Hotline : 800 2378
To contact CERT-MU send e-mail on - info[at]cert-mu.gov.mu
To report incident e-mail on - incident[at]cert-mu.gov.mu
    Constituency
    Authority
    World CERTs
    Email Abuse


Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
National Computer Board - (NCB)


 
     
CERT-MU Vulnerability Note VN-2010-6
  (05 March 2010)
  Microsoft Internet Explorer Unsafe Help File Handling Arbitrary Code Execution Vulnerability
   
CERT-MU Vulnerability Note VN-2010-5
  (26 February 2010)
  SVG Document Cross Domain Scripting Vulnerability in Mozilla Products
   
CERT-MU Vulnerability Note VN-2010-4
  (19 February 2010)
  Novell eDirectory eMBox SOAP Request Denial of Service Vulnerability
   
CERT-MU Advisory AD-2010-3
  (11 February 2010)
  Multiple Vulnerabilities in phpMyAdmin
   
CERT-MU Advisory AD-2010-2
  (05 February 2010)
  Multiple Vulnerabilities in Apache Tomcat
   
CERT-MU Vulnerability Note VN-2010-3
  (29 January 2010)
  Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
   
Microsoft Windows "MsgBox()" HLP File Execution Vulnerability
  (05 March 2010)
  Maurycy Prodeus has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the VBScript "MsgBox()" function allowing the execution of arbitrary HLP files. This can be exploited to execute an HLP file from e.g. an SMB share by tricking a user into pressing F1 when viewing a specially crafted website.
Successful exploitation allows execution of arbitrary commands via HLP macros. The vulnerability is confirmed with Internet Explorer 7 on a fully patched Windows XP SP3, and additionally reported in Windows 2000 and Windows Server 2003.

Click here to read more
   
Google Picasa JPEG Processing Integer Overflow Vulnerability
  (26 February 2010)
  Tielei Wang has discovered a vulnerability in Google Picasa, which can be exploited by malicious people to potentially compromise a user's system.
The vulnerability is caused due to an integer overflow error in

PicasaPhotoViewer.exe when processing JPEG files. This can be exploited to cause a heap-based buffer overflow by tricking a user into opening a specially crafted JPEG file and e.g. zooming in.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is confirmed in PicasaPhotoViewer.exe version 3.6.95.25, included in Google Picasa 3.6 build 95.25. Prior versions may also be affected.

Click here to read more
   
  more...
   
News & Events
 
Technology Update Workshop on Vulnerability Management

Safer Internet Day 2010

  more...
 
Virus Alert
 
W32.Pilleuz!gen4
(05 Mar 2010)
Trojan.Digitala
(26 Feb 2010)
Infostealer.Saluni
(19 Feb 2010)
 
  more...
 
 
 

Last Updated 05-Mar-2010
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +