Friday, December 13, 2013

Mozilla Product Updates Released

Mozilla have released updates to Firefox and Seamonkey browsers and Thunderbird email client to address a bunch of vulnerabilities of which five categorized as critical, three as high, three as moderate and three as low.

Affected products are:
- Mozilla Firefox earlier than 26
- Mozilla Firefox ESR 24.x earlier than 24.1
- Mozilla Thunderbird earlier than 24.2
- Mozilla Thunderbird ESR 17.x earlier than 17.0.11
- Mozilla SeaMonkey earlier than 2.23

Links to the security advisories with details about addressed security issues:
MFSA 2013-117 Mis-issued ANSSI/DCSSI certificate
MFSA 2013-116 JPEG information leak
MFSA 2013-115 GetElementIC typed array stubs can be generated outside observed typesets
MFSA 2013-114 Use-after-free in synthetic mouse movement
MFSA 2013-113 Trust settings for built-in roots ignored during EV certificate validation
MFSA 2013-112 Linux clipboard information disclosure though selection paste
MFSA 2013-111 Segmentation violation when replacing ordered list elements
MFSA 2013-110 Potential overflow in JavaScript binary search algorithms
MFSA 2013-109 Use-after-free during Table Editing
MFSA 2013-108 Use-after-free in event listeners
MFSA 2013-107 Sandbox restrictions not applied to nested object elements
MFSA 2013-106 Character encoding cross-origin XSS attack
MFSA 2013-105 Application Installation doorhanger persists on navigation
MFSA 2013-104 Miscellaneous memory safety hazards (rv:26.0 / rv:24.2)


Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey

Wednesday, December 11, 2013

Microsoft Security Updates For December 2013

Microsoft have released security updates for December 2013. This month update contains 11 security bulletins of which five critical and six important.

A new version of Windows Malicious Software Removal Tool (MSRT) was released too.

More information can be read from the bulletin summary.

VMWare Updates Available

VMware has released security update to patch a vulnerability in their virtualization applications. The vulnerability is in LGTOSYNC.SYS driver and when exploited could result in a privilege escalation on 32-bit Guest Operating Systems running Windows 2000 Server, Windows XP or Windows 2003 Server on ESXi and ESX; or Windows XP on Workstation and Fusion.

Affected versions:
- Workstation earlier than 9.0.3
- Player 5.x Windows earlier than 5.0.3
- Fusion 5.x Mac OS/X versions earlier than 5.0.4
- ESXi 5.1 ESXi
- ESXi 5.0 ESXi
- ESXi 4.1 ESXi
- ESXi 4.0 ESXi
- ESX 4.1 ESX
- ESX 4.0 ESX


Further information including updating instructions can be read from VMware's security advisory.

Thursday, December 5, 2013

Google Chrome Updated

Google have released version 31.0.1650.63 of their Chrome web browser. New version contains fixes to 15 vulnerabilities.

More information in Google Chrome Releases blog.

Wednesday, November 27, 2013

Symantec Intelligence Report: October 2013

Symantec have published their Intelligence report that sums up the latest threat trends for October 2013.

Report highlights:
- This month saw one of the largest data breaches in a number of years, where as many as 150 million identities were exposed due to one breach.
- October saw a fivefold increase in targeted attacks compared to last month, even surpassing this time of year in 2011 and 2012, though still much lower than the summer peak.
- The total number of mobile vulnerabilities disclosed dropped significantly. In September a major update to a popular mobile operating system addressed a number of vulnerabilities, raising the count for that month.

The report (in PDF format) can be viewed here.

Mozilla Product Security Updates Released

Mozilla have released updates to Firefox and Seamonkey browsers and Thunderbird email client to address a few NSS library (Network Security Services) related vulnerabilities. Update is categorized as critical

Affected products are:
- Mozilla Firefox earlier than 25.0.1
- Mozilla Firefox ESR 24.x earlier than 24.1.1
- Mozilla Firefox ESR 17.x earlier than 17.0.11
- Mozilla Thunderbird earlier than 24.1.1
- Mozilla Thunderbird ESR 17.x earlier than 17.0.11
- Mozilla SeaMonkey earlier than 2.22.1

Link to the security advisory with details about addressed security issues:
MFSA 2013-103 Miscellaneous Network Security Services (NSS) vulnerabilities


Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey

Monday, November 18, 2013

Google Chrome Update Available

Google have released version 31.0.1650.57 of their Chrome web browser. New version contains a fix to a critical vulnerability (CVE-2013-6632).

More information in Google Chrome Releases blog.