Tag Archives: CVE

Malware campaign strikes Asian, European governments

Trend Micro says it detected a targeted attack that sent malware-laden emails to representatives of 16 European countries and some Asian governments.

The bogus emails purported to come from China’s defense ministry and contained a malicious attachment that exploited a now-patched vulnerability in Microsoft Office versions 2003 to 2010, wrote Jonathan Leopando, a technical communications specialist with Trend Micro. 

Microsoft patched the vulnerability in Office, CVE-2012-0158, more than a year ago although attackers are still frequently targeting it, including in the Safe and Taidoor campaigns, Leopando wrote.

If the email attachment is opened on an unpatched computer, a “backdoor” program is then installed that steals login credentials for websites and email credentials from Internet Explorer and Microsoft Outlook, Leopando wrote.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Unusual file-infecting malware steals FTP credentials, researchers say

A new version of a file-infecting malware program that’s being distributed through drive-by download attacks is also capable of stealing FTP (File Transfer Protocol) credentials, according to security researchers from antivirus firm Trend Micro.

The newly discovered variant is part of the PE_EXPIRO family of file infectors that was identified in 2010, the Trend Micro researchers said Monday in a blog post. However, this version’s information theft routine is unusual for this type of malware.

The new threat is distributed by luring users to malicious websites that host Java and PDF exploits as part of an exploit toolkit. If visitors’ browser plug-ins are not up to date, the malware will be installed on their computers.

The Java exploits are for the CVE-2012-1723 and CVE-2013-1493 remote code execution vulnerabilities that were patched by Oracle in June 2012 and March 2013 respectively.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Researchers: Surveillance malware distributed via Flash Player exploit

Political activists from the Middle East were targeted in attacks that exploited a previously unknown Flash Player vulnerability to install a so-called lawful interception program designed for law enforcement use, security researchers from antivirus vendor Kaspersky Lab said Tuesday.

Last Thursday, Adobe released an emergency update for Flash Player in order to address two zero-day—unpatched—vulnerabilities that were already being used in active attacks. In its security advisory at the time, Adobe credited Sergey Golovanov and Alexander Polyakov of Kaspersky Lab for reporting one of the two vulnerabilities, namely the one identified as CVE-2013-0633.

On Tuesday, the Kaspersky Lab researchers revealed more information about how they originally discovered the vulnerability. “The exploits for CVE-2013-0633 have been observed while monitoring the so-called ‘legal’ surveillance malware created by the Italian company HackingTeam,” Golovanov said in a blog post.

HackingTeam is based in Milan but also has a presence in Annapolis, Maryland, and Singapore. According to its website, the company develops a computer surveillance program called Remote Control System (RCS) that is sold to law enforcement and intelligence agencies.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Adobe releases emergency patch for Windows and OS X systems

Adobe recently released an emergency update for Flash Player on all platforms after two zero-day bugs were discovered in the wild targeting Windows and Mac OS X computers. The vulnerabilities allowed hackers to hijack both Windows PCs and Macs. Adobe recommends all users to update their systems as soon as possible.

The first vulnerability, CVE-2013-0633, tricks users into downloading a Microsoft Word document sent via e-mail. As you might expect, the document contains malicious SWF (flash’s file extension) content that can then infect a user’s system. This exploit targets the ActiveX version of Flash Player for Windows, Adobe said.

The second exploit, CVE-2013-0634, targets Firefox and Safari users on Mac OS X by directing users to Websites containing malicious Flash content. This vulnerability is also being used against Windows users in a similar manner to the first exploit. Namely, malicious documents delivered via e-mail.

So there’s nothing new here in terms of malware delivery, but you should update your Flash Player software as soon as possible if it isn’t set to update automatically. Even though the newly patched weaknesses target Mac and Windows users, Adobe has also released updates for Flash Player on Linux and all versions of Android from 2.X to 4.X (basically, everyone running Flash on Android).

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Ubuntu Kernel Team: Kernel Team Meeting Minutes – Feb 5, 2013

Meeting Minutes

IRC Log of the meeting.

Meeting minutes.

Agenda

20130205 Meeting Agenda

ARM Status

R/master: work continues on the arm multiplatform kernel – right now i’m
tracking down a “BUG: scheduling while atomic” (actually an alignment problem –
how conform
http://paste.ubuntu.com/1613275/) that only happens on omap4, seems to be ipv6
related and seems to be triggered by our articulated kernel configuration.

Release Metrics and Incoming Bugs

Release metrics and incoming bug data can be reviewed at the following link:

  • http://people.canonical.com/~kernel/reports/kt-meeting.txt

Milestone Targeted Work Items

We were able to clean up quite a few work items last week and are now
well below the trend line for our overall burn down chart. Thanks to
everyone who closed out items.

   apw    hardware-r-kernel-config-review    6 work items   
      hardware-r-delta-review    3 work items   
   ppisati    hardware-r-kernel-config-review    1 work item   
      hardware-r-kernel-version-and-flavors    2 work items   
      hardware-r-delta-review    1 work item   
   rtg    hardware-r-delta-review    1 work item   
   smb    hardware-r-kernel-misc    2 work items   

Status: Raring Development Kernel

We have rebased the Raring kernel to the latest v3.8-rc6 upstream
kernel and uploaded. We’ve also pulled our first set of patches for arm
multiplatform support o/.
Also just a small reminder, the 12.04.2 point release is nearing. If
anyone has free cycles and is able to test, please do so.
Important upcoming dates:

  • Raring:

    • Mon Feb 18 – 13.04 Month 4 Milestone (~2 weeks)
  • Precise:

    • Thu Feb 14 – 12.04.2 Release (~1 week)

Status: CVE’s

Currently we have 32 CVEs on our radar, with 3 CVEs added and 4 CVE retired this week.
See the CVE matrix for the current list:

  • http://people.canonical.com/~kernel/cve/pkg/ALL-linux.html

    Overall the backlog has decreased slightly this week:

  • http://people.canonical.com/~kernel/status/cve-metrics.txt

  • http://people.canonical.com/~kernel/cve/pkg/CVE-linux.txt

Status: Stable, Security, and Bugfix Kernel Updates – Quantal/Precise/Oneiric/Lucid/Hardy

Here is the status for the main kernels, until today (February 05):

  • Hardy – Nothing in this cycle
  • Lucid – Nothing in this cycle
  • Oneiric – In Preparation; 3 CVEs; 4 upstream stable release(s); (154 commits)
  • Precise – In Preparation; 0 CVEs; 2 upstream stable release(s); (222 commits)
  • Quantal – In Preparation; 0 CVEs; 2 upstream stable release(s); (368 commits)
    Current opened tracking bugs details:
  • http://people.canonical.com/~kernel/reports/kernel-sru-workflow.html

    For SRUs, SRU report is a good source of information:

  • http://people.canonical.com/~kernel/reports/sru-report.html

    Future stable cadence cycles:

  • https://wiki.ubuntu.com/RaringRingtail/ReleaseInterlock

Open Discussion or Questions? Raise your hand to be recognized

No open discussions.

Source: FULL ARTICLE at Planet Ubuntu

Ubuntu Kernel Team: Kernel Team Meeting Minutes – Jan 22, 2013

Meeting Minutes

IRC Log of the meeting.

Meeting minutes.

Agenda

20130122 Meeting Agenda

ARM Status

R/master: still working on multiplatform, USB finally works for omap and imx, i’m getting close to a first release

Release Metrics and Incoming Bugs

Release metrics and incoming bug data can be reviewed at the following link:

  • http://people.canonical.com/~kernel/reports/kt-meeting.txt

Milestone Targeted Work Items

   apw    hardware-r-kernel-config-review    9 work items   
      hardware-r-delta-review    4 work items   
      hardware-r-arm-kernel-maintenance    2 work items   
      hardware-r-kernel-misc    4 work items   
      foundations-r-x32-planning    2 work items   
      desktop-r-clean-old-kernels    1 work item   
   ogasawara    hardware-r-kernel-config-review    2 work items   
   ppisati    hardware-r-kernel-config-review    1 work item   
      hardware-r-kernel-version-and-flavors    2 work items   
      hardware-r-delta-review    1 work item   
   sconklin    hardware-r-arm-power-measurement    3 work items   
   rtg    hardware-r-delta-review    1 work item   

Status: Raring Development Kernel

We have rebased the Raring kernel to the latest v3.8-rc4 upstream
kernel and uploaded last week. Please test and let us know your
results.
Important upcoming dates:

  • Raring:

    • Mon Feb 18 – 13.04 Month 4 Milestone (~4 weeks)
  • Precise:

    • Thu Feb 14 – 12.04.2 Release (~3 weeks)

Status: CVE’s

Currently we have 35 CVEs on our radar, with 1 CVE added and 1 CVE retired this week.
See the CVE matrix for the current list:

  • http://people.canonical.com/~kernel/cve/pkg/ALL-linux.html

    The backlog hasn’t change this week:

  • http://people.canonical.com/~kernel/status/cve-metrics.txt

  • http://people.canonical.com/~kernel/cve/pkg/CVE-linux.txt

Status: Stable, Security, and Bugfix Kernel Updates – Quantal/Precise/Oneiric/Lucid/Hardy

As noted last week, we’re skipping a kernel SRU cadence to allow for an additional 3 weeks of testing for the kernel that will ship with the 12.04.2 point release.
Future stable cadence cycles:

  • https://wiki.ubuntu.com/RaringRingtail/ReleaseInterlock

Open Discussion or Questions? Raise your hand to be recognized

trijntje requested a review of bug 1075876.

Source: FULL ARTICLE at Planet Ubuntu

Adobe patches actively exploited ColdFusion vulnerabilities

Adobe released security patches for its ColdFusion application server on Tuesday, addressing four critical vulnerabilities that have been actively exploited by attackers since the beginning of January.

The company published a security advisory about the four vulnerabilities, identified as CVE-2013-0625, CVE-2013-0629, CVE-2013-0631 and CVE-2013-0632, on Jan. 4 and said at the time that it was aware of these flaws being exploited in attacks against its customers.

Two of the vulnerabilities allows attackers to bypass the normal authentication restrictions of a ColdFusion application server in order to gain administrative access. Another flaw allows unauthorized users to access restricted directories, while the fourth can result in information disclosure on a compromised ColdFusion server.

On Tuesday, Adobe released hotfixes for ColdFusion versions 10, 9.0.2, 9.0.1 and 9.0. The company recommends that customers update their installations using the instructions provided in a help document for their respective product version.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Ubuntu Kernel Team: Kernel Team Meeting Minutes – Jan 15, 2013

Meeting Minutes

IRC Log of the meeting.

Meeting minutes.

Agenda

20130115 Meeting Agenda

ARM Status

R/master: still working on multiplatform support: omap3/4 boots, i’m working on adding imx6 support now

Release Metrics and Incoming Bugs

Release metrics and incoming bug data can be reviewed at the following link:

  • http://people.canonical.com/~kernel/reports/kt-meeting.txt

Milestone Targeted Work Items

   apw    hardware-r-kernel-config-review    9 work items   
      hardware-r-delta-review    4 work items   
      hardware-r-arm-kernel-maintenance    2 work items   
      hardware-r-kernel-misc    4 work items   
      foundations-r-x32-planning    2 work items   
      desktop-r-clean-old-kernels    1 work item   
   ogasawara    hardware-r-kernel-config-review    2 work items   
   ppisati    hardware-r-kernel-config-review    1 work item   
      hardware-r-kernel-version-and-flavors    2 work items   
      hardware-r-delta-review    1 work item   
   sconklin    hardware-r-arm-power-measurement    3 work items   
   rtg    hardware-r-delta-review    1 work item   

Status: Raring Development Kernel

We have rebased the Raring kernel to the latest v3.8-rc3 upstream
kernel and uploaded last week. Please test and let us know your
results.
I also want to note that the 12.04.2 point release date has been moved
out by 2 weeks to Thurs Feb 14:

https://lists.ubuntu.com/archives/ubuntu-devel-announce/2013-January/001003.html

Important upcoming dates:

  • Raring:

    • Fri Jan 18 – 13.04 Month 3 Milestone (3 days)
    • Mon Feb 18 – 13.04 Month 4 Milestone (~5 weeks)
  • Precise:

    • Thu Feb 14 – 12.04.2 Release (~4 weeks)

Status: CVE’s

Currently we have 34 CVEs on our radar, with 0 CVEs added and 3 CVEs retired this week.
See the CVE matrix for the current list:

  • http://people.canonical.com/~kernel/cve/pkg/ALL-linux.html

    Overall the backlog has decreased slightly this week:

  • http://people.canonical.com/~kernel/status/cve-metrics.txt

  • http://people.canonical.com/~kernel/cve/pkg/CVE-linux.txt

Status: Stable, Security, and Bugfix Kernel Updates – Quantal/Precise/Oneiric/Lucid/Hardy

Here is the status for the main kernels, until today (January 08):

  • Hardy – Nothing in this cycle
  • Lucid – In -updates; 1 CVE; (2 commits)
  • Oneiric – In -updates; 2 CVEs; 4 upstream stable release(s); (78 commits)
  • Precise – In Testing; 3 CVEs; 1 upstream stable release(s); (104 commits)
  • Quantal – In Testing; 3 CVEs; 1 upstream stable release(s); (254 commits)
    Current opened tracking bugs details:
  • http://people.canonical.com/~kernel/reports/kernel-sru-workflow.html

    For SRUs, SRU report is a good source of information:

  • http://people.canonical.com/~kernel/reports/sru-report.html

    Future stable cadence cycles:

  • https://wiki.ubuntu.com/RaringRingtail/ReleaseInterlock

    The kernel SRU cadence cycle that was to start this week has been canceled. The kernels in -proposed will be used for the 12.04.2 release.

Open Discussion or Questions? Raise your hand to be recognized

No open discussion.

Source: FULL ARTICLE at Planet Ubuntu

Ubuntu Kernel Team: Kernel Team Meeting Minutes – Jan 08, 2013

Meeting Minutes

IRC Log of the meeting.

Meeting minutes.

Agenda

20130108 Meeting Agenda

ARM Status

R/master: working on multiplatform (and dtb) support, but except for that, nothing to report this week.

Release Metrics and Incoming Bugs

Release metrics and incoming bug data can be reviewed at the following link:

  • http://people.canonical.com/~kernel/reports/kt-meeting.txt

Milestone Targeted Work Items

   apw    hardware-r-kernel-config-review    9 work items   
      hardware-r-delta-review    4 work items   
      hardware-r-arm-kernel-maintenance    2 work items   
      hardware-r-kernel-misc    4 work items   
      foundations-r-x32-planning    2 work items   
      desktop-r-clean-old-kernels    1 work item   
   ogasawara    hardware-r-kernel-config-review    2 work items   
   ppisati    hardware-r-kernel-config-review    1 work item   
      hardware-r-kernel-version-and-flavors    2 work items   
      hardware-r-delta-review    1 work item   
   sconklin    hardware-r-arm-power-measurement    3 work items   
   rtg    hardware-r-delta-review    1 work item   

Status: Raring Development Kernel

We have rebased the Raring kernel to the latest v3.8-rc2 upstream
kernel. We have held off on uploading until we have resolved some DKMS
package build failures. Everyone should also review the
ubuntu-raring/dropped.txt file to review anything that may have
inadvertantly gone missing after the rebase.
Important upcoming dates:

  • Raring:

    • Fri Jan 18 – 13.04 Month 3 Milestone (1 week)
    • Mon Feb 18 – 13.04 Month 4 Milestone (~6 weeks)
  • Precise:

    • Thu Jan 10 – 12.04.2 Kernel Freeze (~2 days)
    • Thu Feb 14 – 12.04.2 Release (~5 weeks)
      We should have the last DKMS issues fixed tomorrow.
      We may have -rc3 by then as well.

Status: CVE’s

Currently we have 33 CVEs on our radar, with 4 CVE added and 2 CVEs retired since last meeting (11th Dec).
See the CVE matrix for the current list:

  • http://people.canonical.com/~kernel/cve/pkg/ALL-linux.html

    Overall the backlog has decreased slightly this week:

  • http://people.canonical.com/~kernel/status/cve-metrics.txt

  • http://people.canonical.com/~kernel/cve/pkg/CVE-linux.txt

Status: Stable, Security, and Bugfix Kernel Updates – Quantal/Precise/Oneiric/Lucid/Hardy

Here is the status for the main kernels, until today (January 08):

  • Hardy – Nothing in this cycle
  • Lucid – In Testing; 1 CVE; (2 commits)
  • Oneiric – In Verification; 2 CVEs; 4 upstream stable release(s); (78 commits)
  • Precise – In Verification; 3 CVEs; 1 upstream stable release(s); (104 commits)
  • Quantal – In Verification; 3 CVEs; 1 upstream stable release(s); (254 commits)
    Current opened tracking bugs details:
  • http://people.canonical.com/~kernel/reports/kernel-sru-workflow.html

    For SRUs, SRU report is a good source of information:

  • http://people.canonical.com/~kernel/reports/sru-report.html

    Future stable cadence cycles:

  • https://wiki.ubuntu.com/RaringRingtail/ReleaseInterlock

Open Discussion or Questions? Raise your hand to be recognized

No discussions.

Source: FULL ARTICLE at Planet Ubuntu