Tuesday, April 29, 2014

Adobe Flash Player Updates Available

Adobe have released updated versions of their Flash Player. The new versions fix critical categorized vulnerability (CVE-2014-0515).

Affected versions:

- Users of Adobe Flash Player 13.0.0.182 and earlier versions for Windows Internet Explorer should update to Adobe Flash Player 13.0.0.206.
   
- Users of Adobe Flash Player 13.0.0.201 and earlier versions for Macintosh should update to Adobe Flash Player 13.0.0.206.

- Users of Adobe Flash Player 11.2.202.350 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.356.

- Flash Player integrated with Google Chrome will be updated by Google via Chrome update

- Flash Player integrated with Internet Explorer 10 and 11 (on Windows 8.0 and Windows 8.1) will be updated via Windows Update



More information can be read from Adobe's security bulletin.

Vulnerability In Internet Explorer

Microsoft is aware of a vulnerability affecting Internet Explorer web browser 6-11 versions. The vulnerability (CVE-2014-1776) could allow remote code execution if a user opens a specially crafted website using an affected version of Internet Explorer.

At the moment there is no patch for the vulnerability available. For a workaround and more information please see the related security advisory.

Friday, April 25, 2014

Google Chrome Updated

Google have released version 34.0.1847.131 of their Chrome web browser. Among other bug fixes the new version contains a new version (13.0.0.206) of Flash Player.

More information in Google Chrome Releases blog.

Monday, April 21, 2014

Oracle Critical Patch Update For Q2 of 2014

Oracle have released updates for their products that fix 104 security issues (including 37 Java fixes) in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).

Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.

Next Oracle CPU is planned to be released in July 2014.

Friday, April 18, 2014

Vulnerability In Wireshark

There has been found a vulnerability in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerability an attacker may be able to make Wireshark crash, hang, or execute code by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Vulnerable versions are: 1.10.0 - 1.10.3

Non vulnerable version of Wireshark can be downloaded here.

More information can be read from the related advisory.

Tuesday, April 15, 2014

ESET Global Threat Report for March 2014

ESET have published a report discussing global threats of March 2014.

TOP 10 threats list (previous ranking listed too):

1. WIN32/Bundpil (1.)
2. LNK/Agent.AK (2.)
3. Win32/Sality (3.)
4. INF/Autorun (4.)
5. Win32/Qhost (5.)
6. HTML/ScrInject (6.)
7. Win32/Conficker (8.)
8. Win32/Ramnit (7.)
9. Win32/Dorkbot (9.)
10. JS/Fbook (-)


Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).

Friday, April 11, 2014

Google Chrome Updated

Google have released version 34.0.1847.116 of their Chrome web browser. Among other bug fixes the new version contains fixes to 31 security issues and also a new version (13.0.0.182) of Flash Player.

More information in Google Chrome Releases blog.