Wednesday, May 19, 2010

Unpatched Vulnerability In Latest Windows Versions

Microsoft is investigating a reported vulnerability in the Windows Canonical Display Driver (cdd.dll). If successfully exploited, the vulnerability could allow code execution.

Affected Windows versions are:
Windows 7 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems (Server Core installation not affected)
Windows Server 2008 R2 for Itanium-based Systems


More information:
MSRC blog post
Related Microsoft Security Advisory

Saturday, May 15, 2010

New Shockwave Player Available

Adobe has released a new version of their Shockwave Player. Update contains fixes to several critical vulnerabilities that can be exploited to execute arbitrary code in target system.

Users with Shockwave Player older than 11.5.7.609 should update their players. The latest version can be downloaded here.

More information can be read from the correspondent security bulletin.

Friday, May 14, 2010

Mozilla Plugin Checker To Check Other Browsers' Plugins Too

Last fall Mozilla made available a website that Firefox users could use to check if their browser plugins were outdated. Now Mozilla has extended the plugin check to other browsers too. At the moment, supported are Safari 4, Chrome 4 and Opera 10.5. Support for the most popular, but not for all yet, plugins of Internet Explorer 7 and 8 is included too.

More information in Mozilla blog.

Tuesday, May 11, 2010

Microsoft Security Bulletin Summary for May 2010

Microsoft has released security updates for May 2010. This month update contains fixes for two vulnerabilities which both are categorized as critical:
MS10-030: Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542)
MS10-031: Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (978213)


A new version of Windows Malicious Software Removal Tool (MSRT) was released too.

More information can be read from the bulletin summary.

For consumer the easist way to get the update is to use Microsoft Update service.

Monday, May 10, 2010

Updated Foxit Reader Blocks "Launch" Issue

Foxit Software has released a new version of their PDF viewer software. Foxit Reader 3.3 contains "Trust Manager" that blocks all external commands that may be tucked into a PDF document. The update is a response to reported malware campaigns abusing unfixed "/Launch" flaw.

Source

Monday, May 3, 2010

Update For Opera Available

Opera Software has released an update for their Opera web browser. Version 10.53 contains fix to a vulnerability categorized as "extremely severe".

Extremely severe:
Multiple asynchronous calls to a script that modifies the document contents can cause Opera to reference an uninitialized value, which may lead to a crash. To inject code, additional techniques will have to be employed.

Opera users are strongly recommended to update to 10.53 version. New version can be downloaded here.

Changelog of Windows version

Vulnerability In Adobe Photoshop CS4

There has been found a critical vulnerability in Photoshop CS4. Successful exploitation of the vulnerability makes it possible for an attacker to take control of the affected system. This can be done by luring user to open specially crafted .TIFF file.

Users of the affected version are recommended to update their Photoshop CS4 to version 11.0.1. More information can be read from Adobe security bulletin.