Adobe, Apple, Microsoft and Mozilla all released updates on Tuesday to fix critical security flaws in their products. Adobe issued a patch that corrects four vulnerabilities in Shockwave Player, while Redmond pushed updates to address four Windows flaws. Apple slipped out an update that mends at least 17 security holes in its version of Java, and Mozilla issued yet another major Firefox release, Firefox 8.
The only “critical” patch from Microsoft this month is a dangerous Windows flaw that could be triggered remotely to install malicious software just by sending the target system specially crafted packets of data. Microsoft says this vulnerability may be difficult to reliably exploit, but it should be patched immediately. Information on the other three flaws fixed this week is here. The fixes are available via Windows Updates for most supported versions of the operating system, including XP, Vista and Windows 7.
Adobe’s Shockwave update also fixes critical flaws, but users should check to see if they have this program installed before trying to update it. To test whether you have Shockwave installed, visit this page; if you see an animation, it’s time to update. If you see a prompt to install Shockwave, there is no need to install it. Mozilla Firefox users without Shockwave Player installed may still see “Shockwave Flash” listed in the “Plugins” directory of the browser; this merely indicates that the user has Adobe’s Flash Player installed.
The vulnerabilities fixed by this update exist in versions of Shockwave 11.6.1.629 and earlier. The latest version, v. 11.6.3.633, is available here. As I noted earlier this year, I haven’t had Shockwave on my system for some time now and don’t seem to have missed it. I’m sure it has its uses, but to me Shockwave is just another Adobe program that requires constant care and feeding. What’s more, like Adobe’s Flash Player, Shockwave demands two separate installation procedures for IE and non-IE browsers.
Hat tip to the SANS Internet Storm Center for the heads up on the Java fix from Apple. This update, available via Software Update or Apple Downloads, essentially brings Snow Leopard and Lion up to date with the Oracle patches released last month in Java 6 Update 29 (Apple maintains its own version of Java).
If you use Mozilla Firefox or Thunderbird, you may have noticed that Mozilla is pushing out another major upgrade that includes critical fixes to these programs; both have now been updated to version 8. If you’re still running Firefox version 3.6.x, Mozilla has updated that to 3.6.24 (if anyone can help decipher Mozilla’s timeline for exactly how long it will continue to support this workhorse version of Firefox, please drop a line in the comments below). Perhaps I’m becoming a curmudgeon, but I’m growing weary of the incessant update prompts from Firefox. It seems that almost every time I start it up it’s asking to restart the browser or to remove plugins that no longer work with the latest version. I’ve been gradually transitioning more of my work over to Google Chrome, which seems faster and updates the browser and any installed plugins silently (and frequently patches oft-targeted plugins like Flash Player even before Adobe officially releases the update).
Read More...
-=WELCOME IN MY BLOG=-
10/11/11
Adobe, Apple, Microsoft & Mozilla Issue Critical Patches
18/10/11
Knube Howto #1: Patch Negative One In Aircrack [video]
14/10/11
Apple Ships Mammoth Security Update for OS X
Apple released OS X Lion v10.7.2 yesterday along with an absolutely enormous security update that patches some 80 bugs in the various iterations of Apple’s operating system. One of the patches fixes a highly critical vulnerability that enables an attacker to run code on a remote machine with a simple exploit.
The vulnerability, CVE-2011-3230, which was discovered by researcher Aaron Sigel, lies in the way that Safari handles certain URLs.
"This allows you to send any "file:" url to LaunchServices, which will run binaries, launch applications, or open content in the default application, all from a web page. The only caveat is that since LaunchServices will check for the quarantine bit, you cannot directly push a binary to the browser and launch it," Sigel said in his advisory. The other bugs fixed in the OS X update could lead to denials of service, escalation of privileges, and arbitrary code execution to name a few. In addition, the patch fixes various password authentication problems ranging from password interception to log-ins occurring without passwords.
The update resolves one or more vulnerabilities in all of the following programs: Apache, Application Firewall, ATS, BIND, Certificate Trust Policy, CFNetwork, CoreFoundation, CoreMedia, CoreProcesses, CoreStorage, File Systems, IOGraphics, iChat Server, Kernel, libsecurity, Mailman, MediaKit, Open Directory, PHP, postfix, python, QuickTime, SMB File Server, Tomcat, User Documentation, Web Server, andX11.
Among the most noteworthy fixes are, Multiple DoS vulnerabilities in BIND, the resolution of a cookie storage and configuration bug in Safari, the addition of a number of trusted certificates to Apple’s list of system roots, a number of open directory password issues that could allow users to log-in without passwords, easily change or read other’s passwords, and a bug in the file systems that could allow an attacker in a privileged network position the ability to manipulate HTTPS server certificates, leading to the disclosure of sensitive data.
This latest update caps off a busy week for the world’s largest technology company, who released iOS 5 yesterday and another enormous patch for their music player, iTunes on Tuesday.
Again, this is an enormous patch, so please read the ‘About the security content of OS X Lion v10.7.2 and Security Update 2011-006’ for all the specific details. You can also download the update there.
Read More...
Mac OS X security update causes crashes, say experts
Apple's massive security update addresses more than 70 vulnerabilities, but installing the patches could render computers unbootable
Apple has released a massive security update for Mac OS X along with a new version of its OS, however, according to several reports, installing the patches could render computers unbootable.
The Mac OS X Security Update 2011-006 addresses more than 70 vulnerabilities in core components, as well as third-party products bundled by default with the OS.
[ iOS 5 upgrade error reports have flooded Apple's support forum. | Check out InfoWorld's quick guide to what's new in iOS 5. | Discover the key Mac, iOS, and Apple tech trends for business users. Read InfoWorld's Technology: Apple newsletter. ]
Many of the flaws have the highest severity rating assigned to them and can result in arbitrary code execution through a remote attack vector. Two security issues were patched in the Mac OS X kernel, one in CoreStorage, two in CoreMedia, while others were in CoreProcesses, CoreFoundation, CFNetwork, and even the application firewall.
With this update Apple also played security catch-up with many third-party software packages that provide important functionality, such as Apache HTTPD, BIND, PHP, Tomcat, Mailmain, Python, or libpng.
QuickTime, a central application in Apple's ecosystem, was also updated in this release to address 11 different vulnerabilities. However, some of them only affect OS X Snow Leopard.
Despite the benefits of the security update, users should carefully weigh whether to install it. That's because, according to some reports, the update can result in serious issues.
"Apple OSX Security Update makes macbook kernel panic at boot," warned security researcher Dragos Ruiu Thursday on Twitter. He later confirmed that other users have experienced similar problems, particularly on systems with Lion/Snow dual-boot configurations. "If you have two or more os partition on mbp [MacBook Pro] it breaks," the security expert said.
Meanwhile, Graham Cluley, a senior technology consultant at Mac OS antivirus provider Sophos, reported installation errors for the newly released iOS 5 mobile OS. He couldn't confirm the Mac OS X boot issues, but advised users to postpone updating if they believe they might be affected.
"My advice would be to contact Apple technical support - and see if they have a resolution for the problem. If you suspect you may be impacted by the issue it may be wise to hold off installing the security update until Apple has confirmed if it has fixed it," Cluley said.
Apple's new Mac OS X Lion v10.7.2 contains most of the security patches from Security Update 2011-006, and there are reports that it too is causing issues for adopters. Reports like "After updating to Lion 10.7.2 System now hangs on boot" or "Mac forced me to restart after updating to 10.7.2" started appearing on the Apple support forums.
One user suggests that resetting the PRAM after the update might solve the problem. Apple did not immediately respond to a request for comment.
Read More...
12/10/11
iTunes 10.5 released to fix 79 vulnerabilties on Windows, OS X to follow
Apple released a mammoth update to iTunes for Windows today bumping the version number to 10.5. The update fixes 79 vulnerabilities in iTunes, although not for Mac OS X users.The largest number of fixes, 73, affect WebKit and could cause remote code execution. WebKit is used to render HTML content from the iTunes store.
Fortunately these vulnerabilities can only be exploited through a man-in-the-middle attack while using iTunes.
Other fixes resolve remote code execution flaws in CoreFoundation, ColorSync, CoreAudio, CoreMedia and ImageIO.
According to SANS Internet Storm Center, Apple will be releasing fixes for OS X users as part of the yet unreleased updates for 10.6 (Snow Leopard) and 10.7 (Lion). Users of OS X 10.5 and earlier will be left unprotected.
iTunes 10.5 for OS X is available as well, but only includes new features, not security fixes. iTunes 10.5 introduces iCloud support, wireless syncing and support for iOS 5.One piece of good news is that iTunes no longer requires QuickTime on Windows machines. If you don't need/want QuickTime this might be a great opportunity to remove it, reducing the number of applications you need to keep patched.
I hope we see an update for Mac OS X soon as Apple still have not fixed the six week old directory services vulnerability and the three week old password change vulnerability.
If you are a Mac user interested in protecting your computer consider downloading our Sophos Anti-Virus for Mac Home Edition for free protection from viruses, Trojans and other malware.
Internet Explorer 9 haunted by 'critical' security vulnerabilities
Summary: Microsoft fixes drive-by download flaws in the latest version of its dominant Internet Explorer browser and warns that exploits could emerge within 30 days.
Microsoft’s shiny new Internet Explorer 9 browser contains critical security vulnerabilities that expose users to drive-by download attacks, the company warned today.
The IE warning highlights this month’s batch of security patches from Microsoft where the company shipped eight security bulletins (two critical, six important) to cover gaping holes in Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG and Microsoft Host Integration Server.follow Ryan Naraine on twitter
According to Microsoft, the IE vulnerabilities could be exploited if a user simply surfs to a maliciously rigged website.
The IE update (MS11-081), available for all users or Microsoft Windows and all versions of Internet Explorer, covers at least eight documented security holes in the world’s most widely used browser. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The update fixes the vulnerabilities by modifying the way that Internet Explorer handles objects in memory and the way that Internet Explorer allocates and accesses memory, Microsoft explained.
Microsoft is urging all Windows users to treat this with the utmost priority because of the likelihood of reliable exploit code within 30 days. Malicious hackers typically reverse-engineer the patches to identify the flaws and write exploits immediately to launch malware attacks.
The second “critical” update (MS11-078) addresses a vulnerability in .NET Framework and Microsoft Silverlight that could expose users to remote code execution attacks.
The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.
Microsoft warns that a victim could be exploited if he/she browses to a malicious webpage with aSilverlight-enabled browser.
As with the IE patch, Microsoft exploits to see “reliable exploits” for Silverlight 3 over the next 30 days.
The company also raised an alert for a third bulletin (MS11-077) that covers at least four documented vulnerabilities in Windows kernel-mode drivers (Win32k.sys).
The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment, the company explained.
The security update addresses the vulnerabilities by correcting the way that the Windows kernel-mode drivers validate input passed from user mode, handle the TrueType font type, allocate the proper buffer size before writing to memory, and manage kernel-mode driver objects.
This month’s Patch Tuesday batch also covers five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL.
It also provides fixes for a solitary flaw in the Microsoft Windows Ancillary Function Driver (AFD) and two publicly disclosed vulnerabilities in Host Integration Server.
The Host Integration Server vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478.
Read More...
Microsoft Patches 22 Security Holes, 12 Highly Exploitable, in October
Microsoft released eight security updates on Tuesday, repairing 22 security holes in its October patch release, with 12 of the 22 described as "consistently exploitable" by the company.
The October patch release includes two bulletins that Microsoft rated "critical" to patch holes. The two cumulative updates, reparing a clutch of vulnerabilities in the Internet Explorer Web browser and .NET and Silverlight frameworks could be used to enable remote attacks in which malicious code was planted and run on vulnerable systems, Microsoft said.
The release follows guidance released on October 7. Microsoft warned that the critical holes could allow remote attackers to run malicious code on vulnerable systems, enabling remote attacks using drive by download Web pages and other means. MS11-081, one of the two critical patches, fixes eight vulnerabilities in Internet Explorer Versions 6 through 9 running on a variety of Windows versions. The vulnerabilities, reported to Microsoft by third party vulnerability researchers working at McAfee, TipppingPoint, Google and other firms, include several methods for triggering remote code execution vulnerability using Internet Explorer elements that control how IE accesses an object that has been deleted. According to Microsoft, the vulnerability could be used to corrupt memory on the system running IE in such a way that an attacker could execute arbitrary code in the context of the logged-on user.
MS11-078, the second patch that was rated critical, fixes a remote code execution hole affects a wide range of versions of .NET Framework and Microsoft Silverlight for most supported versions of the Windows- and Windows Server operating systems. According to Microsoft, the patched vulnerabilities could have allowed an attacker to create an XAML Browser Application (XBAP) or Silverlight application to run malicious code on end user systems. The holes could also allow remote code execution on a server system running Internet Information Server (IIS), assuming the attacker could upload a malicious ASP.NET page to the vulnerable IIS server, and that the server was configured to run ASP.NET pages.
As has been noted, however, Microsoft's severity rating system is biased towards vulnerabilities that might be used to power self replicating malicious code, not necessarily based on its ability to be used in malicious attacks. The company's exploitability index is a better measure of how likely a particular vulnerability is to be used in that way.
According to the Exploitability Index Microsoft included with its October patch, MS11-076, -077 and -079 also appear to be more serious than their "Important" rating would suggest. The -076 patch - a fix for the Windows Media Center application - contains a fix for an library loading vulnerability with an exploitability rating of "1", indicating that Microsoft's analysis suggests that an attacker could consistently exploit that vulnerability against the latest releases of affected software. MS11-079, a cumulative patch for versions of Microsoft's Office Suite and related applications, contains fixes for four vulnerabilities with an exploitability rating of "1" against current versions of the company's software.
Read More...
04/10/11
Google Pushes Update For Chrome to Fix Faulty Microsoft Malware Detection
Google has pushed out an update for its Chrome browser that fixes a problem caused by the incident last week in which Microsoft Security Essentials mistakenly detected the browser as the Zeus bot and removed it from some machines. The update should automatically fix any damaged Chrome installations.
The problem was caused by an erroneous update in the Microsoft Security Essentials antimalware tool that on Friday began detecting the Chrome file as a piece of malware called "PWS:Win32/Zbot", which is another name for the Zeus bot, the infamous banking Trojan that has been wreaking havoc for several years. Users immediately began noticing the problem and Microsoft pushed out an emergency update to the antimalware suite to fix the issue on their end.
But some users still had problems and couldn't get Chrome to work again, even after it was reinstalled. So Google has released an update for the browser that will repair it. The company said that if the browser is running fine on your PC, then there's no need to take any further actions. The new update to Chrome should prevent users from having to uninstall and reinstall Chrome themselves.
There's more information on the new updates on the Google Chrome Releases blog. The company also has step-by-step instructions for users who need to know how to manually uninstall and reinstall the browser.
Read More...
02/10/11
Microsoft security update treats Chrome as malware
Redmond releases same-day correction, but not before Windows Security purges Chrome from user systems

Coincidentally (of course), the faux pas comes on the heels of news from StatCounter that Chrome is poised to overtake Firefox this year as the No. 2 most-popular browser in the world.
"Google Chrome has been incorrectly marked as malware by Microsoft security software. Please update your Microsoft security software to version 1.113.672.0, which resolves this issue," according to an alert over at the over at the Google Chrome forums.
Microsoft, meanwhile, posted a somewhat vague alert of its own, starting that it had released a security update today with "an incorrect detection for PWS:Win32/Zbot," a password-stealing Trojan that monitors for visits to certain websites. However, Microsoft neglected to specify in its update just what impact this "incorrect detection" had; the update doesn't even mention Chrome. Evidently, Microsoft would prefer to let Chrome users and Google deal with figuring why, exactly, Microsoft Security Center suddenly started deeming Chrome a security threat and purging it from users' systems.
To Microsoft's credit, it did issue a second update the same day that addresses the error: Signature versions 1.113.672.0 and higher include this update.
One affected Chrome user, with the screen name chasd.harris, started a thread on the Google Chrome forums to report his experience. "I have been using Chrome on my office PC for over a year. This morning, after I started up the PC, a Windows Security box popped up and said I had a security problem that needed to be removed," he wrote. "I clicked the Details button and saw that it was 'PWS:Win32/Zbot.' I clicked the Remove button and restarted my PC. Now I do not have Chrome. It has been removed or uninstalled. The Chrome.exe file is gone. Was there really a problem, or is this just a way for Microsoft to stick it to Google?"
Google reps also provided instructions as to how to go about re-installing Chrome.
- Check that Chrome has been uninstalled.
- Go to Microsoft Security Essentials (MSE) and update, then verify that the version has a signature of 1.113.672.0 of higher.
- Reinstall Chrome.
- Perform a full scan of MSE again.
Read More...
30/09/11
Cisco Patches Slew of IOS Bugs
Cisco has patched a string of serious vulnerabilities in its IOS networking software, including some that could be used for remote code execution, and also fixed flaws in some of its other products. In all, Cisco released 10 advisories, nine of which concerned IOS vulnerabilities.
The most serious of the flaws in IOS, the company's ubiquitous network operating system, is a bug in the way that the Smart Install application works on some Cisco Catalyst switches. The problem can allow an attacker to run arbitrary code on the switch.
"A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Smart Install uses TCP port 4786 for communication. An established TCP connection with a completed TCP three-way handshake is needed to be able to trigger this vulnerability," Cisco said in its advisory.
Several of the other vulnerabilities that Cisco patched in IOS are denial-of-service flaws. IN addition to those problems, there also is a serious issue in the Identity Services Engine, which has a default set of credentials for its underlying database.
"The Cisco ISE contains a set of default credentials for its underlying database. A remote attacker could use those credentials to modify the device configuration and settings or gain complete administrative control of the device," the advisory says.
The full list of Cisco advisories is available on the Cisco security support site.
Read More...
29/09/11
Mozilla Fixes 11 Security Bugs in Firefox 7 Release
Firefox 7 was pushed out on Wednesday and users who have the automatic update functionality in place should see it downloaded to their machines soon. The new browser is designed to run much faster than even the version that was released just six weeks ago, thanks to improvements in the way that Firefox handles memory usage.
"Firefox 7 now uses much less memory than previous versions: often 20% to 30% less, and sometimes as much as 50% less. This means that Firefox and the websites you use will be snappier, more responsive, and suffer fewer pauses. It also means that Firefox is less likely to crash or abort due to running out of memory," Mozilla officials wrote in a blog post.
" Mozilla engineers started an effort called MemShrink, the aim of which is to improve Firefox’s speed and stability by reducing its memory usage. A great deal of progress has been made, and thanks to Firefox’s faster development cycle, each improvement made will make its way into a final release in only 12–18 weeks. The newest update to Firefox is the first general release to benefit from MemShrink’s successes, and the benefits are significant."
In addition to the memory improvements, there are also are fixes for 11 security vulnerabilities in Firefox 7, including eight critical flaws.
The full list of security fixes:
MFSA 2011-45 Inferring Keystrokes from motion data
MFSA 2011-44 Use after free reading OGG headers
MFSA 2011-43 loadSubScript unwraps XPCNativeWrapper scope parameter
MFSA 2011-42 Potentially exploitable crash in the YARR regular expression library
MFSA 2011-41 Potentially exploitable WebGL crashes
MFSA 2011-40 Code installation through holding down Enter
MFSA 2011-39 Defense against multiple Location headers due to CRLF Injection
MFSA 2011-38 XSS via plugins and shadowed window.location object
MFSA 2011-37 Integer underflow when using JavaScript RegExp
MFSA 2011-36 Miscellaneous memory safety hazards (rv:7.0 / rv:1.9.2.23)
On a related note, security researchers are warning that some black hat SEO campaigns are again preying on the new Firefox release to push unsuspecting users to malicious sites. Searching for "Firefox download" can lead to some of these malicious ads on Bing, specifically, warns GFI Labs's Christopher Boyd. You're better off simply going to the official Mozilla Firefox download page or having Firefox download the update automatically. Read More...
Mozilla puts Firefox 7 on memory diet, patches 11 bugs
The company also continues to support Firefox 3.6 with security updates for enterprise users
Mozilla yesterday patched 11 vulnerabilities in the desktop edition of Firefox as it upgraded the browser to version 7.The company has batted a thousand so far in its rapid release schedule: Firefox 7 marks the third consecutive upgrade that Mozilla has met its every-six-week deadline for a new version of the browser.
[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]
Mozilla switched to the faster release tempo last March, when some wondered whether the open-source company -- which has historically struggled to ship on time -- would be able to make its milestones.
The biggest improvement to Firefox 7 is a reduction in memory use. Mozilla has previously claimed that the upgrade slashes memory consumption by as much as 50 percent.
"Firefox [7] manages memory more efficiently to deliver a nimble Web browsing experience," Mozilla said Tuesday when it launched the new edition. "Users will notice Firefox is faster at opening new tabs, clicking on menu items and buttons on websites."
Most users will see a 20 to 30 percent reduction in memory usage compared to Firefox 4, Mozilla said, but in some situations that can climb to 50 percent.
In an accompanying blog post on the Firefox 7 memory changes, Mozilla said that Windows users will see the most benefit.
The company also claimed that the memory diet has boosted the browser's performance, especially in scenarios where users have opened numerous tabs and leave Firefox running for long stretches.
Firefox has long been knocked as hogging memory, criticism that prompted Mozilla to kick off the "MemShrink" project, which was designed to drive down Firefox's memory use and close "memory leaks" -- bugs that prevent memory from being released to the system when tabs are closed.
Other changes that debuted in Firefox 7 included a new hardware acceleration framework to speed up HTML5 rendering, and an opt-in tool called Telemetry that lets users send performance data to Mozilla.
Firefox 7 also patched 11 security vulnerabilities, 10 of which were rated "critical," the company's most serious threat rating; the sole exception was labeled "moderate."
Because Mozilla now bundles virtually security patches almost exclusively with each version upgrade, users stuck on Firefox 6 or earlier must update to quash the bugs.
Two of the critical vulnerabilities patched Tuesday were in Firefox's implementation of WebGL, a 3-D rendering standard that both Firefox and Google's Chrome comply with. One of the pair was reported to Mozilla by a researcher with Context Information Security, a company that has cited serious security issues with WebGL.
The other was credited to a member of Google's security team.
Firefox has received several patches specific to WebGL since Context recommended users and administrators disable the standard in Mozilla's browser and in Chrome.
Mozilla also released Firefox 3.6.23 yesterday, a security update that patched four vulnerabilities. That aging edition -- Mozilla first shipped Firefox 3.6 in January 2010 -- is still maintained, in part because enterprise users have resisted adopting the rapid release cadence.
As part of a proposal called Extended Support Release, Mozilla plans to halt Firefox 3.6 security updates three months after it kicks off a less-frequent shipping schedule for corporations.
Firefox 7 can be downloaded manually from Mozilla's site, while people running Firefox 4, 5, or 6 will be offered the upgrade through the browser's own update mechanism.
The next version of Firefox is currently scheduled for release on Nov. 8.
Read More...
22/09/11
Urgent: Patch Adobe Flash to Protect against Zero-Day Exploit
Adobe issued a critical update today for its Flash Player software. The patch fixes six security vulnerabilities, at least one of which is a zero-day vulnerability being actively exploited in the wild.
The details of the Adobe security bulletin explain, "This update resolves a universal cross-site scripting issue that could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website (CVE-2011-2444)," adding, "Note: There are reports that this issue is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message."
Patch Adobe Flash now to guard against zero-day exploit.The zero-day bug fixed today is similar to a flaw in Flash that was patched in June. Coincidentally, both the June vulnerability, and this one patched today were reported to Adobe by Google.
I have not seen any official indication that the Flash zero-day had anything to do with the Diginotar hack that compromised digital certificates used to authenticate websites as legitimate--but the timing seems about right.
Just as flaws in the ubiquitous Adobe Flash were exploited to infiltrate RSA Security and compromise the encryption keys used in RSA's SecurID two-factor authentication tokens, Flash may also have been the Achilles heel of Diginotar.
Adobe Flash is nearly universal. With Adobe Flash Player software and browser plug-ins available for virtually every operating system and browser, this zero-day flaw could potentially impact 90 to 95 percent of the PCs in the world.
Andrew Storms, director of security operations for nCircle, connects the dots. "Adobe said that today’s bug 'could be used to act on the user's behalf with webmail providers.' I think we can interpret this to mean that a successful attack using this zero-day bug could allow the attacker to access the user's Gmail account."
Storms implores, "It’s time for all IT teams to circle the wagons and patch Flash as soon as possible."
I'll see Storms' "IT teams", and raise him an "everyone who uses Flash". Go download and install the Adobe Flash update now.
nb : pcworld
Read More...
September Adobe Flash update patches critical vulnerabilities
Adobe has just released an update (APSB11-26) to its ubiquitous Flash software, revving it to version 10.3.183.10 for Windows, Mac, Solaris and Linux, and to version 10.3.186.7 for Android.Today's release fixes six vulnerabilities in Flash Player, one of which was being used in targeted attacks (CVE-2011-2444). This bug is a cross-site scripting flaw which could allow malicious web pages to take actions on behalf of the logged in user.
Adobe has rated this update as Critical. SophosLabs has assigned it a High rating.
SophosLabs has yet to see any samples in the wild, and notes that CVE-2011-2444 is not straightforward to exploit. Nevertheless, as Adobe reports, this vulnerability has been exploited, albeit only in targeted attacks so far.
Windows, Mac, Solaris and Linux users can download the latest Flash player from http://get.adobe.com/flashplayer.
Do watch out though. If adding the bloat of Flash to your browsing experience isn't enough for you, Adobe has decided to default to bundling it with the Google Toolbar or McAfee trialware for Windows users.

You can untick the box before downloading if you don't want these options.
Maybe that's why Apple won't support Flash on iDevices. No portable versions of Google Toolbar or McAfee?
Android users can download the latest Flash Player from the Android Marketplace and Google Chrome users were automatically updated on September 20, 2011 with protection against these flaws.
nb : nakedsecurity.sophos
SSCC 73 - Patch Tuesday, UBS, SpyEye, Twit.tv and Windows 8
I was very happy to have Paul Ducklin, Sophos's Head of Technology, Asia Pacific, as my guest again this week.Paul joined me amidst what he referred to as a Denial of Service (DoS) attack at the security checkpoint of Sydney airport.
Paul shared his thoughts on the September 2011 Patch Tuesday release from Microsoft and Adobe (Hint: if you have to prioritize, start with Adobe.)
We chatted a bit about the guy who lost more than £2.3 billion as a trader for UBS bank. If they can't keep track of £2.3 billion, are they taking proper care of our personally identifiable information?
It appears SpyEye is following in the Zeus bot's footsteps and is beginning to target mobile banking users on Android who use their phone as a second factor for authentication. Paul explains the social engineering aspects of this malware.
One of the most popular tech podcast/vodcast sites, Twit.tv, run by Leo LaPorte was hacked this week. The malware targeted unpatched versions of Adobe Reader and Java. Remember, there is no such thing as safe surfing.
I asked Paul what he thought about the news that Microsoft will be including a free unmanaged anti-virus program in Windows 8.
He talked a bit about patching in general, and was upbeat that users who care to keep themselves up to date could definitely benefit.
nb : nakedsecurity.sophos
20/09/11
Microsoft reissues update for Win XP/2003 for DigiNotar certificate revocation
Microsoft had to reissue an update for users of Windows XP and Windows 2003 today related to the compromise of certificate authority DigiNotar.It was not related to further hacking though, it appears to be a quality assurance SNAFU at the software giant.
Microsoft has updated the known issues in security advisory 2607712 to refer to an updated advisory 2616766.
KB article 2616766 points out that the update shipped last week to remove the known compromised certificates from the trusted certificate list omitted the certificates known to have been in use in the wild.
Somehow Microsoft's Patch Tuesday update only removed additional certificates issued to DigiNotar by GTE and Entrust, but did not remove the original root certificates used to intercept communications in Iran.
Users of Windows XP and 2003 with automatic updating enabled will receive the updated patch automatically, but administrators who manually deploy patches using WSUS may be required to push update 2616676 a second time.
Even worse the update requires users of XP and 2003 to reboot after applying the fixed update. Users of Windows 7, Vista, 2008 and 2008 R2 are unaffected.
nb : nakedsecurity.sophos
Microsoft fixes SSL 'kill switch' blooper
The company has re-released an update for Windows XP and Windows Server 2003 after it left machines unprotected last week
Microsoft re-released an update today for Windows XP to correct a snafu that left users vulnerable to potential "man-in-the-middle" attacks for most of last week.Monday's update addressed a gaffe introduced last week when Microsoft blocked six additional root certificates issued by DigiNotar that were cross-signed by a pair of other CAs (certificate authorities).
[ Get all the details you need on deploying and using Windows 7 in the InfoWorld editors' 21-page Windows 7 Deep Dive PDF special report. | Stay abreast of key Microsoft technologies in our Technology: Microsoft newsletter. ]
Servers run by Dutch CA DigiNotar were hacked starting in June, and attackers stole more than 500 SSL (secure socket layer) certificates, including many used by the Dutch government.
SSL certificates are used by websites and browsers to identify a site as legitimate -- that gmail.com or hotmail.com are actually what they claim -- and illegally-obtained certificates can be abused to disguise unauthorized domains using "man-in-the-middle" attacks to snoop on digital communications and harvest account credentials.
One certificate stolen from DigiNotar was used to spy on 300,000 Iranians for about a month this summer.
Today, Microsoft admitted that the update it shipped to Windows XP and Server 2003 users last Tuesday was flawed.
"The versions...for Windows XP and for Windows Server 2003 contained only the latest six digital certificates cross-signed by GTE and Entrust," said Microsoft in a revised support document . "These versions of the update did not contain the digital certificates that were included in [earlier updates]."
The earlier update, delivered by Microsoft on Sept. 6, blocked five DigiNotar root certificates.
"If you installed update 2616676 and had not already installed update 2607712 or update 2524375, your system would not have been protected from the use of fraudulent digital certificates," Microsoft admitted.
The re-released update for XP and Server 2003 has been added to Windows Update, Microsoft said. Customers who do not have Automatic Updates enabled should manually download and install the new version of the DigiNotar blocker.
Windows Vista, Windows 7, Server 2008, and Server 2008 R2 were not affected by the update goof, said Microsoft.
nb : infoworld Read More...
18/09/11
Google patches 32 Chrome bugs, revs browser to v.14
The company also tweaked Mac Chrome for Lion and laid out more than $14K in bug bounties
Google today patched 32 vulnerabilities in Chrome, paying more than $14,000 in bug bounties as it also upgraded the stable edition of the browser to version 14.The company called out a pair of developer-oriented additions to Chrome 14 and noted new support for Mac OS X 10.7, aka Lion, including full-screen mode and vanishing scrollbars.
[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]
Google last upgraded Chrome's stable build in early August. Google produces an update about every six weeks, a practice that rival Mozilla also adopted with the debut of Firefox 5 last June.
Fifteen of the 32 vulnerabilities were rated "high," the second-most-serious ranking in Google's four-step scoring system, while 10 were pegged "medium" and the remaining seven were marked "low."
None of the flaws were ranked "critical," the category usually reserved for bugs that may allow an attacker to escape Chrome's anti-exploit sandbox. Google has patched several critical bugs this year, the last time in April.
Six of the vulnerabilities rated high were identified as "use-after-free" bugs, a type of memory management flaw that can be exploited to inject attack code, while seven of the bugs ranked medium were "out-of-bounds" flaws, including a pair linked to foreign language character sets used in Cambodia and Tibet.
Google paid $14,337 in bounties to nine researchers, including $3,500 to "miaubiz" and $2,337 to Sergey Glazunov, another regular bug finder.
The company's security team also credited others, including researchers who work for Microsoft and Apple, for "working with us in the development cycle and preventing bugs from ever reaching the stable channel." Some of those researchers were also awarded bounties, but Google did not spell out the amounts of those awards.
As per its practice, Google barred access to the Chrome bug-tracking database for the 32 vulnerabilities to prevent outsiders from obtaining details on the flaws. The company only opens the database after users have had time to update the browser.
Google also added a pair of developer-only features to Chrome 14, including support for the Web Audio API (application programming interface) and for "native client," an open-source technology that runs software written in C and C++ within Chrome's security sandbox.
The Mac version of Chrome 14 also supports Lion's new approach to scrollbars, which appear only when a user is actively scrolling through the browser window. Chrome 14 also now runs in Lion's full-screen mode, triggered via the icon in the upper right of the browser or by pressing Ctrl-Command-F.
But Chrome's full-screen support isn't polished or finished; the browser won't return to its windowed view with a press of the Escape key, as do Apple's home-grown applications in Lion.
Chrome 14 can be downloaded for Windows, Mac OS X and Linux from Google's website. Users already running the browser will be updated automatically.
nb : infoworld Read More...
Oracle issues rare out-of-band update for Apache DDoS vulnerability
Oracle, the giant enterprise database company - and, of course, owner of the erstwhile Sun Microsystems - has just published an out-of-band security update.This is only the fifth time Oracle has issued an alert outside its routine quarterly patch cycle since introducing its own version of Patch Tuesday at the start of 2005.
The update introduces an updated version of the Apache web server, httpd, to Oracle's Fusion Middleware and Application Server products. The former product includes Apache httpd 2.2; the latter includes Apache httpd 2.0.
Apache httpd was recently discovered to be vulnerable to an easily-exploited denial of service attack. The vulnerability, CVE-2011-3192, allowed even a single web client to trigger a huge number of simultaneous requests for large amounts of data. The flaw was exploited by sending a request for multiple parts of the same file at the same time.
(The Range feature of the HTTP protocol was intended to make it easy for web clients to restart interrupted downloads where they left off, or to permit large files to be fetched piecemeal and stitched together later. Apache httpd made it easy to misuse this feature by tolerating redundant Range requests which asked for many large and overlapping parts of a single file.)
Oracle doesn't say on its public-facing web pages exactly how it patched the flawed Apache versions in its products.
The Apache Software Foundation has actually issued two official patches for httpd 2.2 relevant to the so-called byte-range flaw. Version 2.2.20 came out at the end of August, but that patch was recently superseded by 2.2.21, which is effect a patch for the 2.2.20 patch. Apache describes 2.2.21 as "[including] fixes to the patch introduced in release 2.2.20 for protocol compliance, as well as the MaxRanges directive."
It's not clear whether Oracle's out-of-band fix includes the patch-to-the-patch, which appeared only three days ago.
And the previous official Apache httpd version, 2.0, hasn't been patched since May, when 2.0.64 came out. Oracle, one assumes, has done its own back-port of the fix it applied to 2.2.
The fact that a patch-to-the-patch was necessary will no doubt cause more conservative IT administrators to say, "See. I told you that patches should never be rushed."
In this case, however, I consider the glass half-full, not half-empty. I'd argue that the first patch greatly improved the situation, despite being imperfect. The second patch simply improved the improvement further.
However conservative you might be, if you're an Oracle user, this patch is definitely recommended in a hurry. The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, "Importance."
As Oracle itself points out, in bold characters:
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Security Alert fixes as soon as possible.Sysadmins, there you have it. A little something for the weekend!
nb : nakedsecurity.sophos
16/09/11
Oracle: Security flaw could bring down app servers
Oracle has issued an emergency patch to fix a vulnerability it says could bring down HTTP application servers it sells that are based on Apache 2.0 or 2.2.
Attackers can exploit the weakness remotely without a username or password, Oracle said in a security alert issued Thursday.
[ Discover what's new in business applications with InfoWorld's Technology: Applications newsletter. | Get the latest insight on the tech news that matters from InfoWorld's Tech Watch blog. ]
Products impacted by the bug include Oracle Fusion Middleware 11g Release 1, versions 11.1.1.3.0, 11.1.1.4.0 and 11.1.1.5.0; Oracle Application Server 10g Release 3, version 10.1.3.5.0; and Oracle Application Server 10g Release 2, version 10.1.2.3.0.
The U.S. Government's National Vulnerability Database has assigned a CVSS (Common Vulnerability Scoring System) rating of 7.8, "indicating a complete Operating System denial of service," Oracle said.
But Oracle took issue with that assessment in its security alert.
"A complete Operating System denial of service is not possible on any platform supported by Oracle, and as a result, Oracle has given the vulnerability a CVSS Base Score of 5.0 indicating a complete denial of service of the Oracle HTTP Server but not the Operating System," it stated.
In any event, the bug is serious enough for Oracle to issue the patch outside of its usual large quarterly updates, the next of which is scheduled for Oct. 18.
nb : infoworld
Read More...
![[+]d'ZheNwaY's Blog[+]](http://feeds.feedburner.com/blogspot/YRtWp.1.gif)
