releeh.com: David Wheeler’s Professional Portfolio

Apple Releases QuickTime 7.7.2

Apple has released QuickTime 7.7.2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review Apple Support Article HT5261 and apply any necessary updates to help mitigate the risk.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Google Releases Google Chrome 19

Google has released Google Chrome 19 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review the Google Chrome Release blog entry and update to Chrome 19.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Hardening the network against targeted APT attacks

Mike Chapple offers best practices to defend your network against the latest threat to the security landscape, targeted APT attacks.

Add to digg
Add to StumbleUpon
Add to del.icio.us
Add to Google


Adobe Releases Security Bulletins for Multiple Products

Adobe has released security bulletins to alert users of critical vulnerabilities in multiple products. The following products are affected:

  • Adobe Illustrator CS 5.5 and earlier versions for Windows and Macintosh
  • Adobe Photoshop CS 5.5 and earlier versions for Windows and Macintosh
  • Adobe Flash Professional CS 5.5 (11.5.1.349) and earlier versions for Windows and Macintosh
  • Shockwave Player 11.6.4.634 and earlier versions for Windows and Macintosh

Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code or take control of an affected system.

US-CERT encourages users and administrators to review the Adobe security bulletin and apply any necessary updates to help mitigate the risk.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Apple Releases iOS 5.1.1

Apple has released iOS 5.1.1 for iPhone, iPod, iPad, and iPad 2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, perform a cross-site-scripting attack, or spoof a website address.

US-CERT encourages users and administrators to review Apple Support Article HT5278 and apply any necessary updates to help mitigate the risk.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

RuggedCom Rugged Operating System Vulnerability

RuggedCom Rugged Operating System (ROS), used in RuggedCom network infrastructure devices, contains a hard-coded user account with a predictable password.

This user account cannot be manually disabled. An attacker who successfully guesses the password may be able to gain complete administrative control of the ROS device.

As a workaround, RuggedCom has recommended disabling the rsh service and setting the number of telnet connections allowed to 0.

For more information, please see US-CERT Vulnerability Note VU#889195.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

HTML5 security: Will HTML5 replace Flash and increase Web security?

Will HTML5 replace Flash? Expert Michael Cobb discusses whether HTML5 security is better than Flash, and why HTML5 traffic can be harder to secure.

Add to digg
Add to StumbleUpon
Add to del.icio.us
Add to Google


Oracle Releases Critical Patch Update for April 2012

Oracle has released its Critical Patch Update for April 2012 to address 88 vulnerabilities across multiple products. This updates contains the following security fixes:

  • 6 for Oracle Database Server
  • 11 for Oracle Fusion Middleware
  • 6 for Oracle Enterprise Manager Grid Control
  • 4 for Oracle E-Business Suite
  • 5 for Oracle Supply Chain Product Suite
  • 15 for Oracle PeopleSoft Products
  • 2 for Oracle Industry Applications
  • 17 for Oracle Financial Services Software
  • 1 for Oracle Primavera Product Suite
  • 15 for Oracle Sun Product Suite
  • 6 for Oracle MySQL

US-CERT Encourages users and administrators to review the April 2012 Critical Patch Update and apply any necessary updates to help mitigate the risks.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Screencast: Burp Suite tutorial highlights Burp Proxy, other key tools

In this screencast, Mike McLaughlin offers a short Burp Suite tutorial, including the key features of this powerful pen testing tool: Burp Proxy.

Add to digg
Add to StumbleUpon
Add to del.icio.us
Add to Google


Apple Releases Flashback Malware Security Updates

Apple has released security updates to address Flashback malware in the following products:

  • OS X Lion v10.7.3
  • OS X Lion Server v10.7.3
  • Mac OS X v10.6.8
  • Mac OS X Server v10.6.8

Apple has released a malware removal tool for the most common variant of the Flashback malware. If the malware is discovered, the tool will notify the user and remove it automatically. If the malware is not discovered, no indication will be given.

US-CERT encourages users and administrators to review article HT5247 and HT5254 and apply any necessary updates to help mitigate the risk.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify