<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
  <channel>
    <title>Computer Science Security Alerts</title>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/</link>
    <description>Security Advisories for the Computer Science Community</description>
    <language>en</language>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>blosxom/2.1.2</generator>

  <item>
    <title>Patches for critical Adobe Reader/Acrobat vulnerability</title>
    <pubDate>Wed, 11 Jan 2012 12:11:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2012/01/11#0111.120946.929.8931</link>
    <category>/alerts/2012</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2012/0111.120946.929.8931</guid>
    <description>Security patches for current versions of Adobe Reader are now available.  These patches fix the critical vulnerability &lt;A HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2011/12/13#1213.102701.929.23543&quot;&gt;previously reported&lt;/A&gt;, a vulnerability that allows a maliciously crafted PDF file to run malicious commands as the person who is running Adobe Reader. For more information, please see Adobe security bulletins &lt;A HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb11-30.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb11-30.html&lt;/A&gt; and &lt;A HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb12-01.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-01.html&lt;/A&gt;.



</description>
  </item>
  <item>
    <title>Adobe Reader flaw on Windows and Mac, please upgrade to Adobe Reader X</title>
    <pubDate>Tue, 13 Dec 2011 10:31:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2011/12/13#1213.102701.929.23543</link>
    <category>/alerts/2011</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2011/1213.102701.929.23543</guid>
    <description>There is an unpatched vulnerability in Adobe Reader for Windows and Mac that allows a maliciously crafted PDF file to run commands as the person who is running Adobe Reader. Adobe claims that this vulnerability is being actively exploited on Windows. Adobe Reader X supports &quot;protected mode&quot;, which guards against this problem. While Adobe is working on a patch for current versions of Reader, it is not available yet.  In the meantime, Adobe recommends upgrading to the latest version of Adobe Reader X, and using its &quot;protected mode&quot; feature. Adobe Reader X is available at &lt;A HREF=&quot;http://get.adobe.com/reader&quot;&gt;http://get.adobe.com/reader&lt;/A&gt;. For more information, see &lt;A HREF=&quot;https://www.adobe.com/support/security/advisories/apsa11-04.html&quot;&gt;https://www.adobe.com/support/security/advisories/apsa11-04.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Malicious Word Document exploiting unpatched Windows hole</title>
    <pubDate>Thu, 03 Nov 2011 17:07:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2011/11/03#1103.170605.929.16395</link>
    <category>/alerts/2011</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2011/1103.170605.929.16395</guid>
    <description>A new &quot;0-day&quot; vulnerability in all versions of Microsoft Windows has been discovered, which is being actively exploited by the W32.Duqu worm. This worm exploits the bug by the use of a malicious Word document, which, if viewed on a Windows system, allows the worm to run arbitrary code on that system. A patch for this vulnerability has not yet been released by Microsoft.
&lt;br&gt;
Until this vulnerability is patched, please be particularly careful about viewing unsolicited Word documents obtained via web pages or via email, even if the sender appears to be a known and trusted person (the sender may be forged, or the sender&apos;s machine may be infected by the worm).  When emailed an unsolicited MS Word document, it may be prudent to confirm with the sender that the document was legitimately sent.
&lt;br&gt;
More information is available at &lt;A HREF=&quot;http://www.securityfocus.com/bid/50462&quot;&gt;http://www.securityfocus.com/bid/50462&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Beware of MacDefender malware for Apple Mac</title>
    <pubDate>Fri, 20 May 2011 14:56:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2011/05/20#0520.144833.929.16202</link>
    <category>/alerts/2011</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2011/0520.144833.929.16202</guid>
    <description>A piece of malicious software called MacDefender (or sometimes MacSecurity or MacProtector), targeting Apple Macintosh computers, is circulating widely.  This software attempts to install itself on a Mac when the user goes to certain web pages. It claims that &quot;Windows Security has found critical process activity on your PC and will perform a fast scan of system files&quot;.  It shows an animation of
a system scan that claims the computer is infected, and presents a popup inviting the user to remove the infection.  Even if the user clicks &quot;cancel&quot;, it will then download an installer and attempt to install. If the user provides his/her password, it will successfully install, and claim the mac is infected. While the software is running, it will unexpectedly display pornographic websites. The software is configured to automatically start itself if the machine is restarted. To &quot;remove&quot; the infection, one is told to &quot;register&quot; the software.  Registration requests a credit card number, which if provided will be sent to a malicious site: the purpose of this software is apparently to persuade the user to provide that number.
&lt;p&gt;
The downloading of the software can be prevented by forcing the browser to quit. Clicking &quot;cancel&quot; will not work because that button is configured to actually install the software.
&lt;p&gt;
Apple has not yet officially/publicly acknowledged this threat but it has been &lt;A HREF=&quot;http://www.thestar.com/news/canada/article/994563--mac-users-hit-by-scareware-that-brings-up-porn-websites?bn=1&quot;&gt;reported in the media&lt;/A&gt;. For more information, and for what to do if infected, see
&lt;A HREF=&quot;http://www.tuaw.com/2011/05/02/macdefender-malware-targeting-mac-users&quot;&gt;http://www.tuaw.com/2011/05/02/macdefender-malware-targeting-mac-users&lt;/A&gt;.

</description>
  </item>
  <item>
    <title>Security vulnerability in Adobe Flash Player now patched</title>
    <pubDate>Wed, 27 Apr 2011 16:08:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2011/04/27#0427.160635.929.29248</link>
    <category>/alerts/2011</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2011/0427.160635.929.29248</guid>
    <description>The security vulnerability &lt;A href=&quot;alerts.cgi/2011/04/12#0412.094503.929.28727&quot;&gt;previously reported&lt;/a&gt; has now been patched by Adobe for Windows and MacOSX.  Patched versions of Adobe Flash player are available for Windows at &lt;A href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Windows&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Windows&lt;/a&gt; and for Macintosh at &lt;A href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Macintosh&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Macintosh&lt;/A&gt;.  For more information, see &lt;a href=&quot;http://www.adobe.com/support/security/advisories/apsa11-02.html&quot;&gt;http://www.adobe.com/support/security/advisories/apsa11-02.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Unpatched security vulnerability in Adobe Flash Player being actively exploited through malicious MS Word attachments.</title>
    <pubDate>Tue, 12 Apr 2011 09:49:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2011/04/12#0412.094503.929.28727</link>
    <category>/alerts/2011</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2011/0412.094503.929.28727</guid>
    <description>There is a security vulnerability in current versions of Adobe Flash player that allows criminals to create a malicious flash file that will run commands of the attacker&apos;s choice on your computer when viewed.  This vulnerability is being actively exploited by malicious email. A .doc or .docx (Microsoft Word) file is attached to the email. Embedded in the .doc attachment is a flash file that runs malicious commands on Microsoft Windows systems.
&lt;p&gt;
The vulnerability exists in Adobe Acrobat Reader as well, which has an embedded flash player, but Adobe is not aware of any attacks yet against Acrobat Reader.  Adobe plans to release a patched version of Flash Player and Acrobat Reader soon. 
&lt;p&gt;
Until this problem is patched, if you receive an email you are not expecting that contains a Microsoft Word attachment, do not open the attachment, even if the email is from someone you know (the sender can be forged).  If it is from someone you know, contact them to inquire whether they in fact sent you the attachment. If they did, you may open it.  If not, please delete it immediately without opening it.
&lt;p&gt;
For more information, see &lt;A href=&quot;http://www.adobe.com/support/security/advisories/apsa11-02.html&quot;&gt;http://www.adobe.com/support/security/advisories/apsa11-02.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Unpatched security vulnerability in Internet Explorer being actively exploited</title>
    <pubDate>Thu, 16 Dec 2010 12:57:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/12/16#1216.124748.929.15358</link>
    <category>/alerts/2010</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/2010/1216.124748.929.15358</guid>
    <description>&lt;p&gt;A security vulnerability in Internet Explorer (IE) version 6, 7, and 8 has been discovered, and is being exploited in targeted attacks.  It allows a specially crafted web page to run commands on your computer if you browse the page using IE. Microsoft has not yet released a patch. If possible, while waiting for a patch for this problem, consider using another web browser, such as &lt;a href=&quot;http://www.getfirefox.com&quot;&gt;Firefox&lt;/a&gt;, &lt;a href=&quot;http://chrome.google.com&quot;&gt;Chrome&lt;/a&gt; or &lt;a href=&quot;http://www.apple.com/safari&quot;&gt;Safari&lt;/a&gt;. If you rely on certain web pages that render properly only when using IE, the &lt;a href=&quot;http://www.ietab.net&quot;&gt;IE Tab&lt;/a&gt; plugin for &lt;a href=&quot;http://www.getfirefox.com&quot;&gt;Firefox&lt;/a&gt; and &lt;a href=&quot;http://chrome.google.com&quot;&gt;Chrome&lt;/a&gt; will allow you to designate specific pages within &lt;a href=&quot;http://www.getfirefox.com&quot;&gt;Firefox&lt;/a&gt; or &lt;a href=&quot;http://chrome.google.com&quot;&gt;Chrome&lt;/a&gt; to be rendered by IE. &lt;/p&gt;

&lt;p&gt;For more information, see &lt;a href=&quot;http://threatpost.com/en_us/blogs/new-remotely-exploitable-bug-found-internet-explorer-121010&quot;&gt;http://threatpost.com/en_us/blogs/new-remotely-exploitable-bug-found-internet-explorer-121010&lt;/a&gt; and &lt;a href=&quot;http://www.kb.cert.org/vuls/id/634956&quot;&gt;http://www.kb.cert.org/vuls/id/634956&lt;/a&gt;.&lt;/p&gt;
</description>
  </item>
  <item>
    <title>Protecting Web Login Data</title>
    <pubDate>Fri, 10 Dec 2010 14:17:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/12/10#webintercept</link>
    <category>/advice</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/advice/webintercept</guid>
    <description>&lt;p&gt;Many websites, like &lt;a href=&quot;http://www.facebook.com&quot;&gt;Facebook&lt;/a&gt;, &lt;a href=&quot;http://www.twitter.com&quot;&gt;Twitter&lt;/a&gt; or &lt;a href=&quot;http://www.gmail.com&quot;&gt;Gmail&lt;/a&gt;, require a login and password.  After you type that password, the website assigns your web browser a cookie, which represents your identity on that site while you are logged in.  If someone else can intercept your cookie, they can do anything on that website that you can.  &lt;/p&gt;

&lt;p&gt;Unfortunately, not all websites that use cookies in this way also use encryption (such as SSL/HTTPS) to protect your cookie from being intercepted as it is transmitted. You can tell if a particular web site uses encryption, by checking to see that the URLs used always start with &lt;em&gt;https://&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;If the website is not using encryption, anyone with the right software may be able to intercept your cookie and use it to impersonate you. One example of a software program that can do this is Firesheep, a plugin for the &lt;a href=&quot;http://www.firefox.com&quot;&gt;Firefox&lt;/a&gt; web browser. Firesheep makes it very easy to capture any visible cookies on a
network, without any sign to the user that this is happening, and to use those cookies to impersonate someone on a website. &lt;a href=&quot;http://articles.cnn.com/2010-11-01/tech/firesheep.wifi.security_1_wi-fi-social-networking-sites-firefox&quot;&gt;Amy Gahran of CNN wrote an article&lt;/a&gt; about her experience using Firesheep on a coffee-shop&apos;s wireless network.&lt;/p&gt;

&lt;p&gt;To protect yourself from this sort of attack, it is important to choose secure
access to websites whenever available.  The &lt;a href=&quot;https://www.eff.org/https-everywhere&quot;&gt;HTTPS Everywhere&lt;/a&gt; plugin
for &lt;a href=&quot;http://www.firefox.com&quot;&gt;firefox&lt;/a&gt; makes this easy for many common sites: if the site offers both http and https access, &lt;a href=&quot;https://www.eff.org/https-everywhere&quot;&gt;HTTPS Everywhere&lt;/a&gt; will direct your &lt;a href=&quot;http://www.firefox.com&quot;&gt;firefox&lt;/a&gt; web browser to use &lt;em&gt;HTTPS&lt;/em&gt;. &lt;/p&gt;

&lt;p&gt;Another way to protect yourself is to use a Virtual Private Network (VPN).  Any CSLab user can request access to the &lt;a href=&quot;http://support.cs.toronto.edu/wiki/Networking/VPN&quot;&gt;CSLab VPN&lt;/a&gt;, which will encrypt all your network traffic and tunnel it to the CSLab network, from which it will then be forwarded on to its destination. The University of Toronto also has a &lt;a href=&quot;http://vpn.utoronto.ca&quot;&gt;VPN service&lt;/a&gt;, which works similarly.  Note, however, that if you use a VPN, your network traffic will be routed through the university, so please do not do anything that you would not do when connected to the university&apos;s networks.&lt;/p&gt;

&lt;p&gt;Finally, please use general good sense when using online websites.  For example, when you are finished using a website, log out.  Be especially vigilant when using a public network (such as a WIFI hotspot or an Internet Cafe). Watch for signs that your social networking and other web accounts have been used by someone else, and change your password (using &lt;em&gt;HTTPS&lt;/em&gt; of course) if you think it has been.&lt;/p&gt;
</description>
  </item>
  <item>
    <title>Serious Vulnerability in Adobe Acrobat, Reader 9.4 and earlier: patch available</title>
    <pubDate>Wed, 17 Nov 2010 12:33:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/11/17#acrobat94</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat94</guid>
    <description>Adobe has announced a serious vulnerability exists in Adobe Acrobat
and Acrobat Reader versions 9.4 and earlier, for all platforms
(Windows, Macintosh and UNIX).  It allows a specially crafted PDF
document to run arbitrary commands when viewed.  The vulnerability
has been fixed in version 9.4.1 of Acrobat and Acrobat Reader. Version
9.4.1 also incorporates an Adobe Flash security fix. Previous
versions should be upgraded. For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-28.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb10-28.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Critical Exploited Vulnerability in Adobe Acrobat and Acrobat Reader Fixed</title>
    <pubDate>Wed, 06 Oct 2010 16:37:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/10/06#acrobat-20100913fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat-20100913fix</guid>
    <description>A security update is now available for the critical vulnerability in all versions of Adobe Acrobat/Acrobat Reader (version 9.3.4 and earlier), &lt;A HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2010/09/15#flashplayer-20010913&quot;&gt;reported previously&lt;/A&gt;.
The vulnerability allows an attacker to crash your computer
and/or take control of it.  Adobe recommends that all users of Acrobat
and Acrobat reader versions 9.3.4 and earlier upgrade to version 9.4.
For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/bulletins/apsb10-21.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb10-21.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Fix for critical exploited vulnerability in Adobe Flash Player</title>
    <pubDate>Tue, 21 Sep 2010 09:56:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/09/21#flashplayer-20010913-fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer-20010913-fix</guid>
    <description>Adobe has released version 10.1.85.3 of its Flash player, which
fixes the critical exploited vulnerability in 10.1.82.76 and before, &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2010/09/15#flashplayer-20010913&quot;&gt;reported
earlier&lt;/A&gt;.  The vulnerability allows an attacker to crash the computer
running Flash Player, and/or take control of it.  Adobe recommends all
users of Flash Player upgrade to 10.1.85.3.  For more information, see
&lt;a HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-22.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb10-22.html&lt;/A&gt;
</description>
  </item>
  <item>
    <title>Critical Exploited Vulnerability in Adobe Flash Player, Acrobat Reader</title>
    <pubDate>Wed, 15 Sep 2010 13:07:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/09/15#flashplayer-20010913</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer-20010913</guid>
    <description>Adobe has reported that a critical vulnerability exists in current
versions of Adobe Flash Player (version 10.1.82.76 and earlier) and
Acrobat/Acrobat Reader (version 9.3.4 and earlier), for all platforms.
The vulnerability allows an attacker to crash your computer
and/or take control of it.  Adobe claims that there are reports the flash player
vulnerability is being actively exploited on Microsoft Windows.
Adobe promises fixes during the week of September 27th, 2010 for
Flash player, and during the week of October 4th, 2010 for Acrobat and
Acrobat Reader.  In the meanwhile, users of
&lt;A HREF=&quot;http://www.mozilla.org&quot;&gt;Mozilla&lt;/A&gt; web browsers (&lt;A HREF=&quot;http://www.mozilla.org/firefox&quot;&gt;Firefox&lt;/A&gt;, &lt;A HREF=&quot;http://www.seamonkey-project.org&quot;&gt;SeaMonkey&lt;/A&gt;) can restrict the automatic execution of Flash media using the &lt;A
HREF=&quot;https://addons.mozilla.org/en-US/firefox/addon/722/&quot;&gt;noscript
add-on&lt;/A&gt; .  For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/advisories/apsa10-03.html&quot;&gt;
http://www.adobe.com/support/security/advisories/apsa10-03.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Critical Vulnerability in Adobe Acrobat, Acrobat Reader</title>
    <pubDate>Mon, 23 Aug 2010 12:01:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/08/23#acrobat933</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat933</guid>
    <description>
Adobe has announced a vulnerability in Adobe Acrobat and Adobe Acrobat
Reader 9.3.3 (and earlier versions) for Windows, Macintosh and UNIX
(Reader only) and Adobe Acrobat and Adobe Acrobat Reader 8.2.3 (and
earlier versions) for Windows and Macintosh.  It allows a specially
crafted PDF document to run arbitrary commands when viewed.  The
vulnerability has been fixed in version 9.3.4 and 8.2.4 of Acrobat and
Acrobat Reader, and previous versions should be upgraded. For more
information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-17.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb10-17.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Critical Vulnerability in Adobe Flash Player, Adobe AIR </title>
    <pubDate>Mon, 16 Aug 2010 10:58:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/08/16#flashplayer20100816</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer20100816</guid>
    <description>Adobe has released patches for the critical vulnerability in Adobe
Flash Player versions 9 and 10, and in Adobe AIR. This vulnerability
allows a malicious person to create flash media that will run commands
of their choosing on your computer when viewed.  This vulnerability
can be exploited by convincing a user to open a webpage, a PDF file or
another document that contains embedded malicious flash media.  Adobe
urges users of Flash Player 10 to upgrade to version 10.1.82.76, users
of Flash Player 9 to upgrade to 9.0.280, and users of Adobe AIR to
2.0.3.  For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-16.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb10-16.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Windows Remote Code Execution flaw being actively exploited, fix available </title>
    <pubDate>Tue, 03 Aug 2010 15:52:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/08/03#win-sh</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/win-sh</guid>
    <description>A serious vulnerability in all current versions of Microsoft
Windows permits remote attackers to run programs of their choice on a
Windows computer if they can persuade the user to display the icon of a
specially crafted shortcut.  This problem is being actively
exploited.  An off-cycle patch has been released by Microsoft and
is available via &lt;A HREF=&quot;http://update.microsoft.com&quot;&gt;Windows
Update&lt;/A&gt;. For more information, see &lt;a
href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx&quot;&gt;http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Unpatched vulnerability in Adobe Flash now partially fixed</title>
    <pubDate>Thu, 10 Jun 2010 16:10:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/06/10#flashplayer10-0fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer10-0fix</guid>
    <description>The critical unpatched vulnerability in Adobe Flash
Player 10.0.45.2 and earlier versions for all platforms &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2010/06/08#flashplayer10-0&quot;&gt;mentioned
previously&lt;/A&gt; has now been partially addressed by Adobe.
Flash Player version 10.1, which does not have this vulnerability, has
been released for most platforms (including
Windows and Mac), and it is now available from the &lt;A
HREF=&quot;http://get.adobe.com/flashplayer/&quot;&gt;Adobe Flash Player Download
Centre&lt;/A&gt;.  The version of Flash Player 10.1 released by Adobe for
Windows is the same version as the previous release candidate of 10.1
(10.1.53.64), so if you have installed that release candidate, that
should be sufficient.  Adobe confirms that version 8 and earlier do not
possess this vulnerability.  However, version 9 is still vulnerable;
Adobe promises a patch by June 29th, 2010.  For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/advisories/apsa10-01.html&quot;&gt;
http://www.adobe.com/support/security/advisories/apsa10-01.html&lt;/A&gt;
</description>
  </item>
  <item>
    <title>Critical unpatched vulnerability in Adobe Flash, Reader and Acrobat</title>
    <pubDate>Tue, 08 Jun 2010 12:31:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/06/08#flashplayer10-0</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer10-0</guid>
    <description>Adobe has announced a critical unpatched vulnerability in Adobe Flash
Player 10.0.45.2 and earlier versions for all platforms.  This
vulnerability is also present in the embedded Flash functionality of
Adobe Acrobat and Acrobat Reader, for all platforms.  The vulnerability
allows an attacker to take control of an affected computer, and is
actively being exploited.  Adobe does not yet have a patch
for the problem. The Flash Player 10.1 release candidate at
&lt;A HREF=&quot;http://labs.adobe.com/technologies/flashplayer10&quot;&gt;
http://labs.adobe.com/technologies/flashplayer10&lt;A&gt;
is not vulnerable, so although it is in &quot;beta&quot;, it may be
worthwhile to consider running it.  For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/advisories/apsa10-01.html&quot;&gt;
http://www.adobe.com/support/security/advisories/apsa10-01.html&lt;/A&gt;
</description>
  </item>
  <item>
    <title>New Vulnerability in Adobe Acrobat, Acrobat Reader: patch available</title>
    <pubDate>Wed, 14 Apr 2010 14:57:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/04/14#acrobat931</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat931</guid>
    <description>Adobe has announced a vulnerability in recent versions of Adobe
Acrobat and Adobe Acrobat Reader, for all platforms (Windows, Macintosh
and UNIX).  It allows a specially crafted PDF document to run arbitrary
commands when viewed.  The vulnerability has been fixed in version 9.3.2
and 8.2.2 of Acrobat and Acrobat Reader, and previous versions should be
upgraded. For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-09.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb10-09.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Acrobat PDF Launch Action Can Be Used to Create Malicious PDF Documents</title>
    <pubDate>Wed, 07 Apr 2010 15:17:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/04/07#acrobatexec</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobatexec</guid>
    <description>The PDF data format has a little-used feature called &quot;Launch Action&quot;,
which allows a specially crafted PDF file to execute an external program.
&lt;A HREF=&quot;http://blog.didierstevens.com/2010/03/29/escape-from-pdf/&quot;&gt;It
has recently been shown &lt;/A&gt; that this feature can be used by an attacker
to run arbitrary programs of the attacker&apos;s choosing.  Adobe Acrobat and
Acrobat Reader will issue a warning when this feature is being invoked,
and will permit it to execute only if the user selects &lt;B&gt;Open&lt;/B&gt;.
The warning reads: &lt;EM&gt;The file and its viewer appliation are set to be
launched by this PDF file. The file may contain programs, macros, or viruses
that could potentially harm your computer.  Only open the file if you are
sure it is safe.  If this file was placed by a trusted person or program,
you can click Open to view the file.&lt;/EM&gt;.  We recommend that you always
select &lt;B&gt;Do Not Open&lt;/B&gt; when you see this message.

&lt;p&gt;Those who want to turn off the &quot;Launch Action&quot; feature
entirely can click &quot;Edit &gt; Preferences &gt; Categories &gt; Trust Manager &gt; PDF
File Attachments&quot; and then un-check the box that reads &quot;Allow opening of
non-PDF file attachments with external applications.&quot;

&lt;p&gt;Versions of the &lt;A HREF=&quot;http://www.foxitsoftware.com&quot;&gt;Foxit
PDF reader&lt;/A&gt; prior to 3.2.1 execute the
external program without issuing any warning, so &lt;A
HREF=&quot;http://www.foxitsoftware.com/pdf/reader/security.htm#0401&quot;&gt;Foxit
users should upgrade to 3.2.1 or later immediately&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Patch Available for Actively Exploited Internet Explorer Version 6 and 7 Vulnerability </title>
    <pubDate>Tue, 30 Mar 2010 13:50:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/03/30#ie-mar2010fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/ie-mar2010fix</guid>
    <description>
Microsoft has issued today a new patch for an actively exploited
vulnerability in Internet Explorer version 6 and 7 (IE6, IE7) 
&lt;A HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2010/03/11#ie-mar2010&quot;&gt; described previously&lt;/A&gt;.  The vulnerability allows an
attacker to run arbitrary commands as the user who is
running the web browser.  The patch has been made available through
&lt;A HREF=&quot;http://windowsupdate.microsoft.com&quot;&gt;Windows Update&lt;/A&gt;,
so Windows machines configured for automatic updates should receive the patch
automatically.  For more information, see &lt;A
HREF=&quot;http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Unpatched Internet Explorer Version 6 and 7 Vulnerability </title>
    <pubDate>Thu, 11 Mar 2010 15:50:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/03/11#ie-mar2010</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/ie-mar2010</guid>
    <description>An unpatched vulnerability in Internet Explorer version 6 and 7
(IE6, IE7) has been confirmed by Microsoft, and details about the
vulnerability have just been released. Public exploits are expected
imminently.  All versions of IE6 and IE7 are affected but IE8 (and IE5)
are not affected.  The vulnerability allows an attacker to run arbitrary
commands as the user who is running the web browser.  Microsoft has not
yet released a patch.  

&lt;p&gt; Microsoft makes some general suggestions at &lt;A
HREF=&quot;http://www.microsoft.com/protect&quot;&gt; http://www.microsoft.com/protect&lt;/A&gt;
that may help to reduce the likelihood and impact of an attack.  However,
we recommend the use of a web browser other than Internet Explorer,
such as &lt;a href=&quot;http://www.firefox.com&quot;&gt;www.firefox.com&lt;/a&gt;,
&lt;a href=&quot;http://www.google.com/chrome&quot;&gt;Google Chrome&lt;/a&gt;,
&lt;a href=&quot;http://www.apple.com/safari&quot;&gt;Apple Safari&lt;/a&gt;, or &lt;a
href=&quot;http://www.opera.com&quot;&gt;www.opera.com&lt;/a&gt;.  For more information, see
&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/981374.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/981374.mspx&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Recent Internet Explorer Vulnerability fixed</title>
    <pubDate>Fri, 22 Jan 2010 11:06:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/01/22#ie-jan2010fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/ie-jan2010fix</guid>
    <description>A fix is now available for the serious vulnerability
in all recent versions of Internet Explorer (IE) &lt;A
HREF=&quot;/support/security/alerts.cgi/2010/01/15#ie-jan2010&quot;&gt;reported
previously&lt;/A&gt;. Microsoft has disclosed in its patch release that the
vulnerability affected IE 5 too.  The fix (for all supported versions
of Internet Explorer) has been made available as an off-cycle
release via &lt;A HREF=&quot;http://update.microsoft.com&quot;&gt;Windows
Update&lt;/A&gt;.  For more information, please see &lt;A
HREF=&quot;http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx&lt;/A&gt;.

&lt;p&gt; Given the fact that Internet Explorer is very frequently targetted
for exploits, and good alternative browsers exist, at present we continue
to recommend in general that web browsers other than Internet Explorer
be used for one&apos;s default or everyday browser.  Alternatives to Internet
Explorer include &lt;a href=&quot;http://www.firefox.com&quot;&gt;www.firefox.com&lt;/a&gt;,
&lt;a href=&quot;http://www.google.com/chrome&quot;&gt;Google Chrome&lt;/a&gt;,
&lt;a href=&quot;http://www.apple.com/safari&quot;&gt;Apple Safari&lt;/a&gt;, or &lt;a
href=&quot;http://www.opera.com&quot;&gt;www.opera.com&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Unpatched Internet Explorer Vulnerability</title>
    <pubDate>Fri, 15 Jan 2010 13:54:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/01/15#ie-jan2010</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/ie-jan2010</guid>
    <description>An unpatched vulnerability in all recent versions of Internet Explorer
(IE) has been confirmed by Microsoft, and is being actively exploited.
All versions of IE 6, 7, and 8 are affected.  The vulnerability allows
an attacker to run arbitrary commands as the user who is running the
web browser.  Microsoft has not yet released a patch.
&lt;p&gt;
Microsoft makes some general suggestions at &lt;A
HREF=&quot;http://www.microsoft.com/protect&quot;&gt; http://www.microsoft.com/protect&lt;/A&gt;
that may help to reduce the likelihood and impact of an attack.  However,
we recommend the use of a web browser other than Internet Explorer,
such as &lt;a href=&quot;http://www.firefox.com&quot;&gt;www.firefox.com&lt;/a&gt;,
&lt;a href=&quot;http://www.google.com/chrome&quot;&gt;Google Chrome&lt;/a&gt;,
&lt;a href=&quot;http://www.apple.com/safari&quot;&gt;Apple Safari&lt;/a&gt;, or &lt;a
href=&quot;http://www.opera.com&quot;&gt;www.opera.com&lt;/a&gt;.  For more information, see
&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/979352.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/979352.mspx&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Fix for December 2009 Adobe Acrobat Vulnerability</title>
    <pubDate>Fri, 15 Jan 2010 13:36:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2010/01/15#acrobat93jsfix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat93jsfix</guid>
    <description>Adobe has released Acrobat and Acrobat Reader 9.3 that fixes the serious and actively exploited Javascript
vulnerability &lt;A HREF=&quot;
http://www.cs.toronto.edu/support/security/alerts.cgi/2009/12/17#dec2009acrobat92&quot;&gt; previously reported.&lt;/A&gt;. Users of Acrobat and Acrobat Reader 9.2 and
earlier are urged to upgrade to 9.3.  For users of Acrobat 8.x who are unable
to upgrade to 9.3, Adobe has released Acrobat 8.2, which also fixes
this vulnerability. For more information, see &lt;A HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb10-02.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb10-02.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system.&lt;BR&gt;</title>
    <pubDate>Thu, 17 Dec 2009 09:24:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/12/17#dec2009acrobat92</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/dec2009acrobat92</guid>
    <description>
 There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.&lt;BR&gt;


This vulnerabilty applies to Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX and
Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh.&lt;BR&gt;


It is possible to mitigate the issue by disabling JavaScript in Adobe Reader and Acrobat using the instructions below:&lt;BR&gt;

1. Launch Acrobat or Adobe Reader.&lt;BR&gt;

2. Select Edit&gt;Preferences&lt;BR&gt;

3. Select the JavaScript Category&lt;BR&gt;

4. Uncheck the &apos;Enable Acrobat JavaScript&apos; option&lt;BR&gt;

5. Click OK&lt;BR&gt;


Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue. &lt;BR&gt;


See &lt;a href=&quot;http://www.adobe.com/support/security/advisories/apsa09-07.html&quot;&gt;http://www.adobe.com/support/security/advisories/apsa09-07.html&lt;/a&gt; for more information.
</description>
  </item>
  <item>
    <title>Critical Vulnerabilities in Adobe Flash Player, Adobe AIR</title>
    <pubDate>Fri, 11 Dec 2009 10:49:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/12/11#flashplayer-multiple</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer-multiple</guid>
    <description>Adobe has reported that a number of critical vulnerabilities exist in widely
used versions of Adobe Flash Player versions 9 and 10, and Adobe AIR, that
allows a malicious person to create flash media that will run commands of
their choosing on your computer when viewed.  
This problem is fixed in Adobe Flash Player version
9.0.260, version 10.0.42.34, and Adobe AIR 1.5.3. Previous
versions are vulnerable.  For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-19.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb09-19.html&lt;/a&gt;, or
&lt;A HREF=&quot;http://www.publicsafety.gc.ca/prg/em/ccirc/2009/av09-051-eng.aspx&quot;&gt;
http://www.publicsafety.gc.ca/prg/em/ccirc/2009/av09-051-eng.aspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Unpatched Internet Explorer 6 and 7 Vulnerability</title>
    <pubDate>Tue, 24 Nov 2009 09:57:00 -0500</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/11/24#ie-css</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/ie-css</guid>
    <description>An unpatched vulnerability in Internet Explorer (IE) versions 6 and 7, the
default web browser in many versions of Microsoft Windows (Windows 2000,
XP, Server 2003, Server 2008, and Vista), has been publicly announced,
and an exploit for this vulnerability is available.  It allows an attacker
to run arbitrary commands as the user who is running the web browser.
Microsoft has not yet released a patch.  Internet Explorer version 8 is
not affected.

&lt;p&gt;Microsoft makes 
&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;some
configuration suggestions&lt;/a&gt; that can reduce the
impact of an attack.  However, we recommend the use of a
web browser other than Internet Explorer 6 or 7, such as &lt;a
href=&quot;http://www.microsoft.com/windows/Internet-explorer/default.aspx&quot;&gt;Internet
Explorer 8&lt;/a&gt;, &lt;a href=&quot;http://www.firefox.com&quot;&gt;www.firefox.com&lt;/a&gt;,
&lt;a href=&quot;http://www.google.com/chrome&quot;&gt;Google Chrome&lt;/a&gt;,
&lt;a href=&quot;http://www.apple.com/safari&quot;&gt;Apple Safari&lt;/a&gt;, or &lt;a
href=&quot;http://www.opera.com&quot;&gt;www.opera.com&lt;/a&gt;.  For more information, see
&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/977981.mspx&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Patches available for Vista SMB2 Remote Command Execution Vulnerability </title>
    <pubDate>Wed, 14 Oct 2009 09:38:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/10/14#smb2fix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/smb2fix</guid>
    <description>The security vulnerability in Windows Vista, Server 2008, and &lt;A
HREF=&quot;http://www.microsoft.com/windows/windows-7/get/download.aspx&quot;&gt;Windows
7 RC&lt;/A&gt; &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2009/09/17#smb2&quot;&gt;reported
previously&lt;/A&gt; has been patched.  The vulnerability was caused by a
bug in SMB v2.0 (the part of Windows that implements enhanced network
shares), allowing an attacker to create a specially crafted network
packet to run arbitrary commands on an affected Windows machine.  For more
information, see &lt;A
HREF=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx&quot;&gt;
http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx&lt;/A&gt;
</description>
  </item>
  <item>
    <title>Patch for A New Adobe Acrobat Vulnerability</title>
    <pubDate>Tue, 13 Oct 2009 16:13:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/10/13#acrobat92</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobat92</guid>
    <description>Adobe has released patches to all shipping versions of Acrobat and
Acrobat reader, for all platforms (Windows, Mac, UNIX) that fix
a newly identified vulnerability that would allow an attacker to
create a malicious PDF file that, when viewed with Acrobat, could run
arbitrary commands as the user viewing the file.  Adobe claims that
versions 9.2, 8.1.7 and 7.1.4 of Acrobat and Acrobat reader contain
the fix.  Users of previous versions of Acrobat on all platforms are
urged to upgrade to one of these versions. For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-15.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb09-15.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Vista SMB2 Vulnerability Allows Remote Command Execution</title>
    <pubDate>Thu, 17 Sep 2009 13:31:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/09/17#smb2</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/smb2</guid>
    <description>A security vulnerability in Windows Vista, Server 2008, and &lt;A
HREF=&quot;http://www.microsoft.com/windows/windows-7/get/download.aspx&quot;&gt;Windows
7 RC&lt;/A&gt; has been discovered.  A bug in SMB v2.0 (the part of Windows
that implements enhanced network shares) allows an attacker to create a
specially crafted network packet to run arbitrary commands on an affected
Windows machine.  &lt;A HREF=&quot;http://isc.sans.org/diary.html?storyid=7141&quot;&gt;An
exploit of this bug has already been made public.&lt;/A&gt;  Windows 2000, XP, and
the RTM (final) version of Windows 7 is not affected by this bug, but the
&lt;A HREF=&quot;http://www.microsoft.com/windows/windows-7/get/download.aspx&quot;&gt;RC
(beta/testing) version of Windows 7&lt;/A&gt; is apparently affected.  Microsoft
has not yet released a fix, but has published some workarounds at &lt;A
HREF=&quot;http://www.microsoft.com/technet/security/advisory/975497.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/975497.mspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Patches for Critical Vulnerability in Adobe Flash Player, Acrobat Reader </title>
    <pubDate>Fri, 31 Jul 2009 16:49:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/31#flashplayerfix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayerfix</guid>
    <description>Adobe has released patches for the critical vulnerability in Adobe
Flash Player versions 9 and 10, and in Adobe Acrobat and Acrobat Reader &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/28#flashplayer&quot;&gt;mentioned
previously.&lt;/A&gt; This vulnerability allows a malicious person to create
flash media that will run commands of their choosing on your computer
when viewed.  This vulnerability can be exploited in Adobe Acrobat reader
via a PDF file that contains embedded malicious flash media.  There are
reports that malicious PDF files that exploit this vulnerability are actively
propagating.  Adobe urges users of Flash Player 10 to upgrade
to version 10.0.32.18 or later, users of Flash Player 9 to
upgrade to 9.0.246.0 or later, and users of Adobe Reader
to upgrade to 9.1.3 or later.  For more information, see &lt;A
HREF=&quot;http://www.adobe.com/support/security/bulletins/apsb09-10.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb09-10.html&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Critical Exploited Vulnerability in Adobe Flash Player, Acrobat Reader</title>
    <pubDate>Tue, 28 Jul 2009 12:05:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/28#flashplayer</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/flashplayer</guid>
    <description>Adobe has reported that a critical vulnerability exists in current
versions of Adobe Flash Player versions 9 and 10 that allows a malicious
person to create flash media that will run commands of their choosing
on your computer when viewed.  This vulnerability can be exploited in Adobe
Acrobat reader via a PDF file that contains embedded malicious flash media.
There are reports that malicious PDF files that exploit this
vulnerability are actively propagating.  Adobe promises fixes on
July 30th and 31st.  In the meanwhile, as a partial workaround, Adobe has
supplied instructions that temporarily disable the ability of Acrobat Reader
to display flash media embedded in a PDF file.  For more information, see
&lt;a href=&quot;http://www.adobe.com/support/security/advisories/apsa09-03.html&quot;&gt;
http://www.adobe.com/support/security/advisories/apsa09-03.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Another Exploited ActiveX Vulnerability in Windows web browsers; workaround available</title>
    <pubDate>Tue, 14 Jul 2009 21:49:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/14#msofficeactivex</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/msofficeactivex</guid>
    <description>Another security vulnerability in Microsoft ActiveX for Internet Explorer
has been reported by Microsoft, and is being actively exploited.  This
vulnerability exploits a flaw in a Microsoft Office Web Component ActiveX 
control, and allows an attacker to create a malicious web page
which, when browsed by a Windows-based web browser, will run
commands of the attacker&apos;s choosing on the browsing machine.
While a fix is not yet available, Microsoft has published a
workaround that (temporarily) disables the vulnerable ActiveX
control(s).  This workaround is available from Microsoft at &lt;A
HREF=&quot;http://support.microsoft.com/default.aspx/kb/973472&quot;&gt;http://support.microsoft.com/default.aspx/kb/973472&lt;/A&gt;.
For more information, see &lt;A HREF=&quot;http://www.microsoft.com/technet/security/advisory/973472.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/973472.mspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Important Windows Patches Expected for Exploited DirectX, Quicktime Flaws </title>
    <pubDate>Fri, 10 Jul 2009 16:21:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/10#msvideofix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/msvideofix</guid>
    <description>Microsoft has announced that it plans to release six security
bulletins on Tuesday, July 14th, along with patches that will fix the &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2009/05/29#directx&quot;&gt;DirectX
DirectShow Quicktime flaw&lt;/A&gt; and the &lt;A
HREF=&quot;http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/07#msvideo&quot;&gt;Video
ActiveX Control flaw&lt;/A&gt;, both mentioned previously. These
both are being actively exploited via compromised web sites.
Other flaws discovered by Microsoft, not yet being actively
exploited, will also be fixed.  For more information, see &lt;A
HREF=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Unpatched Web-Exploitable Flaw in DirectX on Windows XP, 2003 and 2000 </title>
    <pubDate>Fri, 10 Jul 2009 16:06:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/10#directshow</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/directshow</guid>
    <description>An unpatched security vulnerability in DirectX on Windows XP, 2003 and 2000
has been announced.  It allows an attacker to create and distribute (e.g. via
a web site) a malicious QuickTime media file.  This malicious file, when
viewed (e.g. via a web browser) will run the attacker&apos;s commands
on the viewing machine.  Microsoft is aware of limited active attacks
that exploit this vulnerability.  While no patches have yet been
released, Microsoft has outlined some workarounds that will block
some of the ways that this vulnerability is presently being exploited.
For more information, and for workaround instructions, please see &lt;a
href=&quot;http://www.microsoft.com/technet/security/advisory/971778.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/971778.mspx&lt;/a&gt;
</description>
  </item>
  <item>
    <title>Exploited ActiveX Vulnerability in Windows web browsers; workaround available</title>
    <pubDate>Tue, 07 Jul 2009 09:24:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/07/07#msvideo</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/msvideo</guid>
    <description>A security vulnerability in the Microsoft Video ActiveX control
has been discovered and is being actively exploited.  This vulnerability
allows an attacker to create a malicious web page which, when browsed by
a Windows-based web browser, will run commands of the attacker&apos;s choosing
on the browsing machine.  While a fix is not yet available, Microsoft
has published a workaround that (temporarily) disables the vulnerable
ActiveX control(s).  This workaround is available from Microsoft at &lt;A
HREF=&quot;http://support.microsoft.com/kb/972890&quot;&gt;http://support.microsoft.com/kb/972890&lt;/A&gt;.
For more information, see &lt;A
HREF=&quot;http://www.kb.cert.org/vuls/id/180513&quot;&gt;http://www.kb.cert.org/vuls/id/180513&lt;/A&gt;
and &lt;A HREF=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot;&gt;
http://www.microsoft.com/technet/security/advisory/972890.mspx&lt;/A&gt;.
</description>
  </item>
  <item>
    <title>Significant vulnerability in Adobe Shockwave; update available.</title>
    <pubDate>Mon, 29 Jun 2009 09:29:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/06/29#shockwave</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/shockwave</guid>
    <description>Adobe has reported a significant vulnerability in Adobe Shockwave Player
version 11.5.0.596 and earlier. The vulnerability allows an attacker to
create a malicious shockwave file which, when viewed in an affected version
of Shockwave Player, runs arbitrary commands of the attacker&apos;s choice on
the machine running the player.  Because Shockwave Player is available as a
plug-in for web browsers, any web browser using a vulnerable version of the
player can be exploited by an attacker by making a malicious shockwave file
available on a web site, and luring the user of the web browser to that site.

&lt;p&gt;The flaw is fixed in Shockwave Player version 11.5.0.600 and later; please
update any installations of Shockwave Player accordingly by going to the
website &lt;a
href=&quot;http://get.adobe.com/shockwave/&quot;&gt;http://get.adobe.com/shockwave/&lt;/a&gt;.
For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-08.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb09-08.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Patch for A New Adobe Acrobat Vulnerability</title>
    <pubDate>Thu, 18 Jun 2009 14:59:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/06/18#acrobatmorefixes</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/acrobatmorefixes</guid>
    <description>Adobe has released patches to all shipping versions of Acrobat and
Acrobat reader that fix a newly identified vulnerability that would allow
an attacker to create a malicious PDF file that, when viewed with Acrobat,
could run arbitrary commands as the user viewing the file.  Adobe claims
that versions 9.1.2, 8.1.6 and 7.1.3 of Acrobat and Acrobat reader contain
the fix.  Users of previous versions of Acrobat on all platforms are
urged to upgrade to one of these versions. For more information, see &lt;a
href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-07.html&quot;&gt;
http://www.adobe.com/support/security/bulletins/apsb09-07.html&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>Critical Unpatched Mac OSX Java Vulnerability Now Fixed</title>
    <pubDate>Tue, 16 Jun 2009 12:37:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/06/16#macjavafix</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/macjavafix</guid>
    <description>The serious flaw in the Java virtual machine 
&lt;A HREF=&quot;/support/security/alerts.cgi/2009/05/27#macjava&quot;&gt;mentioned earlier&lt;/A&gt; is now fixed for Mac OS X 10.4.11 and 10.5.7. 
The flaw allows a Java applet to run
arbitrary commands as the user of the web browser viewing the applet.
This means a malicious web site could do harmful things to any unpatched
Macintosh that connects to it with a web browser capable of running Java
applets.

&lt;p&gt;Patches are presently available vi &lt;A
HREF=&quot;http://www.apple.com/softwareupdate/&quot;&gt;Apple Software Update&lt;/A&gt;, or
as &lt;A HREF=&quot;http://support.apple.com/downloads/Java_for_Mac_OS_X_10_5_Update_4&quot;&gt;&lt;EM&gt;Java for Mac OS X 10.5 Update 4&lt;/EM&gt;&lt;/A&gt; or &lt;A HREF=&quot;http://support.apple.com/downloads/Java_for_Mac_OS_X_10_4__Release_9&quot;&gt;&lt;EM&gt;Java for Mac OS X 10.4, Release 9&lt;/EM&gt;&lt;/A&gt;
from Apple&apos;s support site at &lt;A HREF=&quot;http://support.apple.com/downloads/&quot;&gt;
http://support.apple.com/downloads/&lt;/A&gt;.

&lt;p&gt;
Please note that Java and Java applets are different and distinct from
Javascript.  This particular flaw does not affect Javascript.
</description>
  </item>
  <item>
    <title>Multiple Security Flaws in Microsoft Office Applications: Patches Available</title>
    <pubDate>Wed, 10 Jun 2009 10:21:00 -0400</pubDate>
    <link>http://www.cs.toronto.edu/support/security/alerts.cgi/2009/06/10#office2</link>
    <category>/alerts</category>
    <guid isPermaLink="false">http://www.cs.toronto.edu/support/security/alerts.cgi/alerts/office2</guid>
    <description>A set of flaws in all current versions of Microsoft Office for Windows
and the Macintosh allow maliciously crafted MS Word or Excel
files to be provided by an attacker, for example, as an email
attachment or on a web page, which, when opened, allows the
attacker to run arbitrary commands as the user who opened
the file.  Patches are available from Microsoft via Automatic
Update/Windows Update, and for download from Microsoft&apos;s web site.
For more information, see Microsoft&apos;s security bulletin at &lt;a
href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx&quot;&gt;
http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx&lt;/a&gt;.
</description>
  </item>
  </channel>
</rss>

