lt;/a&gt;.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Disable the QuickTime plug-in &lt;/strong&gt;for Mozilla-based browsers as specified in the PluginDoc article &lt;a href=&quot;http://plugindoc.mozdev.org/faqs/uninstall.html&quot;&gt;Uninstalling Plugins&lt;/a&gt;.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Disable file association &lt;/strong&gt;for QuickTime files.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Disable JavaScrpit &lt;/strong&gt;as specified in the &lt;a href=&quot;http://www.us-cert.gov/reading_room/securing_browser/&quot;&gt;Securing Your Web Browser&lt;/a&gt; document.&lt;/li&gt;
		&lt;li&gt;&lt;strong&gt;Do not access &lt;/strong&gt; QuickTime files from untrusted sources.&lt;/li&gt;
	&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;</description>
            <author>XRamp Security Services, Inc</author>
        </item>
    </channel>
</rss>