Google have released version 38.0.2125.122 of their Chrome web browser. Among other fixes (log) the new version contains an update for Adobe Flash.
More information about these in Google Chrome Releases blog.
Wednesday, November 12, 2014
Adobe Flash Player And Adobe AIR Updates Available
Adobe have released updated versions of their Flash Player and AIR. The new versions fix critical vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.
Affected versions:
- Users of Adobe Flash Player 15.0.0.189 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 15.0.0.223
- Users of Adobe Flash Player 11.2.202.411 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.418
- Flash Player integrated with Google Chrome will be updated by Google via Chrome update
- Flash Player integrated with Internet Explorer 10 and 11 (on Windows 8.x) will be updated via Windows Update
- Users of the Adobe AIR 15.0.0.302 SDK and earlier versions should update to the Adobe AIR 15.0.0.356 SDK.
- Users of the Adobe AIR 15.0.0.302 SDK & Compiler and earlier versions should update to the Adobe AIR 15.0.0.356 SDK & Compiler.
- Users of Adobe AIR 15.0.0.293 and earlier versions for Android should update to Adobe AIR 15.0.0.356.
- Users of Adobe AIR 15.0.0.293 and earlier versions for Windows and Macintosh should update to Adobe 15.0.0.356.
More information can be read from Adobe's security bulletin.
Affected versions:
- Users of Adobe Flash Player 15.0.0.189 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 15.0.0.223
- Users of Adobe Flash Player 11.2.202.411 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.418
- Flash Player integrated with Google Chrome will be updated by Google via Chrome update
- Flash Player integrated with Internet Explorer 10 and 11 (on Windows 8.x) will be updated via Windows Update
- Users of the Adobe AIR 15.0.0.302 SDK and earlier versions should update to the Adobe AIR 15.0.0.356 SDK.
- Users of the Adobe AIR 15.0.0.302 SDK & Compiler and earlier versions should update to the Adobe AIR 15.0.0.356 SDK & Compiler.
- Users of Adobe AIR 15.0.0.293 and earlier versions for Android should update to Adobe AIR 15.0.0.356.
- Users of Adobe AIR 15.0.0.293 and earlier versions for Windows and Macintosh should update to Adobe 15.0.0.356.
More information can be read from Adobe's security bulletin.
Microsoft Security Updates For November 2014
Microsoft have released security updates for November 2014. This month update contains fourteen security bulletins of which four categorized as critical, eight as important and two as moderate.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
Monday, November 10, 2014
Google Study About Manual Hijacking
Account hijacking is a thing that happens a lot. There are different types of hijacking of which one of the most common is mass hijacking. In this case, an automated process uses compromised systems to send out spam messages, malware and phishing campaigns to get even more accounts hijacked. This kind of attacks are usually targeting political institutions, universities, governments and corporations.
Another type of hijacking is so called manual hijacking. This type of attacks are targeting normal users and are done by individuals instead of automated botnets.
Google have published a study they made about manual hijacking. This study can be viewed here (as a pdf document)
Another type of hijacking is so called manual hijacking. This type of attacks are targeting normal users and are done by individuals instead of automated botnets.
Google have published a study they made about manual hijacking. This study can be viewed here (as a pdf document)
Friday, November 7, 2014
Also 53 Million Email Addresses Taken In Home Depot Data Breach
Some time ago Home Depot was in headlines with a data breach where 56 million credit card account details were compromised. During the investigation of that data breach Home Depot found out that the payment data was not the only thing stolen but that 53 million email addresses were taken too.
More information in Home Depot press release.
More information in Home Depot press release.
Sunday, October 19, 2014
Mozilla Product Updates Released
Mozilla have released updates to Firefox browser and Thunderbird email client to address a bunch of vulnerabilities of which three categorized as critical, four as high and two as moderate.
Affected products are:
- Mozilla Firefox earlier than 33
- Mozilla Firefox ESR earlier than 31.2
- Mozilla Thunderbird earlier than 31.2
Links to the security advisories with details about addressed security issues:
MFSA 2014-82 Accessing cross-origin objects via the Alarms API
MFSA 2014-81 Inconsistent video sharing within iframe
MFSA 2014-80 Key pinning bypasses
MFSA 2014-79 Use-after-free interacting with text directionality
MFSA 2014-78 Further uninitialized memory use during GIF
MFSA 2014-77 Out-of-bounds write with WebM video
MFSA 2014-76 Web Audio memory corruption issues with custom waveforms
MFSA 2014-75 Buffer overflow during CSS manipulation
MFSA 2014-74 Miscellaneous memory safety hazards (rv:33.0 / rv:31.2)
Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
Affected products are:
- Mozilla Firefox earlier than 33
- Mozilla Firefox ESR earlier than 31.2
- Mozilla Thunderbird earlier than 31.2
Links to the security advisories with details about addressed security issues:
MFSA 2014-82 Accessing cross-origin objects via the Alarms API
MFSA 2014-81 Inconsistent video sharing within iframe
MFSA 2014-80 Key pinning bypasses
MFSA 2014-79 Use-after-free interacting with text directionality
MFSA 2014-78 Further uninitialized memory use during GIF
MFSA 2014-77 Out-of-bounds write with WebM video
MFSA 2014-76 Web Audio memory corruption issues with custom waveforms
MFSA 2014-75 Buffer overflow during CSS manipulation
MFSA 2014-74 Miscellaneous memory safety hazards (rv:33.0 / rv:31.2)
Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
Labels:
Firefox,
Mozilla,
security,
thunderbird,
update,
vulnerability
Adobe Flash Player And Adobe AIR Updates Available
Adobe have released updated versions of their Flash Player and AIR. The new versions fix critical vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.
Affected versions:
- Users of Adobe Flash Player 15.0.0.167 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 15.0.0.189
- Users of Adobe Flash Player 11.2.202.406 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.411
- Flash Player integrated with Google Chrome will be updated by Google via Chrome update
- Flash Player integrated with Internet Explorer 10 and 11 (on Windows 8.x) will be updated via Windows Update
- Users of the Adobe AIR 15.0.0.249 SDK and earlier versions should update to the Adobe AIR 15.0.0.302 SDK.
- Users of the Adobe AIR 14.0.0.249 SDK & Compiler and earlier versions should update to the Adobe AIR 15.0.0.302 SDK & Compiler.
- Users of Adobe AIR 15.0.0.252 and earlier versions for Android should update to Adobe AIR 15.0.0.293.
- Users of Adobe AIR 15.0.0.249 and earlier versions for Windows and Macintosh should update to Adobe 15.0.0.293.
More information can be read from Adobe's security bulletin.
Affected versions:
- Users of Adobe Flash Player 15.0.0.167 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 15.0.0.189
- Users of Adobe Flash Player 11.2.202.406 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.411
- Flash Player integrated with Google Chrome will be updated by Google via Chrome update
- Flash Player integrated with Internet Explorer 10 and 11 (on Windows 8.x) will be updated via Windows Update
- Users of the Adobe AIR 15.0.0.249 SDK and earlier versions should update to the Adobe AIR 15.0.0.302 SDK.
- Users of the Adobe AIR 14.0.0.249 SDK & Compiler and earlier versions should update to the Adobe AIR 15.0.0.302 SDK & Compiler.
- Users of Adobe AIR 15.0.0.252 and earlier versions for Android should update to Adobe AIR 15.0.0.293.
- Users of Adobe AIR 15.0.0.249 and earlier versions for Windows and Macintosh should update to Adobe 15.0.0.293.
More information can be read from Adobe's security bulletin.
Subscribe to:
Posts (Atom)