Wednesday, May 15, 2013

Adobe ColdFusion Update Available

Adobe have released updated version of ColdFusion web application development platform. The new version fix two vulnerabilities. A vulnerability (CVE-2013-1389) that could allow remote arbitrary code execution on a system running ColdFusion, and a vulnerability (CVE-2013-3336) that could permit an unauthorized user to remotely retrieve files stored on the server.

Affected versions:
- ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX.

More information can be read from Adobe's security bulletin.

Adobe Flash Player and Adobe AIR Updates Available

Adobe have released updated versions of their Flash Player and AIR. The new versions fix critical vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.

Affected versions:
- Users of Adobe Flash Player 11.7.700.169 and earlier versions for Windows should update to Adobe Flash Player 11.7.700.202
- Users of Adobe Flash Player 11.7.700.169 and earlier versions for Macintosh should update to Adobe Flash Player 11.7.700.202
- Users of Adobe Flash Player 11.2.202.280 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.285
- Users of Adobe Flash Player 11.1.115.54 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.58 (applicable only for Flash Player installed before August 15, 2012)
- Users of Adobe Flash Player 11.1.111.50 and earlier versions for Android 3.x and 2.x versions should update to Flash Player 11.1.111.54 (applicable only for Flash Player installed before August 15, 2012)
- Flash Player integrated with Google Chrome will be updated by Google via Chrome update
- Flash Player integrated with Internet Explorer 10 will be updated via Windows Update
- Users of Adobe AIR 3.7.0.1530 and earlier versions for Windows should update to Adobe AIR 3.7.0.1860
- Users of Adobe AIR 3.7.0.1530 and earlier versions for Macintosh should update to Adobe AIR 3.7.0.1860
- Users of Adobe AIR 3.7.0.1660 and earlier versions for Android should update to Adobe AIR 3.7.0.1860
- Users of the Adobe AIR 3.7.0.1530 SDK should update to the Adobe AIR 3.7.0.1860 SDK

More information can be read from Adobe's security bulletin.

Tuesday, May 14, 2013

Microsoft Security Updates For May 2013

Microsoft have released security updates for May 2013. This month update contains ten security bulletins of which two critical and eight important.

A new version of Windows Malicious Software Removal Tool (MSRT) was released too.

More information can be read from the bulletin summary.

Monday, May 13, 2013

Unpatched Vulnerability In ColdFusion

Adobe has identified a critical vulnerability in its ColdFusion web application development platform. The vulnerability (CVE-2013-3336) could be exploited to gain access to files stored on vulnerable computers.

Affected versions are ColdFusion 10, 9.0.2, 9.0.0, 9.0 and older versions for Windows, Mac, and Unix. An exploit for the flaw is reportedly available. Adobe plans to release a patch for the vulnerability on May 14. More information in related security advisory.

Sunday, May 12, 2013

F-Secure Introduces Safe Profile App For Facebook

F-Secure have made available a Facebook app called Safe Profile. It's job is to inform user about the most important safety and privacy issues. After a scan Safe Profile gives a rating for the account's privacy, displays any potential issues and makes recommendations for more secure settings. Safe Profile won't store any personal data.

Safe Profile is currently at a beta stage. To try it, log into your Facebook account and search for "Safe Profile Beta".

Source: F-Secure press release

Monday, May 6, 2013

Vulnerability In Internet Explorer

There has been found a vulnerability in Microsoft Internet Explorer that may allow an attacker to execute arbitrary code in vulnerable system. Microsoft is aware of attacks that try to exploit this vulnerability. Affected Internet Explorer version is 8.

At the moment, there is no patch released againts the vulnerability. About workarounds can be read here.

Friday, May 3, 2013

Adobe PDF Leakage Issue To Be Fixed May 14

Adobe stated in their blog that there will be a fix released to a low severity issue affecting Adobe Reader and Acrobat products. User's IP address and timestamp could be exposed when a specifically crafted PDF document is opened. The fix will be included in the next Adobe Reader and Acrobat versions scheduled to be released on May 14.

The problem was originally found and reported by McAfee researchers (blog post).