DotNetNuke User Account Security Bypass Vulnerability
Microsoft has issued a Security Bulletin Advance Notification indicating that the January release cycle will contain one bulletin, which will have a severity rating of Critical. The notification states that this Critical bulletin is for Microsoft Windows. Release of this bulletin is scheduled for Tuesday, January 13.US-CERT will provide additional information as it becomes available.
Cisco has released a Security Advisory to address a vulnerability in the Application Control Engine Global Site Selector (GSS). By sending a specially crafted sequence of DNS requests, a remote attacker may be able to cause a denial-of-service condition.US-CERT encourages users and administrators to review Cisco Security Advisory cisco-sa-20090107-gss and apply any necessary updates or workarou...