Friday, July 30, 2021

Google Chrome updated

Google have released version 92.0.4515.107 for Windows, macOS and Linux. In addition to other changes the new version contains fixes to 35 security vulnerabilities.

More information can be read from Google Chrome releases blog.

Oracle Critical Patch Update For Q3 of 2021

Oracle have released updates for their products that fix 342 security issues (including six Java fixes) in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).

Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.

The next Oracle CPU is planned to be released in October 2021.

Thursday, July 15, 2021

New Adobe Dimension Version Released

Adobe have released an updated version of their Adobe Dimension. The new version fixes a critical vulnerability (CVE-2021-28595) that may allow arbitrary code execution in the context of the current user.

Affected versions
Adobe Dimension 3.4 and earlier versions 

Solution
Update to Dimension 3.4.3 (or newer) version

More information in the correspondent security bulletin.

Adobe Illustrator Vulnerabilities Fixed

Adobe have released an updated version of their Adobe Illustrator for Windows. The new version fixes critical vulnerabilities (CVE-2021-28591, CVE-2021-28592) that may allow arbitrary code execution in the context of the current user. One important categorized vulnerability (CVE-2021-28593) was fixed, too.

Affected versions
Illustrator 2021 25.2.3 and earlier versions

Solution
Update to Illustrator 2021 25.3 (or newer) version

More information in the correspondent security bulletin.

Adobe Framemaker Updated

Adobe has released an updated version of their Framemaker. New version contains fix to a critical security vulnerability (CVE-2021-28596). Successful exploitation of the vulnerability could lead to arbitrary code execution in the context of the current user.

Affected versions
-Framemaker 2019 release for Windows without update 8
-Framemaker 2020 release for Windows without update 2

More information from the Adobe's security advisory.

Adobe Reader And Acrobat Security Updates

Adobe have released security updates to fix vulnerabilities in their PDF products, Adobe Reader and Adobe Acrobat. Exploiting the vulnerabilities could allow arbitrary code execution in the context of the current user.

Affected versions:
*Acrobat DC and Acrobat Reader DC, continuous track
versions earlier than 2021.005.20058

*Acrobat 2020 and Acrobat Reader 2020, 2020 classic track
versions earlier than 2020.004.30006

*Acrobat 2017 and Acrobat Reader 2017, 2017 classic track
versions earlier than 2017.011.30199


Users of vulnerable versions are instructed to update their versions either by using automatic update functionality or by downloading fresh version manually. The default installation configuration runs automatic updates on a regular schedule and can be manually activated by choosing Help > Check for Updates.

Full version of Adobe Acrobat Reader DC and a trial version of Adobe Acrobat Pro DC can be found here.


More information about fixed vulnerability can be read from Adobe's security bulletin.

Adobe Bridge Updated

Adobe Bridge has received a new version. This new version resolves critical vulnerabilities which may allow execution of arbitrary code.

Affected versions:
- Adobe Bridge 11.0.2 and earlier versions for Windows

Solution:
- Update to Adobe Bridge 11.1


More information can be read from Adobe's security bulletin.

VMware ThinApp Updated

VMware has released updated version of their ThinApp for Windows. The update fixes a DLL hijacking vulnerability (CVE-2021-22000).

Affected versions:
-VMware ThinApp 5.x earlier than 5.2.10

More information in related VMware advisory.

VMware ESXi Vulnerabilities Fixed

VMware has released updated versions of their virtualization software patching security vulnerabilities (CVE-2021-21994, CVE-2021-21995).

Affected versions:
-VMware ESXi 7.0 without ESXi70U2-17630552
-VMware ESXi 6.7 without ESXi670-202103101-SG update
-VMware ESXi 6.5 without ESXi650-202107401-SG update
-VMware Cloud Foundation (ESXi) 4.x, patch pending
-VMware Cloud Foundation (ESXi) 3.x earlier than 3.10.2

More information in related VMware advisory.

Mozilla Firefox Updated

Mozilla have released updated versions of their Firefox web browser. New versions fix security vulnerabilities.

Affected versions:
-Mozilla Firefox earlier than 90 (advisory)
-Mozilla Firefox ESR 78.x earlier than 78.12 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.

Mozilla Thunderbird Updated

Mozilla have released updated version of their Thunderbird email client containing some fixes to security vulnerabilities.

Affected versions:
- Mozilla Thunderbird earlier than 78.12 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading from the product site.

Microsoft Security Updates For July 2021

Microsoft have released security updates for July 2021.

Release notes of the updates can be viewed here.

New PHP versions available

PHP development team has released 8.0.8 and 7.4.21 versions of the PHP scripting language. Among other bugs some security bugs have been fixed. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.

Changelogs:
Version 8.0.8
Version 7.4.21