Wednesday, July 31, 2019

Google Chrome Updated

Google have released a version 76.0.3809.87 of their Chrome web browser. Among other changes the new version contains fixes to 43 security vulnerabilities.

More information about changes can be viewed in Google Chrome Releases blog.

Thursday, July 25, 2019

ITunes 12.9.6 For Windows Released

Apple have released version 12.9.6 of their iTunes media player. New version fixes security vulnerabilities.

More information about the security content of iTunes 12.9.6 can be read from related security advisory.

Users of old versions should update to the latest one available.

New iCloud Versions For Windows Released

Apple have released new versions of their iCloud client for Windows. New versions fix security vulnerabilities.

iCloud for Windows 10.6 is for Windows 10 and later and is available via Windows Store. iCloud for Windows 7.13 is available for Windows 7 and later.

More information about the security content of the new versions can be read from the correspondent security advisories:
-iCloud 10.6
-iCloud 7.13

Monday, July 22, 2019

Vulnerability Fixed In Wireshark

There have been fixed a security vulnerability in Wireshark, free open source program for analyzing network protocols. The vulnerability is related to ASN.1 BER and related dissectors. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Affected versions
-3.0.x versions 3.0.0-3.0.2
-2.6.x versions 2.6.0-2.6.9
-2.4.x versions 2.4.0-2.4.15

Non vulnerable version can be downloaded here.

More information in the security advisory

Oracle Critical Patch Update For Q3 of 2019

Oracle have released updates for their products that fix 319 security issues (including ten Java fixes) in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).

Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.

Next Oracle CPU is planned to be released in October 2019.

Vulnerability Fixed In Drupal

There have been released a new version of open-source content management framework Drupal. The new version fix a critical vulnerability.

The only affected version is Drupal 8.7.4. Its users should update to 8.7.5 version.

More information in Drupal security advisory

VLC Player Updated

VideoLAN project has released a new version of their VLC media player. The new version contains a fix to a heap-based buffer-overflow vulnerability. By exploiting the vulnerability it is possible to cause a denial-of-service condition denying service to legitimate users.

Affected are VLC Player versions prior 3.0.7.1. Owners of those versions should update to the latest version.

Thursday, July 18, 2019

Mozilla Thunderbird Update Available

Mozilla have released an updated version of their Thunderbird email client containing fixes to security vulnerabilities.

Affected versions:
Mozilla Thunderbird versions earlier than 60.8

Fresh version can be obtained via inbuilt updater or by downloading from the product site.

Vulnerabilities In Mozilla Firefox

Mozilla have released updated versions of their Firefox web browser. New versions fix security vulnerabilities.

Affected versions:
-Mozilla Firefox 68 (advisory)
-Mozilla Firefox ESR 60.8 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.

Adobe Dreamweaver Installer Updated

Adobe has released an updated version of direct download windows installer of Adobe Dreamweaver fixing an important categorized vulnerability (CVE-2019-7956). The vulnerability is related to insecure library loading and it could lead to privilege escalation.

Affected versions:
-Adobe Dreamweaver direct download installer 18.0 and below
-Adobe Dreamweaver direct download installer 19.0 and below

More information in the security advisory>

Adobe Experience Manager Updated

Adobe has released updated versions of their Experience Manager. Updates fix one moderate (CVE-2019-7955) and two important (CVE-2019-7953 and CVE-2019-7954) categorized vulnerabilities that could result in sensitive information disclosure.

Affected are versions 6.0, 6.1, 6.2, 6.3 and 6.4

More information from the Adobe's security advisory.

New Adobe Bridge CC Version Available

Adobe has released version 9.1 of their Bridge CC. The update fixes an important categorized vulnerability (CVE-2019-7963).

Affected are versions 9.0.2 and earlier.

More information from the Adobe's security advisory.

New Google Chrome Version Released

Google have released a version 75.0.3770.142 of their Chrome web browser. The new version contains fixes to two security vulnerabilities.

More information about changes can be viewed in Google Chrome Releases blog.

Microsoft Security Updates For July 2019

Microsoft have released security updates for July 2019.

Summary of the updates (filter by inserting 06/14/2019 to the From field and 07/09/2019 to the To field) here.

Symantec Intelligence Report: June 2019

Symantec have published their Intelligence report that sums up the latest threat trends for June 2019.
The report can be viewed here.

Latest PHP Versions Available

PHP development team has released 7.3.7 and 7.2.20 versions of the PHP scripting language. New versions contain bug fixes. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.

Changelogs:
Version 7.3.7
Version 7.2.20