It was Patch Tuesday for the second time this month — except this week it’s Adobe and Apple, not Microsoft, products that have urgent security updates.
Adobe yesterday released updates for its Acrobat and Reader applications and Flash Player browser plug-in to patch a dangerous vulnerability reported last week.
Bad guys had already been using the hole to attack PC users via Excel files infected with bad Flash objects.
The vulnerability affects all major PC operating systems (Windows, Mac and Linux), plus a minor one (Oracle’s Solaris) and Android OS smartphones, as well as all browsers.
Google’s Chrome got a jump on the Flash Player patch a few days earlier, thanks to a tight relationship with Adobe. Users running Chrome will still have to patch other browsers and the stand-alone Reader and Acrobat applications.
As has been the case for years, Internet Explorer requires a separate Flash Player plug-in from the other browsers.
Apple iOS devices will not need a patch; Steve Jobs’ ban on Flash for the iPhone and iPad seems to extend to Acrobat and Reader as well. (iOS reads PDF files natively.)
All patches are available from Adobe’s website here.
Slightly less urgent, but no less comprehensive, is Apple’s latest and possibly final major update to its Snow Leopard version of OS X.
This one bumps the version number up to 10.6.7 and patches 40 vulnerabilities in Apple and open-source apps and services, many related to the handling of image files.
Sophos’s Naked Security blog notes that the update also boosts Apple’s Safari browser to 5.0.4, which patches another 60 or so security holes.
Similar security upgrades are also available for OS X 10.5 Leopard, the last version of OS X to run on PowerPC-based Macs.
Apple’s OS X 10.7 Lion is scheduled to come out this summer.
Apple’s Software Update should automatically download the updates and prompt users to install them. If not, the updates can be found here.
[SecurityNewsDaily]
Showing posts with label updates. Show all posts
Showing posts with label updates. Show all posts
Thursday, 24 March 2011
Wednesday, 23 March 2011
Mac OS X 10.6.7 fixes security vulnerabilities
Apple today released Mac OS X 10.6.7 which increases the stability, compatibility, and security of your Mac.

AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
Sunday, 13 March 2011
Apple issues mammoth security update for Safari browser
Apple has released Safari 5.0.4 - the latest version of Apple's browser software for Windows and Mac users - patching an eye-watering 62 security vulnerabilities in the process.
The vulnerabilities, described in an Apple knowledgebase article, were disclosed at the same time as a host of security holes in the iOS software used by the iPhone, iPad and iPod touch were also revealed by the company.
What this means is, just like their iPhone/iPod touch/iPad-owning cousins, people who run Safari on their Mac or Windows computers would be wise to check out the latest available security updates as soon as possible.
Apple doesn't like to assign severity levels to the security vulnerabilities found in its products, but the bugs in Safari look pretty critical to me. 57 of the 62 bugs can be exploited just by a user visiting a maliciously-crafted website.
If that's not a reason to install a security update to your Safari browser, I'm not sure what is.
You can download Safari 5.0.4 from Apple's website for Mac OS X 10.5 (Leopard), Mac OS X 10.6 (Snow Leopard), Windows XP, Windows Vista and Windows 7.
SophosLabs see tens of thousands of legitimately websites that have been infected by malware every single day, so it's really important to keep your browser up-to-date with the latest security patches.
[NakedSecurity]
The vulnerabilities, described in an Apple knowledgebase article, were disclosed at the same time as a host of security holes in the iOS software used by the iPhone, iPad and iPod touch were also revealed by the company.
What this means is, just like their iPhone/iPod touch/iPad-owning cousins, people who run Safari on their Mac or Windows computers would be wise to check out the latest available security updates as soon as possible.
Apple doesn't like to assign severity levels to the security vulnerabilities found in its products, but the bugs in Safari look pretty critical to me. 57 of the 62 bugs can be exploited just by a user visiting a maliciously-crafted website.
If that's not a reason to install a security update to your Safari browser, I'm not sure what is.
You can download Safari 5.0.4 from Apple's website for Mac OS X 10.5 (Leopard), Mac OS X 10.6 (Snow Leopard), Windows XP, Windows Vista and Windows 7.
SophosLabs see tens of thousands of legitimately websites that have been infected by malware every single day, so it's really important to keep your browser up-to-date with the latest security patches.
[NakedSecurity]
Sunday, 6 March 2011
Microsoft announces 3 Security Bulletins
The Redmond company announced 3 security bulletins for the upcoming Patch Tuesday next week. These are meant to fix at least 4 security vulnerabilities. One flaw which affects Windows from XP to Windows 7 as well as Windows Server 2008 R2 is rated “critical” which means that attackers can smuggle in malware quite easily; a second bulletin deals with at least “important” vulnerabilities in the Windows operating systems. The third bulletin is about Microsoft Office – in Groove 2007 there is an “important” rated flaw to be fixed.
Users and Administrators should prepare to install those updates as soon as possible upon release next Tuesday.
[ComputerSecurityArticles]
Users and Administrators should prepare to install those updates as soon as possible upon release next Tuesday.
[ComputerSecurityArticles]
Friday, 4 March 2011
Microsoft pushes anti-AutoRun update at XP, Vista users
Microsoft last week changed how it delivers an update that disables AutoRun, a Windows feature that big name worms, including Conficker and Stuxnet, have used to infect millions of PCs.
The company is now pushing the update to Windows XP and Vista users automatically.
When Microsoft first deployed the update Feb. 8, it said the patch would be offered as an optional download. To retrieve it, users had to manually checkmark the “KB971029″ update in the “Software, Optional” section of Windows Update in XP, or in Vista’s Windows Update panel under “Important.”
But last week Microsoft changed those rules and began feeding users the update through the Automatic Updates feature of Windows Update, which automatically downloads and installs hotfixes and other software upgrades. In Windows XP, for example, users now see the AutoRun fix under the “High-priority updates” label, and the patch is pre-checked so it downloads and installs without any user action.
The “High-priority updates” section of XP’s Windows Update is the same location where security-related patches appear.
Microsoft’s move to cripple AutoRun is a response to malware’s continued reliance on infection tactics that abuse AutoRun and AutoPlay, the technologies that automatically launch executable files on removable media, especially USB flash drives.
Both Conficker, a worm that spread widely in early 2009, and Stuxnet, the worm that analysts suspect was developed to sabotage Iran’s nuclear programs, used AutoRun and flash drives to infect Windows PCs.
Microsoft changed AutoRun’s behavior in Windows 7 to block automatic execution of files on a USB drive, and first backported the modifications to Windows XP and Vista in August 2009.
When the update is in place, flash drives inserted into a PC running XP or Vista no longer offer the option to run programs; the AutoRun extinction does not affect CDs or DVDs.
Microsoft confirmed the update reset, and said that it changed the delivery process to “minimize the user interaction required to install the updates on systems configured for automatic updating.” However, the company did not respond to questions about why it did not communicate the change to users as it had in early February when it said the patch was optional.
The unannounced automatic deployment of the AutoRun update may cause confusion if users expect files — in particular, setup executables that kick off software installation — to launch when they insert a flash drive in their Windows XP or Vista PCs.
Microsoft noted that the update breaks the functionality of some USB drives. “Users who install this update will no longer receive a setup message that prompts them to install programs that are delivered by USB flash drives. Users will have to manually install the software,” Microsoft warned in a security advisory.
To disable the update’s changes and revert to Windows XP’s and Vista’s earlier behavior, users can run the “Enable Autorun” tool found on Microsoft’s support site.
[ComputerWorld]
The company is now pushing the update to Windows XP and Vista users automatically.
When Microsoft first deployed the update Feb. 8, it said the patch would be offered as an optional download. To retrieve it, users had to manually checkmark the “KB971029″ update in the “Software, Optional” section of Windows Update in XP, or in Vista’s Windows Update panel under “Important.”
But last week Microsoft changed those rules and began feeding users the update through the Automatic Updates feature of Windows Update, which automatically downloads and installs hotfixes and other software upgrades. In Windows XP, for example, users now see the AutoRun fix under the “High-priority updates” label, and the patch is pre-checked so it downloads and installs without any user action.
The “High-priority updates” section of XP’s Windows Update is the same location where security-related patches appear.
Microsoft’s move to cripple AutoRun is a response to malware’s continued reliance on infection tactics that abuse AutoRun and AutoPlay, the technologies that automatically launch executable files on removable media, especially USB flash drives.
Both Conficker, a worm that spread widely in early 2009, and Stuxnet, the worm that analysts suspect was developed to sabotage Iran’s nuclear programs, used AutoRun and flash drives to infect Windows PCs.
Microsoft changed AutoRun’s behavior in Windows 7 to block automatic execution of files on a USB drive, and first backported the modifications to Windows XP and Vista in August 2009.
When the update is in place, flash drives inserted into a PC running XP or Vista no longer offer the option to run programs; the AutoRun extinction does not affect CDs or DVDs.
Microsoft confirmed the update reset, and said that it changed the delivery process to “minimize the user interaction required to install the updates on systems configured for automatic updating.” However, the company did not respond to questions about why it did not communicate the change to users as it had in early February when it said the patch was optional.
The unannounced automatic deployment of the AutoRun update may cause confusion if users expect files — in particular, setup executables that kick off software installation — to launch when they insert a flash drive in their Windows XP or Vista PCs.
Microsoft noted that the update breaks the functionality of some USB drives. “Users who install this update will no longer receive a setup message that prompts them to install programs that are delivered by USB flash drives. Users will have to manually install the software,” Microsoft warned in a security advisory.
To disable the update’s changes and revert to Windows XP’s and Vista’s earlier behavior, users can run the “Enable Autorun” tool found on Microsoft’s support site.
[ComputerWorld]
Labels:
malware,
Microsoft,
security,
updates,
vulnerabilities
Wednesday, 23 February 2011
Windows 7 Service Pack 1 now available
Microsoft has released Windows 7 Service Pack one with a ton of bug fixes and security updates for your Windows PC
Subscribe to:
Posts (Atom)
