Computer Security News and Alert Feeds

 

A compilation of Computer Security alerts, advisories, and news from a variety of sources, such as US CERT, McAfee, SANS, CIAC, and Microsoft.

 

-Latest Security News-
 

Rogue MD5 SSL Certificate Vulnerability

US-CERT is aware of a public report describing how MD5 collisions can be leveraged to generate rogue SSL CA certificates. A rogue CA certificate could be used by an attacker to generate valid SSL certificates for arbitrary web sites. Using these certificates in DNS redirection attacks, an attacker could spoof an SSL protected web site and obtain sensitive information.

US-CERT encourages users to review VU#836068 in the Vulnerability Notes Database. 

US-CERT will provide additional information as it becomes available.

 

SANS 2009

More than 35 courses, SANS top instructors, all in one great place! SANS 2009 is being held in Orlando, FL on March 2-9. Register today!

http://www.sans.org/info/35964/

 
 
-Recent Technical Security Alerts-
 

TA08-352A: Microsoft Internet Explorer Data Binding Vulnerability

Microsoft Internet Explorer Data Binding Vulnerability

http://www.us-cert.gov/cas/techalerts/TA08-352A.html

 

VU#836068: MD5 vulnerable to collision attacks

Weaknesses in the MD5 algorithm allow for collisions in output. As a result,attackers can generate cryptographic tokens or other data that illegitimately appear to be authentic.

http://www.kb.cert.org/vuls/id/836068

 

T-025: Vulnerabilities in Microsoft XML Core Services

A remote code execution vulnerability exists in the way that Microsoft XML Core Services parses XML content. The
vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens
specially crafted HTML e-mail. The risk is MEDIUM. An attacker who successfully exploited this vulnerability could take complete
control of an affected system.

http://doecirc.energy.gov/ciac/bulletins/t-025.shtml

 
MM_XSLTransform error.
http://www.microsoft.com/technet/security/advisory/RssFeed.aspx?securityadvisory is not a valid XML document.
DOMDocument::loadXML() [domdocument.loadxml]: Opening and ending tag mismatch: META line 3 and HEAD in Entity, line: 4
DOMDocument::loadXML() [domdocument.loadxml]: Opening and ending tag mismatch: META line 2 and HTML in Entity, line: 4
DOMDocument::loadXML() [domdocument.loadxml]: Premature end of data in tag META line 1 in Entity, line: 6
DOMDocument::loadXML() [domdocument.loadxml]: Premature end of data in tag HEAD line 1 in Entity, line: 6
DOMDocument::loadXML() [domdocument.loadxml]: Premature end of data in tag HTML line 1 in Entity, line: 6 in file http://www.microsoft.com/technet/security/advisory/RssFeed.aspx?securityadvisory.
<HTML><HEAD><META HTTP-EQUIV="Refresh" CONTENT="0.1">
<META HTTP-EQUIV="Pragma" CONTENT="no cache">
<META HTTP-EQUIV="Expires" CONTENT="-1">
</HEAD></HTML>