<?xml version="1.0" encoding="ISO-8859-1" ?>
		
		<rss version="2.0">
		<channel>
			<title>SecurePurdue - Advisory Alerts</title>
			<link>http://www.purdue.edu/securePurdue/</link>
			<description>Collaborating to create the university of the future through IT. Service quality, powerful partnerships, and a great place to work.</description>
			<language>en-us</language>
			<copyright>Copyright 2005 Purdue University</copyright>
			<docs>http://www.purdue.edu/securePurdue/</docs>
			<lastBuildDate>Fri, 02 Oct 2009 16:16:03 PST</lastBuildDate>
			<image>
				<title>SecurePurdue</title>
				<url>http://www.purdue.edu/securePurdue//images/loginBanner.gif</url>
				<link>http://www.purdue.edu/securePurdue/</link>
			</image>
		
			
			<item>
				<title>Microsoft Server Message Block (SMB) Vulnerability allows for Remote Code Execution</title>        
				<description>STEAM-ADVISORY NO. 2009091801
PURDUE UNIVERSITY SECURITY TEAM CIRT
Friday, September 18 16:10:00 EDT 2009
**** NOTICE ****
Update 2: Microsoft has released a &quot;Fix-it&quot; tool to automatically disable the SMBv2 service, which is presently the only known mitigation technique other than implementing firewall rules to block SMB traffic.
The tool can be downloaded from Microsoft&apos;s website at the following URL:

support.microsoft.com/kb/975497

(Copy and paste link into browser)

The MS Security advisory page further down in the Further Information and Resources section has also been updated to include a link to the Fix-It tool.

Update: Microsoft Server Message Block (SMB) Vulnerability allows for DoS and arbitrary remote code execution.
****************
A vulnerability exists in Microsoft Windows SMB2.0 that can be exploited remotely to cause system failure.  Currently this exploit is unpatched but workarounds are available.</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=283&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Fri, 02 Oct 2009</pubDate>
			</item>
		
			
			<item>
				<title>Security Advisory for Adobe Reader, Acrobat and Flash Player</title>        
				<description></description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=272&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Fri, 31 Jul 2009</pubDate>
			</item>
		
			
			<item>
				<title>ISC BIND Dynamic Update Denial of Service Vulnerability</title>        
				<description></description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=270&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Thu, 30 Jul 2009</pubDate>
			</item>
		
			
			<item>
				<title>Microsoft Office Web Components ActiveX Remote Code Execution Vulnerability</title>        
				<description>The Microsoft Office Web Components ActiveX control used by Internet Explorer contains a vulnerability that when exploited will allow an attacker to gain rights of the local user and allow remote code execution.

Microsoft KB973472
CVE-2009-1136</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=266&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Mon, 13 Jul 2009</pubDate>
			</item>
		
			
			<item>
				<title>Critical Unpatched Internet Explorer Issue</title>        
				<description></description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=240&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Fri, 12 Dec 2008</pubDate>
			</item>
		
			
			<item>
				<title>Phishing Emails Threatening Internet Service Disconnection Carry Virus</title>        
				<description>In the past couple of days we have been seeing a new batch of phishing emails which carry a virus infected attachment. Users should immediately delete any emails with a subject line &quot;Your internet access is going to get suspended&quot;</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=226&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Wed, 17 Sep 2008</pubDate>
			</item>
		
			
			<item>
				<title>Critical SSH Issue Involving Education and Research Institutions</title>        
				<description></description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=224&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Tue, 26 Aug 2008</pubDate>
			</item>
		
			
			<item>
				<title>Multiple reports of attempted and successful SQL injection attacks against campus web sites.</title>        
				<description></description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=219&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Fri, 18 Jul 2008</pubDate>
			</item>
		
			
			<item>
				<title>Adobe Acrobat and Reader Vulnerability affects Windows and Macs</title>        
				<description>Adobe has reported a critical vulnerability in Acrobat and Reader.  The vulnerability could allow a malicious user to crash an affected machine to gain full access.  Most versions are affected.</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=217&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Mon, 30 Jun 2008</pubDate>
			</item>
		
			
			<item>
				<title>Multiple Xserver and XInput Vulnerabilities</title>        
				<description>Multiple vulnerabilities have been discovered in the server code of the X window system, which can cause an assortment of overflows.  Local exploitation of these overflows cause the X server to crash or allow the execution of arbitrary code in certain situations.</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=193&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Wed, 23 Jan 2008</pubDate>
			</item>
		
			
			<item>
				<title>Critical Vulnerabilities In Adobe Flash Content May Lead to Cross-Site Scripting (XSS) Attacks</title>        
				<description>Critical vulnerabilities in Adobe Flash content have been found which leave potentially hundreds of thousands of websites and a considerable percentage of major Internet sites susceptible to Cross-Site Scripting (XSS) attacks that would allow malicious individuals to steal personal details of visitors.</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=191&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Mon, 14 Jan 2008</pubDate>
			</item>
		
			
			<item>
				<title>Adobe Flash Player: Multiple Vulnerabilities</title>        
				<description>Adobe Flash Player and Flash Plugin have been found to have multiple
vulnerabilities which could allow an attacker to remotely execute code
on a vulnerable system, obtain sensitive information via browser
keystrokes, and allow cross-site request forgery.  These
vulnerabilities affect all users of Adobe Flash Player regardless of
platform (Win, Mac, Solaris, and Linux).  A new version that addresses
the security issues has been released by Adobe.</description>
				<link>http://www.purdue.edu/securePurdue//news/detail.cfm?NewsID=138&amp;tm=commons_news</link>
				<author>Advisory Alerts</author>
				<pubDate>Tue, 17 Jul 2007</pubDate>
			</item>
		
			</channel>
			</rss>
		
