Oracle has released updates for their products that fix 88 security issues in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).
Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.
Next Oracle CPU is planned to be released in July 2012.
Thursday, April 19, 2012
Monday, April 16, 2012
Vulnerability In VMware Products
There has been found a vulnerability in VMware Tools component of VMware products. The vulnerability may lead to local privilege escalation on Windows-based Guest Operating Systems. Attacker can't exploit this vulnerability to break into the host machine itself.
Affected software versions are:
- Workstation 8.0.1 and earlier
- Player 4.0.1 and earlier
- Fusion 4.1.1 and earlier
- ESXi 5.0 prior update ESXi500-201203102-SG
- ESXi 4.1 prior update ESXi410-201201402-BG
- ESXi 4.0 prior update ESXi400-201203402-BG
- ESXi 3.5 prior update ESXe350-201203402-T-BG
- ESX 4.1 prior update ESX410-201201401-SG
- ESX 4.0 prior update ESX400-201203401-SG
- ESX 3.5 prior update ESX350-201203402-BG
Instructions for updating to a non-vulnerable version can be read from the related security advisory.
Affected software versions are:
- Workstation 8.0.1 and earlier
- Player 4.0.1 and earlier
- Fusion 4.1.1 and earlier
- ESXi 5.0 prior update ESXi500-201203102-SG
- ESXi 4.1 prior update ESXi410-201201402-BG
- ESXi 4.0 prior update ESXi400-201203402-BG
- ESXi 3.5 prior update ESXe350-201203402-T-BG
- ESX 4.1 prior update ESX410-201201401-SG
- ESX 4.0 prior update ESX400-201203401-SG
- ESX 3.5 prior update ESX350-201203402-BG
Instructions for updating to a non-vulnerable version can be read from the related security advisory.
Wednesday, April 11, 2012
Adobe Reader And Acrobat Security Updates
Adobe has released security updates to fix a bunch of critical vulnerabilities in their PDF products, Adobe Reader and Adobe Acrobat.
Affected versions:
*of series X (10.x)
Adobe Reader 10.1.2 and earlier
Adobe Acrobat 10.1.2 and earlier
*of series 9.x
Adobe Reader 9.5 and earlier 9.x versions
Adobe Acrobat 9.5 and earlier 9.x versions
Users of vulnerable versions are instructed to update their versions either by using automatic update functionality or by downloading fresh version manually. The default installation configuration runs automatic updates on a regular schedule and can be manually activated by choosing Help > Check for Updates.
Those who want to upgrade manually, can download the latest versions of the links below:
Adobe Reader
Acrobat Standard and Pro
Acrobat Pro Extended
More information about fixed vulnerabilities can be read from Adobe's security bulletin.
Affected versions:
*of series X (10.x)
Adobe Reader 10.1.2 and earlier
Adobe Acrobat 10.1.2 and earlier
*of series 9.x
Adobe Reader 9.5 and earlier 9.x versions
Adobe Acrobat 9.5 and earlier 9.x versions
Users of vulnerable versions are instructed to update their versions either by using automatic update functionality or by downloading fresh version manually. The default installation configuration runs automatic updates on a regular schedule and can be manually activated by choosing Help > Check for Updates.
Those who want to upgrade manually, can download the latest versions of the links below:
Adobe Reader
Acrobat Standard and Pro
Acrobat Pro Extended
More information about fixed vulnerabilities can be read from Adobe's security bulletin.
Labels:
acrobat,
adobe,
pdf,
pdf reader,
security,
update,
vulnerability
Microsoft Security Updates For April 2012
Microsoft has released security updates for April 2012. This month update contains six security bulletins of which four critical and two important.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
Tuesday, April 10, 2012
Chrome Updates Released
Google has released a new version of their Chrome web browser. Version 18.0.1025.151 fixes 12 security vulnerabilities of which seven high, four medium and one low categorized.
More information in Google Chrome Releases blog.
After that version, Google released version 18.0.1025.152 that contains fixes to SSL issues (issue 118706) but may reintroduce issue 117371.
More information in Google Chrome Releases blog.
After that version, Google released version 18.0.1025.152 that contains fixes to SSL issues (issue 118706) but may reintroduce issue 117371.
Thursday, April 5, 2012
ESET Global Threat Report for March 2012
ESET has released a report discussing global threats of March 2012.
TOP 10 threats list (previous ranking listed too):
1. HTML/ScrInject.B (1.)
2. INF/Autorun (2.)
3. HTML/Iframe.B (3.)
4. Win32/Conficker (4.)
5. JS/Agent (90.)
6. JS/Iframe.AS (66.)
7. Win32/sirefef (-)
8. Win32/Sality (8.)
9. Win32/Dorkbot (7.)
10. JS/Redirector (47.)
Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).
TOP 10 threats list (previous ranking listed too):
1. HTML/ScrInject.B (1.)
2. INF/Autorun (2.)
3. HTML/Iframe.B (3.)
4. Win32/Conficker (4.)
5. JS/Agent (90.)
6. JS/Iframe.AS (66.)
7. Win32/sirefef (-)
8. Win32/Sality (8.)
9. Win32/Dorkbot (7.)
10. JS/Redirector (47.)
Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).
Sunday, April 1, 2012
New Chrome Version Available
Google have released a new version of their Chrome web browser. Chrome 18 contains some new features like faster graphics (more about these here). Last but not least, new version 18.0.1025.142 contains fixes to three high, five medium and one low catogorized vulnerabilities.
More information in Google Chrome Releases blog.
More information in Google Chrome Releases blog.
Subscribe to:
Posts (Atom)