Category: Security Advisories

06/23/10

Permalink 03:19:11 pm, by Zach Brewer, 295 words
Categories: Security Advisories, General Security, BigFix

Application Whitelisting and MS Authenticode

F-Secure has recently reported of "…tens of thousands of malware samples that have been signed (with MS Authenticode)."MS Authenticode uses digital signatures (code signing) to authenticate software and inform the user of the fact that the software w… more »

04/14/10

Permalink 09:53:42 am, by Zach Brewer, 99 words
Categories: Security Advisories, General Security

Apache.Org Compromise

On 04/05/2010, Apache's issue tracker for projects was compromised via an XSS attack. The attackers used a simple URL redirect service appended to a new issue to grab administrator session credentials and ultimately download hashed copies of JIRA, Bugzi… more »

04/06/10

Permalink 02:37:28 pm, by Zach Brewer, 157 words
Categories: Cisco Security Agent, Security Advisories

IMPORTANT: No New ClamAV Signatures for CSA Versions Earlier than 6.0.1.138

ClamAV will no longer release new signatures for ClamAV scan engines older than 0.95 effective as of April 15, 2010. As a result, any CSA 6.0 implementation prior to 6.0.1.138 using the ClamAV signature protection (AV - Signature AV Policy) will not rec… more »

03/16/10

Permalink 05:44:23 pm, by Chad Sullivan, 136 words
Categories: Security Advisories

Microsoft Virtual PC Creates Vulnerabilities

A Core Security researcher has announced a vulnerability in Microsoft PC Virtualization that in effect, can expose a vulnerability in applications where one did not exist in un-virtualized systems. The problem is, if you run an application in a Microsoft… more »

03/12/10

Permalink 01:44:28 pm, by Zach Brewer, 325 words
Categories: Security Advisories, General Security

CVE-2010-0624: Heap-Based Overflow in GNU Tar and GNU Cpio

GNU Tar and GNU Cpio are used for managing archives on many *nix distributions (note: most BSD distributions including MacOSX use bsdtar).  Both GNU TAR and GNU Cpio are capable of using the RMT protocol - a protocol used for accessing tape devices on re… more »

1 2 3 4 5 6 >>

Priveon, Inc.

Today's complex security and networking solutions require a great deal of knowledge to successfully support and operate. Priveon uses the field experience of its expert staff to develop and maintain a positive reinforcement loop between business practices and to provide the latest information to our customers. The information posted here is supported by Priveon subject-matter experts.

Search

XML Feeds

Archives

©2010 by Priveon, Inc.