<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.91">
        <channel>
          <title>Check Point SmartDefense Service Advisories</title>
          <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          <description>The SmartDefense Service provides real-time updates and new attack protection capabilities for Application Intelligence, Web Intelligence, and Network defenses for various products.</description>
          <language>en-us</language>
          <copyright>http://www.checkpoint.com/copyright.html</copyright>
          <pubDate>Tue, 19 Aug 2008 06:24:30 PDT</pubDate>
          <lastBuildDate>August 13, 2008 07:07:59 PDT</lastBuildDate>
          <webMaster>webmaster@checkpoint.com</webMaster>
		  
          <image>
            <title>Check Point Software Technologies Ltd.</title>
            <url>https://sc1.checkpoint.com/www/images/layout/duke/logo-checkpoint.gif</url>
            <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          </image>

		  
          <item>
            <title>Security Best Practice: Adobe Flash Proxy Auto-Discovery DHCP Traffic Inspection</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/sbp-28-Sep.html</link>
            <severity>3</severity>
            <description><![CDATA[The Dynamic Host Configuration Protocol (DHCP) is a protocol used by networked devices to obtain the parameters necessary for operation in an Internet Protocol network. This protocol reduces system administration workload, allowing devices to be added to the network with little or no manual configuration.<br />
Adobe Flash is a multimedia software that is commonly used to create animation, advertisements, and various web page components.<br />
There is a feature in Flash Player 8 that allows auto discovery of an Edge server on a local network. When the connection is created a broadcast is sent on the DHCP port, the Edge server answers the request and the Flash Player reconnects through the edge server. <br />
<br />
The SmartDefense DHCP Protocol Enforcement protection is blocking this kind of pseudo-DHCP traffic by default.<br />
The update enables users to allow such traffic without inspection. 
]]></description>
            <pubDate>Wed, 01 Oct 2008 23:38:04 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Macrovision InstallShield Update Service Agent ActiveX Memory Corruption Vulnerability</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-22-Sep.html</link>
            <severity>3</severity>
            <description><![CDATA[A memory corruption vulnerability has been reported in Macrovision InstallShield Update Service. Macrovision InstallShield is a software tool for creating installers or software packages. By convincing a user to visit a specially crafted Web page, a remote attacker may trigger this vulnerability to execute arbitrary code on an affected system. 
]]></description>
            <pubDate>Wed, 01 Oct 2008 23:13:03 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Trend Micro OfficeScan Server cgiRecvFile Buffer Overflow</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-30-Sep.html</link>
            <severity>3</severity>
            <description><![CDATA[A buffer overflow vulnerability exists in Trend Micro OfficeScan, which if successfully exploited, allows execution of arbitrary code. Trend Micro OfficeScan is a centralized virus and security scan management system. The application fails to properly&nbsp;handle specially crafted ,user-supplied parameters, allowing an attacker to compromise a vulnerable computer. &nbsp;
]]></description>
            <pubDate>Mon, 06 Oct 2008 00:30:01 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Windows WRITE_ANDX SMB Processing Denial of Service</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-28-Sep.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote denial of service vulnerability was reported in Microsoft Windows. Windows fails to properly handle crafted Server Message Block (SMB) packets. SMB is Microsoft Windows native networking protocol, used for&nbsp;file sharing, network printing, and remote procedure calls. By sending a crafted SMB packet to the target system, a remote attacker may cause the system to stop responding, ultimately denying service to legitimate users. 
]]></description>
            <pubDate>Thu, 02 Oct 2008 02:09:22 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Trend Micro OfficeScan objRemoveCtrl ActiveX Control Buffer Overflow Vulnerability</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-06-Jul.html</link>
            <severity>3</severity>
            <description><![CDATA[A buffer overflow vulnerability has been reported in Trend Micro OfficeScan. Trend Micro OfficeScan is a centralized virus and security scan management system. By convincing a user to visit a specially crafted Web page, a remote attacker may trigger this vulnerability to execute arbitrary code on an affected system. 
]]></description>
            <pubDate>Wed, 01 Oct 2008 23:23:15 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Apache mod_proxy_ftp XSS Vulnerability</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-05-Octa.html</link>
            <severity>2</severity>
            <description><![CDATA[The Apache web server mod_proxy_ftp module is prone to a a cross-site scripting (XSS) vulnerability. The Apache mod_proxy_ftp module allows the Apache web server to act as a proxy for FTP sites. By sending a crafted URL to the module, an attacker can&nbsp;execute arbitrary HTML and script code in a user's browser session in the context of an affected site. 
]]></description>
            <pubDate>Mon, 06 Oct 2008 13:02:20 PDT</pubDate>
          </item>

		  
          <item>
            <title>Workaround for Windows Media Player Sampling Rate Vulnerability (MS08-054)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/sbp-31-Aug.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability was reported in Windows Media Player 11 which is an application for Windows that supports numerous video, audio, and image formats. A remote attacker could exploit this issue via a specially crafted server-side playlist (.wsx) file. A server-side playlist (SSPL) is a list that identifies what content is played for a client, the time at which it is played, and the order in which it is played. WSX is a document used as SSPL by Windows Media server. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system. 
]]></description>
            <pubDate>Wed, 01 Oct 2008 23:31:41 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against GDI+ BMP Integer Overflow Vulnerability (MS08-052)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-02-Sep.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been discovered in the way GDI+ handles integer calculations for Bitmap (BMP) files. BMP is an image file format used to store bitmap digital images. By persuading a user to open a specially crafted BMP image file, an attacker could take complete control of an affected system. 
]]></description>
            <pubDate>Sun, 05 Oct 2008 02:40:35 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against GDI+ VML Buffer Overrun Vulnerability (MS08-052)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-01-Sepb.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in the way that GDI+ handles Vector Markup Language (VML) files. VML is a set of XML tags used for exchange, editing, and delivery of vector graphics on the web. By convincing a user to visit a specially crafted Web page, a remote attacker may trigger this vulnerability to execute arbitrary code on an affected system. 
]]></description>
            <pubDate>Wed, 01 Oct 2008 23:36:29 PDT</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against GDI+ WMF Buffer Overrun Vulnerability (MS08-052)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2008/cpai-01-Sepa.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been discovered in the way GDI+ allocates memory for Windows Metafile (WMF) image files. WMF is a 16-bit metafile image format optimized for the Windows operating system that can contain both vector information and bitmap information. By persuading a user to open a specially crafted WMF image file, an attacker could take complete control of an affected system. 
]]></description>
            <pubDate>Sun, 05 Oct 2008 01:28:04 PDT</pubDate>
          </item>


        </channel>
      </rss>
