Monday, August 31, 2020

Mozilla Thunderbird Updated

Mozilla have released updated versions of their Thunderbird email client containing fixes to security vulnerabilities.

Affected versions:
- Mozilla Thunderbird earlier than 78.2 (advisory)
- Mozilla Thunderbird earlier than 68.12 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading from the product site.

Mozilla Firefox Vulnerabilities Fixed

Mozilla have released updated versions of their Firefox web browser. New versions fix security vulnerabilities.

Affected versions:
-Mozilla Firefox earlier than 80 (advisory)
-Mozilla Firefox ESR 78.x earlier than 78.2 (advisory)
-Mozilla Firefox ESR 68.x earlier than 68.12 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.

VMware Vulnerabilities Fixed

VMware have released updated versions of their virtualization software patching a security vulnerability (CVE-2020-3976).

Affected versions:
-VMware ESXi 7.0 without ESXi_7.0.0-1.25.16324942 update
-VMware ESXi 6.7 without ESXi670-202008101-SG / ESXi670-202008401-BG update
-VMware ESXi 6.5 without ESXi650-202007401-BG / ESXi650-202007101-SG update
-VMware Cloud Foundation (ESXi) 4.x.x versions earlier than 4.0.1
-VMware Cloud Foundation (ESXi) 3.x.x versions earlier than 3.10.0
-vCenter Server 7.x versions earlier than 7.0.0b
-vCenter Server 6.7.x versions earlier than 6.7u3j
-vCenter Server 6.5.x versions earlier than 6.5u3k
-VMware Cloud Foundation (vCenter) 4.x.x versions earlier than 4.0.1
-VMware Cloud Foundation (vCenter) 3.x.x versions earlier than 3.10.1 (release pending)

More information in VMware advisory here.

Thursday, August 27, 2020

New Chrome Version Available

Google have released a version 85.0.4183.83 of their Chrome web browser. In addition to other changes 20 security vulnerabilities were fixed. More information about changes can be viewed in Google Chrome release blog.

Friday, August 14, 2020

vBulletin Update Available

There has been released an update to vBulletin, a popular forum software that is used on almost 20000 internet sites to address a critical security vulnerability. The vulnerability bypasses a fix for CVE-2019-16759, a previously disclosed remote code execution vulnerability in vBulletin. There have already been seen attacks in the wild exploiting this vulnerability.

Currently there are fix available for these vBulletin versions:
5.6.2
5.6.1
5.6.0

All other versions of vBulletin prior to the 5.6.x branch are considered vulnerable. Users should migrate over to a patched version as soon as possible.

Instructions for updating:
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2-security-patch

More information:
https://www.tenable.com/blog/zero-day-remote-code-execution-vulnerability-in-vbulletin-disclosed

Wednesday, August 12, 2020

Google Chrome Updated

Google have released a version 84.0.4147.125 of their Chrome web browser. In addition to other changes 15 security vulnerabilities were fixed. More information about changes can be viewed in Google Chrome release blog.

Adobe Lightroom Updated

Adobe have released security update to fix a vulnerability (CVE-2020-9724) in Adobe Lightroom Classic. Exploiting the vulnerability could lead to privilege escalation in the context of the current user.

Affected versions:
*Lightroom Classic earlier than 9.3


Users of vulnerable versions are instructed to update their versions by using the Creative Cloud desktop app's update functionality (help).

More information about fixed vulnerability can be read from Adobe's security bulletin.