Saturday, March 28, 2009

Firefox Update Released

Mozilla has released a new version of Firefox which fixes two vulnerabilities. One of the vulnerabilities affects also Mozilla Seamonkey. Both vulnerabilities makes it possibly to execute arbitrary code in target system.

The first vulnerability can be exploited by luring a user to open specially crafted XML file. That results to browser crash and an attacker may be able to execute malicious code in target system. Also Mozilla Seamonkey is affected by this vulnerability.

The other fixed vulnerability is related to the handling of XUL element. By exploiting the vulnerability an attacker may make target browser crash and execute malicious code in target system. This vulnerability doesn't affect Seamonkey and older Firefox 2.x.x versions.

Vulnerable versions are:
- Mozilla Firefox prior 3.0.8 version
- Mozilla Seamonkey 1.1.15 and earlier versions

Firefox users should get version 3.0.8 either thru browser's in-built updater or by downloading the latest version here. Seamonkey users have to wait for update since it's not released at the moment of writing this. It can be found here when released.

Firefox 3.0.8 release notes can be found here.

Thursday, March 26, 2009

New Java SE Runtime Environment (JRE) Update Available

Sun has released update for Java SE Runtime Environment (JRE) 6 (JRE allows end-users to run Java applications) to fix a bunch of security vulnerabilities and other bugs. By exploiting the vulnerabilities an attacker may be able to cause denial of service, gain escalated privileges and execute arbitrary code in target system.

Found vulnerabilities are related to HTTP and LDAP implementation, JAR -file unpacking, PNG and GIF image handling and saving & handling fonts. Java Plug-in used in web browsers is vulnerable too.

The latest update can be downloaded from Sun's Java SE Downloads site. Release notes of Java SE 6 Update 13 can be read here.

Tuesday, March 24, 2009

Tool For Flash Vulnerability Detecting Released

Hewlett-Packard (HP) has released a free tool named HP SWFScan, which according to the company, can help Flash developers protect their websites against unintended application security vulnerabilities and reduce the risk of hackers accessing sensitive data.

HP SWFScan helps identify vulnerabilities that lie under the surface of an application and are not detectable with traditional dynamic methods. One example of these are for example xss -vulnerabilities (cross site scripting). The tool guides developers on fixing found vulnerabilities in source code so that those get fixed according to best security practices.

"Flash developers often create an unintentional vulnerability by encoding access information such as passwords, encryption keys or database information directly into their applications," states HP.

HP analyzed almost 4,000 web applications developed with Flash. 35 percent of these contained things that violate Adobe security best practices.


Related press release can be read here.

Tuesday, March 17, 2009

Norton Online Living Report 09

Annual Norton Online Living Report has been released. According to the report half of internet using adults visit intentionally on dubious websites. User doesn't create backups and uses easily breakable passwords. Every third adult taking part in the survey told that one's system had gotten infected by malware.

Careless surfing, irresponsibility and malware infected systems are alarming general shows the survey. Still, 99% of adults claims protecting personal information.

The survey covered twelve countries. According to the survey also children could do better. Every fifth child told being blamed for one's way of using internet. Still parents seem to be badly unaware of their children internet use - children tell that they spend time in internet twice as much as their parents think.

The survey was conducted by Harris Interactive assigned by Symantec during October-December 2008. 6,427 over 18 years old adults attended the survey.

Whole report can be downloaded here. The Survey Data is also available.

Wednesday, March 11, 2009

Patch For Adobe Reader And Acrobat Available

A few weeks ago I blogged about unpatched vulnerability in Adobe Reader & Acrobat.

Adobe has now released version 9.1 that fixes mentioned vulnerability. Users of 7 and 8 have to still wait unless they update to 9.1. Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

More details and instructions how to get a new version can be found from Adobe's security advisory.

Microsoft Updates For March 2009 Released

Microsoft has released updates for March. This time release contains three updates which fix eight vulnerabilities in Windows operating system. One of the updates is categorized as critical (MS09-006) and other two as important (MS09-007 & MS09-008).

New version of Microsoft Windows Malicious Software Removal Tool was also released.

More information about the updates can be read here.

The easist way to get the update is to use Microsoft automatic update service.

Tuesday, March 10, 2009

Foxit Reader Vulnerable

Foxit Reader is a light alternative to Adobe Reader used for PDF file reading. There's now found vulnerabilities in its way to handle open/execute a file action. That makes the software victim of two kinds of vulnerabilities: authorization bypass and buffer overflow.

Vulnerable are at least builds 1120 and 1301 of Foxit Reader 3.0. Older builds of 3.0 are probably affected too, but they weren't checked.

Foxit Reader users are recommended to update to the latest version (at the moment Foxit Reader 3.0 build 1506). It can be done by either using in-built updater or by downloading new version here.

More information can be read from Foxit Reader security bulletins.