Showing posts with label vulnerability security. Show all posts
Showing posts with label vulnerability security. Show all posts
Updates for Mac OSX, Security Update
Dear Mac OSX to keep your system secure and update the Mac has lauched a new security update. When many still have not finished to surprise us with all the improvements and developments of the newly released Snow Leopard, Apple has just released the first update "important" this operating system. Moreover, some earlier versions of Mac OS X, has also released an update. First Mac OS X 10.6.1. Although not exactly a "security update" finally incorporates the latest version of Adobe's Flash Player. This is because as you know, Apple made a neglect to include an insecure version of this popular player in the first version of Snow Leopard. Moreover, for users of Mac OS X 10.4.x and 10.5.x, has released the "Security Update 2009-004, which fixes multiple security issues among which include code execution vulnerabilities affecting both the system in general and third party components.
So, whether Snow Leopard, Leopard or Tiger (much wildlife here), it's time to upgrade. As always, updates can be downloaded from Apple's web site or through the system "Software Update" in Mac OS X.
http://support.apple.com/kb/DL930?viewlocale=es_ES&locale=es_ES
http://support.apple.com/kb/HT3865
Labels: Apple, osx update, security update, update os x, Updates, vulnerability security
Internet Explorer 6 and 7 vulnerable
If a few days ago Microsoft published a security advisory to warn users about a security flaw in Windows 7, now doing the same but to confirm a critical vulnerability affecting Internet Explorer 6 and 7.
The vulnerability in question was caused by a problem in Microsoft HTML Viewer (mshtml.dll) to process certain CSS objects, and this can be exploited by an attacker to execute code and take
control of your computer. For now it is not reported that this vulnerability is being actively
exploited.
As published a solution for this problem in the browser configuration is recommended to
increase the security level for the Internet zone. In addition, the mode of security
protection that incorporates Internet Explorer 7 on Windows Vista can help reduce the impact
of an attack.
Every month Microsoft releases a series of updates, and things are going, it seems that
December will come loaded with some patches, and inform them.
Eleven security bulletins for Mozilla Firefox
The Mozilla Foundation has published eleven security bulletins to fix various vulnerabilities in Mozilla Firefox which could be exploited by a remote attacker to manipulate or disclose sensitive information, bypass security restrictions or compromise a vulnerable system.
Below are the published vulnerabilities:
The first problem lies in a flaw in the way Firefox handles the history of forms. This vulnerability could allow a remote attacker to steal stored data and cause the browser to automatically fill in forms via a specially crafted web page. Another error occurs in the way Firefox appointing temporary files download. A local attacker could exploit this issue to execute arbitrary code via a change of contents of the temporary files download.
Creating Web recursive-workers in JavaScript can be used to create a set of objects whose memory can be released prior to use. These conditions usually result in a denial of service, which could potentially allow an attacker to arbitrary code execution. Multiple vulnerabilities are due to the way Firefox processes the wrong web content, a remote attacker could cause a denial of service and potentially execute arbitrary code via a specially crafted web page.
Another bulletin is a bug in the GIF image processing of Firefox that could cause an overflow of heap memory. A remote attacker could exploit this issue to cause a denial of service and potentially execute arbitrary code via a specially crafted GIF image.
Another error occurs in the fixed conversion routines floating point string to Firefox, which could overflow a heap-based memory. A remote attacker could exploit this issue to cause a denial of service and potentially execute arbitrary code with the permissions of the user through a web page with Javascript, specially crafted code.
Another bulletin refers to an error in the way Firefox handles text selection. A remote attacker could exploit this issue to see the user selected text from a different domain via a specially crafted website. An error occurs in the way Firefox displays the name when you download a file, which would show a different name in the title bar and body dialogue. A remote attacker could perform an attack by man in the middle and execute arbitrary code via a specially crafted file.
Mozilla has also updated several third-party libraries to correct failures in the treatment of memory and stability bugs.
We recommend you upgrade to Mozilla Firefox 3.5.4 or 3.0.15 versions:
http://www.mozilla.com/firefox/
Microsoft security bulletins
As it developed, on Tuesday Microsoft has released six security bulletins (from MS09-063 to MS09-068) for its usual cycle of updates. According to Microsoft's own classification of three of the bulletins have a severity level "critical" while the other five are "important." A total of 15 vulnerabilities have been resolved.
The bulletin "critical" are:
* MS09-063: Update to correct a vulnerability in Web Services on Devices Application Programming Interface (WSDAPI), which could allow remote code execution if Windows affected system receives a specially created package. It affects Windows Vista and Windows Server 2008.
* MS09-064: Update is intended to correct a vulnerability in License Logging Server on Windows 2000 that could allow arbitrary remote code execution if an attacker sends a network specifically created a system running License Logging Server.
* MS09-065: Update to fix for three vulnerabilities in Windows Kernel that could allow remote execution of arbitrary code. It affects Windows 2000, XP, Vista, Server 2003 and Server 2008.
The newsletters are classified as "important" are:
* MS09-066: Update designed to correct a denial of service vulnerability in the Active Directory service, Active Directory Application Mode (ADAM) and Active Directory Lightweight Directory Service (AD LDS).
* MS09-067: Update that addresses eight vulnerabilities in Microsoft Excel. The problems may come to allow remote code execution if a user opens an Excel file specifically manipulated.
* MS09-068: Update that fixes a vulnerability in Microsoft Word, which could allow remote code execution if a user opens a Word file specifically manipulated.
You can download the updates released through Windows Update or Microsoft bulletins consultation which includes the addresses of each patch direct download. Given the seriousness of the vulnerabilities we recommend updating systems as soon as possible.
Denial of Service Vulnerability in Linksys WAP4400N
It has reported a vulnerability to denial of service in wireless access points WAP4400N Linksys (Wireless Access Point).The problem is due to an error when trying Association requests poorly constructed, which could result in the device is
rebooted or becomes blocked causing unusable wireless network with the consequent denial of service condition.It has released firmware version 1.2.19 to correct this problem.
More Information:
Links:
Vulnerability in HP Color LaserJet
It has reported a vulnerability in some printers HP Color LaserJet range, which could allow denial of service attacks orbypass security restrictions and allow unauthorized access to data.
On several occasions we talked about the importance of keeping systems up to date, but we must also remember that hardwareelements may also be affected by security problems that can cause significant impact to business continuity. They arefrequent updates for vulnerabilities in routers, switches and network devices similar, but the printers are importantelements in the daily operational work and may also be affected by serious problems. Especially workplace printers withmultiple functionalities.
The problem is caused by an error from which HP has not provided details, but confirmed that affected the HP Color LaserJetM3530 Multifunction Printer with firmware 53.021.2 and HP Color LaserJet CP3525 Printer with firmware 05.058.4. Only printersare affected with these specific versions of firmware.
HP has released firmware updates to correct these problems:
HP Color LaserJet M3530 Multifunction Printer 53.031.4 or later.
HP Color LaserJet CP3525 Printer 05.059.3 or later.
Available from the HP website at www.hp.com
This problem is an example of how important it can be given to all systems and devices that make up our network, even those
who think they can not have problems as a printer.
More Information:
HPSBPI02472 SSRT090196 rev.1 - Certain HP Color LaserJet Printers, Remote Unauthorized Access to Data, Denial of Service
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01886100
Subscribe to:
Posts (Atom)