Mozilla have released updates to Firefox and Seamonkey browsers and Thunderbird email client to address a bunch of vulnerabilities of which five categorized as critical, three as high, three as moderate and three as low.
Affected products are:
- Mozilla Firefox earlier than 26
- Mozilla Firefox ESR 24.x earlier than 24.1
- Mozilla Thunderbird earlier than 24.2
- Mozilla Thunderbird ESR 17.x earlier than 17.0.11
- Mozilla SeaMonkey earlier than 2.23
Links to the security advisories with details about addressed security issues:
MFSA 2013-117 Mis-issued ANSSI/DCSSI certificate
MFSA 2013-116 JPEG information leak
MFSA 2013-115 GetElementIC typed array stubs can be generated outside observed typesets
MFSA 2013-114 Use-after-free in synthetic mouse movement
MFSA 2013-113 Trust settings for built-in roots ignored during EV certificate validation
MFSA 2013-112 Linux clipboard information disclosure though selection paste
MFSA 2013-111 Segmentation violation when replacing ordered list elements
MFSA 2013-110 Potential overflow in JavaScript binary search algorithms
MFSA 2013-109 Use-after-free during Table Editing
MFSA 2013-108 Use-after-free in event listeners
MFSA 2013-107 Sandbox restrictions not applied to nested object elements
MFSA 2013-106 Character encoding cross-origin XSS attack
MFSA 2013-105 Application Installation doorhanger persists on navigation
MFSA 2013-104 Miscellaneous memory safety hazards (rv:26.0 / rv:24.2)
Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey
Friday, December 13, 2013
Wednesday, December 11, 2013
Microsoft Security Updates For December 2013
Microsoft have released security updates for December 2013. This month update contains 11 security bulletins of which five critical and six important.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
VMWare Updates Available
VMware has released security update to patch a vulnerability in their virtualization applications. The vulnerability is in LGTOSYNC.SYS driver and when exploited could result in a privilege escalation on 32-bit Guest Operating Systems running Windows 2000 Server, Windows XP or Windows 2003 Server on ESXi and ESX; or Windows XP on Workstation and Fusion.
Affected versions:
- Workstation earlier than 9.0.3
- Player 5.x Windows earlier than 5.0.3
- Fusion 5.x Mac OS/X versions earlier than 5.0.4
- ESXi 5.1 ESXi
- ESXi 5.0 ESXi
- ESXi 4.1 ESXi
- ESXi 4.0 ESXi
- ESX 4.1 ESX
- ESX 4.0 ESX
Further information including updating instructions can be read from VMware's security advisory.
Affected versions:
- Workstation earlier than 9.0.3
- Player 5.x Windows earlier than 5.0.3
- Fusion 5.x Mac OS/X versions earlier than 5.0.4
- ESXi 5.1 ESXi
- ESXi 5.0 ESXi
- ESXi 4.1 ESXi
- ESXi 4.0 ESXi
- ESX 4.1 ESX
- ESX 4.0 ESX
Further information including updating instructions can be read from VMware's security advisory.
Thursday, December 5, 2013
Google Chrome Updated
Google have released version 31.0.1650.63 of their Chrome web browser. New version contains fixes to 15 vulnerabilities.
More information in Google Chrome Releases blog.
More information in Google Chrome Releases blog.
Wednesday, November 27, 2013
Symantec Intelligence Report: October 2013
Symantec have published their Intelligence report that sums up the latest threat trends for October 2013.
Report highlights:
- This month saw one of the largest data breaches in a number of years, where as many as 150 million identities were exposed due to one breach.
- October saw a fivefold increase in targeted attacks compared to last month, even surpassing this time of year in 2011 and 2012, though still much lower than the summer peak.
- The total number of mobile vulnerabilities disclosed dropped significantly. In September a major update to a popular mobile operating system addressed a number of vulnerabilities, raising the count for that month.
The report (in PDF format) can be viewed here.
Report highlights:
- This month saw one of the largest data breaches in a number of years, where as many as 150 million identities were exposed due to one breach.
- October saw a fivefold increase in targeted attacks compared to last month, even surpassing this time of year in 2011 and 2012, though still much lower than the summer peak.
- The total number of mobile vulnerabilities disclosed dropped significantly. In September a major update to a popular mobile operating system addressed a number of vulnerabilities, raising the count for that month.
The report (in PDF format) can be viewed here.
Mozilla Product Security Updates Released
Mozilla have released updates to Firefox and Seamonkey browsers and Thunderbird email client to address a few NSS library (Network Security Services) related vulnerabilities. Update is categorized as critical
Affected products are:
- Mozilla Firefox earlier than 25.0.1
- Mozilla Firefox ESR 24.x earlier than 24.1.1
- Mozilla Firefox ESR 17.x earlier than 17.0.11
- Mozilla Thunderbird earlier than 24.1.1
- Mozilla Thunderbird ESR 17.x earlier than 17.0.11
- Mozilla SeaMonkey earlier than 2.22.1
Link to the security advisory with details about addressed security issues:
MFSA 2013-103 Miscellaneous Network Security Services (NSS) vulnerabilities
Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey
Affected products are:
- Mozilla Firefox earlier than 25.0.1
- Mozilla Firefox ESR 24.x earlier than 24.1.1
- Mozilla Firefox ESR 17.x earlier than 17.0.11
- Mozilla Thunderbird earlier than 24.1.1
- Mozilla Thunderbird ESR 17.x earlier than 17.0.11
- Mozilla SeaMonkey earlier than 2.22.1
Link to the security advisory with details about addressed security issues:
MFSA 2013-103 Miscellaneous Network Security Services (NSS) vulnerabilities
Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey
Labels:
Firefox,
Mozilla,
seamonkey,
security,
thunderbird,
update,
vulnerability
Monday, November 18, 2013
Google Chrome Update Available
Google have released version 31.0.1650.57 of their Chrome web browser.
New version contains a fix to a critical vulnerability (CVE-2013-6632).
More information in Google Chrome Releases blog.
More information in Google Chrome Releases blog.
Subscribe to:
Posts (Atom)