Tuesday, January 26, 2010

New Version of Google Chrome Released

Google has released a new version of their Chrome web browser. The first stable version of Chrome 4 contains some new features like long-waited support for extensions and bookmark syncing. A bunch of security issues has been fixed too.

More information can be read from Chrome Releases blog.

Saturday, January 23, 2010

Microsoft Patches Internet Explorer Vulnerability

Microsoft has fixed the Internet Explorer (IE) vulnerability I blogged about last week. The update MS10-002 patches also a few other IE vulnerabilities. More details can be read from the correspondent security bulletin.

Wednesday, January 20, 2010

Updated Shockwave Player Available

Adobe has released a new version of their Shockwave Player. The update contains fixes for a few vulnerabilities that could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. The affected versions are Shockwave Player 11.5.2.602 and earlier. Fresh version can be obtained here.

More information can be read on Adobe's Security Bulletin.

Security Updates For RealPlayer

RealNetworks has released updates that patch eleven vulnerabilities in different RealPlayer versions. More information about affected versions and patching can be read here.

Monday, January 18, 2010

Vulnerabilities In D-Link Routers

SourceSec writes in their blog about vulnerabilities in D-Link routers' HNAP (Home Network Administration Protocol) implementations. "While HNAP does require basic authentication, the mere existence of HNAP on D-Link routers allows attackers and malware to bypass CAPTCHA “security”. Further, HNAP authentication is not properly implemented, allowing anyone to view and edit administrative settings on the router."

SourceSec has verified that vulnerabilities exist in the HNAP implementations of the DI-524, DIR-628 and DIR-655 routers. They also suspect that in worst case all D-Link routers since 2006 could be affected.

Full writeup can be read here.

Friday, January 15, 2010

Reported Vulnerability In Internet Explorer

Microsoft is investigating a report of publicly exploited vulnerability in Internet Explorer.The vulnerability exists as an invalid pointer reference within Internet Explorer and when exploited successfully can be used to allow remote code execution in target system.

Affected Internet Explorer versions are:
-Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 and
-Internet Explorer 6, Internet Explorer 7 and Internet Explorer 8 on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2

Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 is not affected.

Currently there's no patch available. There're some workarounds listed in the corresponding security advisory though.

Wednesday, January 13, 2010

Patches To Oracle Products Available

Oracle has released updates for 24 security vulnerabilities as a part of their quarterly released critical patch update (CPU).

Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.

Next Oracle CPU is planned to be released in April 2010.