Adobe warns about two vulnerabilities in its Adobe Reader and Acrobat products. The vulnerabilities are related to the way of handling getAnnots() and customDictionaryOpen() JavaScript calls. The vulnerabilities can be exploited by luring user to open specially crafted PDF file. Successful exploitation makes it possible to execute arbitrary code in target system.
Vulnerable versions are:
* Adobe Reader and Acrobat 9.1 and earlier versions (Windows, Unix, Mac)
* Adobe Reader and Acrobat 8.1.4 and earlier versions (Windows, Unix, Mac)
* Adobe Reader and Acrobat 7.1.1 and earlier versions (Windows, Mac)
Currently, there's no update or schedule of upcoming one available. Adobe recommends disabling JavaScript support in Adobe products until update is available and installed.
Disabling can be done by following these steps:
1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the ‘Enable Acrobat JavaScript’ option
5. Click OK
Opening PDF documents received or found from dubious sources should be avoided.
More information can be found here.
Wednesday, April 29, 2009
Firefox Gets New Update Again
Mozilla released Firefox 3.0.9 last week and now it's time for a new one. Version 3.0.10 contains fixes to a security issue and to a major stability issue + other bug fixes. Details about the update can be found in release notes here.
Update will be provided thru automatic update functionality in Firefox. Alternatively, new version can be downloaded from http://getfirefox.net/.
Update will be provided thru automatic update functionality in Firefox. Alternatively, new version can be downloaded from http://getfirefox.net/.
Friday, April 24, 2009
Ransomware Takes PC Hostage
Security company Panda writes in their blog about malicious software that takes PC hostage. If user doesn't pay the ransom, PC can't be used. According to Panda, Trj/Smslock.A works differently from most older ransomware. Traditionally, ransomware has for example encrypted important folders and files (e.g. Gpcode). In order to get a decryption key user has been asked to pay ransom to the criminals.
However, Trj/Smslock.A is different from those older ones. It takes whole PC hostage locking the access to the system. Instructions for unlocking are displayed on the screen. The instructions ask user to send an SMS text message with a series of numbers to some service number. In return, user receives a code that will open the lock.
Used language indicates the target victims are Russian speaking users.
However, Trj/Smslock.A is different from those older ones. It takes whole PC hostage locking the access to the system. Instructions for unlocking are displayed on the screen. The instructions ask user to send an SMS text message with a series of numbers to some service number. In return, user receives a code that will open the lock.
Used language indicates the target victims are Russian speaking users.
Wednesday, April 22, 2009
Firefox 3.0.9 Released
Mozilla has released a new version of its Firefox web browser. Version 3.0.9 contains updates for 12 vulnerabilities of which four are critical and may make it possible for an attacker to execute arbitrary code in target system.
Mozilla recommends all Firefox users to update to the latest version. Update can be made with automatic update functionality in Firefox or by installing new version from http://getfirefox.net.
Details about the update can be read from releasenotes of 3.0.9 version.
Mozilla recommends all Firefox users to update to the latest version. Update can be made with automatic update functionality in Firefox or by installing new version from http://getfirefox.net.
Details about the update can be read from releasenotes of 3.0.9 version.
Monday, April 20, 2009
AV Antispyware - New Rogue Security Program
WinSpywareProtect, rogue security program family, has gotten a new member named as AV Antispyware.
Its associated sites are:
64.191.12.38 Av-antispyware com
195.88.81.74 Files scanner-antispy-av-files com
195.88.81.116 dl scan-antispy-4pc com
195.88.80.207 Int reporting32 com
Bleeping Computer has a tutorial that guides in uninstalling and removing this pest.
Its associated sites are:
64.191.12.38 Av-antispyware com
195.88.81.74 Files scanner-antispy-av-files com
195.88.81.116 dl scan-antispy-4pc com
195.88.80.207 Int reporting32 com
Bleeping Computer has a tutorial that guides in uninstalling and removing this pest.
Wednesday, April 15, 2009
Critical Vulnerability In VMware
There has been found a critical vulnerability in VMware virtualization software products. The vulnerability in the virtual machine display function might allow a guest operating system to run code on the host.
Affected versions are:
-VMware Workstation 6.5.1 and earlier,
-VMware Player 2.5.1 and earlier,
-VMware ACE 2.5.1 and earlier,
-VMware Server 2.0,
-VMware Server 1.0.8 and earlier,
-VMware Fusion 2.0.3 and earlier,
-VMware ESXi 3.5 without patch ESXe350-200904201-O-SG,
-VMware ESX 3.5 without patch ESX350-200904201-SG,
-VMware ESX 3.0.3 without patch ESX303-200904403-SG,
-VMware ESX 3.0.2 without patch ESX-1008421.
Users of affected versions are recommended to update their versions according to the VMware's instructions.
Affected versions are:
-VMware Workstation 6.5.1 and earlier,
-VMware Player 2.5.1 and earlier,
-VMware ACE 2.5.1 and earlier,
-VMware Server 2.0,
-VMware Server 1.0.8 and earlier,
-VMware Fusion 2.0.3 and earlier,
-VMware ESXi 3.5 without patch ESXe350-200904201-O-SG,
-VMware ESX 3.5 without patch ESX350-200904201-SG,
-VMware ESX 3.0.3 without patch ESX303-200904403-SG,
-VMware ESX 3.0.2 without patch ESX-1008421.
Users of affected versions are recommended to update their versions according to the VMware's instructions.
Pack of Updates From Oracle
Oracle has released updates that contains fixes to 43 different vulnerabilities. The fixes are part of the company's quarterly CPU (critical patch update). Of the updates 16 are for Oracle Database, 12 for Oracle Application Server, three for Oracle E-Business Suite, four for PeopleSoft Enterprise and JDEdwards Suite and eight updates for BEA product Suite.
Exact list of the vulnerabilities and instructions how to apply the fixes can be read from Oracle's Critical Patch Update Advisory.
Next critical patch update Oracle plans to release 14 July 2009.
Exact list of the vulnerabilities and instructions how to apply the fixes can be read from Oracle's Critical Patch Update Advisory.
Next critical patch update Oracle plans to release 14 July 2009.
Subscribe to:
Posts (Atom)