Tag Archives: patches

Firefox version 20 released, patches 11 serious flaws

Firefox wasn’t full of vulnerabilities previously, but now users of Mozilla’s customizable Web browser can rest even easier.


FOX News

Microsoft quietly patches first Modern app for Windows 8, RT

Microsoft earlier this week quietly issued its first security update for one of its Windows 8 apps, patching a link-spoofing vulnerability in Mail.
Computerworld News

Apple updates Mountain Lion, patches Safari

Apple yesterday updated OS X Mountain Lion for the first time in six months, patching 14 security vulnerabilities and addressing a host of other issues.
Computerworld News

NASA to apply two software patches to Curiosity rover

Earlier this month, NASA’s Mars Curiosity rover experienced its first major malfunction, with one of its on-board computers experiencing a “memory glitch” and failing to go into sleep mode. A few days later, the space agency announced that the rover had been transitioned to its secondary computer and put back into active mode. Now, a

Read The Full Story
SlashGear

iOS 6.1.3 Beta 2 Patches evasi0n Jailbreak

hypnosec writes “Apple released iOS 6.1.3 beta 2 to developers, patching at least one of the vulnerabilities used by evasi0n thereby rendering the jailbreak tool useless — the time zone settings vulnerability. David Wang aka @planetbeing, has confirmed that iOS 6.1.3 beta 2 does patch one of the vulnerabilities that they exploited in their evasi0n tool.”

Read more of this story at Slashdot.




Slashdot

Oracle to release yet more patches for Java

Oracle isn’t done releasing patches for Java SE this month, as another batch will arrive Feb. 19, according to a company blog post.
Computerworld News

New Secure Boot Patches Break Hibernation

hypnosec writes “Matthew Garrett published some patches today which break hibernate and kexec support on Linux when Secure Boot is used. The reason for disabling hibernation is that currently the Linux kernel doesn’t have the capability of verifying the resume image when returning from hibernation, which compromises the Secure Boot trust model. The reason for disabling the kexec support while running in Secure Boot is that the kernel execution mechanism may be used to load a modified kernel thus bypassing the trust model of Secure Boot.” Before arming your tactical nuclear flame cannon, note that mjg says “These patches break functionality that people rely on without providing any functional equivalent, so I’m not suggesting that they be merged as-is.” Support for signed kexec should come eventually, but it looks like hibernation will require some clever hacking to support properly in a Restricted Boot environment.

Read more of this story at Slashdot.




Slashdot

Foxit patches critical flaw in PDF viewer browser plug-in

Foxit released version 5.4.5 of its Foxit Reader PDF viewer plug-in on Thursday in order to address a critical remote code execution vulnerability that could have allowed attackers to compromise computers running previous versions of the software.
Computerworld News

Adobe patches exploited ColdFusion flaws

Adobe released security patches for its ColdFusion application server on Tuesday, addressing four critical vulnerabilities that have been actively exploited by attackers since the beginning of January.
Computerworld News

Oracle patches Java exploits, toughens its default security levels

Java disabled in Firefox

Oracle hasn’t had a great start to 2013. It’s barely into the new year, and Apple and Mozilla are already putting up roadblocks to some Java versions after discoveries of significant browser-based exploits. The company has been quick to respond, however, and already has a patched-up version ready to go. The Java update goes one step further to minimize repeat incidents, as well — it makes the “high” setting the default and asks permission before it lauches any applet that wasn’t officially signed. If you’ve been skittish about running a Java plugin ever since the latest exploits became public, hit the source to (potentially) calm your nerves.

[Thanks, Trevor]

Filed under: , ,

Comments

Via: Reuters

Source: Oracle

Engadget

Oracle patches latest zero-day vulnerabilities in Java

Oracle released two out-of-band patches on Sunday for vulnerabilities in its Java programming language, both of which pose a high risk to users browsing the web.
Computerworld News

Microsoft plans patches for IE10, Windows 8 next week

Microsoft today announced it will deliver seven security updates next week to patch 11 vulnerabilities, including the first that apply to Internet Explorer 10, the company’s newest browser.
Computerworld News

Oracle Makes Red Hat Kernel Changes Available As Broken-Out Patches



Artefacto writes “The Ksplice team has made available a git repository with the changes Red Hat made to the kernel broken down. They are calling this project RedPatch. This comes in response to a policy change Red Hat had implemented in early 2011, with the goal of undercutting Oracle and other vendors’ strategy of poaching Red Hat’s customers. The Ksplice team says they’ve been working on these individual patches since then. They claim to be now making it public because they ‘feel everyone in the Linux community can benefit from the work.’ ‘For Ksplice, we build individual updates for each change and rely on source patches that are broken-out, not a giant tarball. Otherwise, we wouldn’t be able to take the right patches to create individual updates for each fix, and to skip over the noise — like a change that speeds up bootup — which is unnecessary for an already-running system.’”

Read more of this story at Slashdot.


Slashdot

Microsoft’s November security updates include critical Windows 8 and RT patches

Microsoft's November security updates include critical Windows 8 and RT patches

Microsoft recently issued its “Security Bulletin Advance Notification” for this month, detailing which operating systems and software will be updated on November 13th. While many products are being addressed, including Office for Mac, newly released Windows 8 and RT are the most notable entries on the list. The first patches since they hit the market will fix “critical” issues which open them up to “remote code execution.” Microsoft hasn’t gone into specifics (obviously), but you can register for a webcast being held on the 14th (see source link) should you want enlightening. If you thought your fresh machine or slate was flawless, we’re afraid to say it’s just another member of the ‘Patch Tuesday’ club.

Filed under: , , ,

Microsoft’s November security updates include critical Windows 8 and RT patches originally appeared on Engadget on Sat, 10 Nov 2012 02:15:00 EDT. Please see our terms for use of feeds.

Permalink The Inquirer  |  sourceMicrosoft, Microsoft TechNet Webcast  | Email this | Comments
Engadget

Windows 8, RT to get first critical security patches next Tuesday

Microsoft’s new OS is up for its first security update to shore up holes that would allow hackers to run malware on unprotected PCs. [Read more]


CNET News

Facebook patches security hole that allowed mass harvesting of phone numbers

Facebook has restricted the rate at which users can perform phone number searches on its mobile website in order to block a recently disclosed method of harvesting phone numbers.
Computerworld News

Microsoft patches critical Flash bugs in Windows 8

Microsoft on Friday updated Flash on Windows 8 to protect IE10 users from attacks that may have started months ago.
Computerworld News

Microsoft hustles, patches IE to ward off increasing attacks

Microsoft today released an emergency patch for Internet Explorer to stymie active attacks that have been exploiting a bug in the browser, finishing a job it started only Monday.
Computerworld News

Apple patches Java 6 for OS X Snow Leopard, Lion

Apple today issued a Java update for OS X Lion and Snow Leopard to make it more difficult for hackers to exploit other vulnerabilities.
Computerworld News

Microsoft patches critical security holes in Windows, Office, IE

Microsoft has fixed 26 vulnerabilities in its software products, including several considered critical, the company said on Tuesday in its monthly security patch report.
Computerworld News

Mozilla ships Firefox 14, patches 18 bugs, encrypts search

Just days after a former employee blasted Mozilla for its frequent updates, the company on Tuesday shipped Firefox 14, patching 18 vulnerabilities and adding automatic encryption of searches passed to Google’s search engine.
Computerworld News

VMware patches arbitrary code execution flaw in desktop, server virtualization products

Virtualization software vendor VMware has released security patches for its Workstation, Player, Fusion, ESXi and ESX products in order to address two vulnerabilities that could allow attackers to compromise the host system or crash a virtual machine.
Computerworld News

Adobe patches critical Flash bugs, ships sandboxed plug-in for Firefox

Adobe today patched seven critical vulnerabilities in Flash Player — the fifth security update so far in 2012 — and released a sandboxed plug-in for Mozilla’s Firefox.
Computerworld News

Apple patches Safari, blocks outdated Flash Player

Apple on Wednesday patched four security vulnerabilities in Safari and blocked outdated versions of Adobe’s Flash Player from running in its browser.
Computerworld News

Adobe patches security flaw in Flash Player for PC, Mac and Android

If you’re reading this on your laptop, desktop or smartphone, odds are pretty good that you’ve got some way, shape or form of Adobe’s Flash Player installed. If that’s the case, scoot your browser on over to the Flash Player update page and download the latest version of Flash Player 11.2 quick, fast and in

Read The Full Story
SlashGear

Adobe patches new Flash zero-day bug with emergency update

Adobe today warned that hackers are exploiting a critical vulnerability in its popular Flash Player program, and issued an emergency update to patch the bug.
Computerworld News

Oracle to issue 88 security patches on Tuesday

Oracle is planning to release 88 patches on Tuesday, covering vulnerabilities affecting a wide array of its products, according to a pre-release announcement posted to its website on Thursday.
Computerworld News

Google patches 9 Chrome bugs, pays more to top researchers

Google yesterday patched nine vulnerabilities in Chrome in the sixth security update to Chrome 17, the edition that launched Feb. 8.
Computerworld News

Google patches 14 Chrome bugs, pays record $47K in bounties and bonuses

Google yesterday patched 14 vulnerabilities in Chrome and handed out a record $ 47,500 in rewards to researchers, including $ 30,000 for “sustained, extraordinary” contributions to its bug-reporting program.
Computerworld News

Adobe patches Flash Player for second time in 20 days

Adobe today patched a pair of critical vulnerabilities in Flash Player and told IT administrators to apply the update within 30 days.
Computerworld News

Microsoft to issue more critical patches next week for Win7 than XP

Microsoft today said it would deliver nine security updates next week, four of them critical, to patch 21 vulnerabilities in Windows, Internet Explorer (IE), Office, .Net and Silverlight.
Computerworld News

Apple updates Lion, patches 51 bugs in Mac OS X

Apple on Tuesday patched 51 vulnerabilities in Mac OS X, most of them critical, in 2012′s first security update.
Computerworld News

Google patches several serious Chrome bugs

Google on Monday patched four vulnerabilities in Chrome, and disclosed that it had patched a fifth two weeks ago.
Computerworld News

PSA: McAfee computer security patches flaw: are you fixed?

Earlier this week, the McAfee group began sending out a fix to stopper up a flaw which turned their protection service into a hijacked spam festival. The flaw, they say, was allowing hackers to attach themselves to your computer specifically and shoot spam throughout your machine – hijacking that which was supposed to be protected [...]
SlashGear

Google patches Chrome, beefs up malicious file blocking tech

Google last week patched Chrome 16 and improved the download warnings in the impending Chrome 17.
Computerworld News

Update: Microsoft plans 20 patches next week, will fix Duqu and BEAST bugs

Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.
Computerworld News

Microsoft plans 20 patches next week, likely to fix Duqu and BEAST bugs

Microsoft today announced it will issue 14 security bulletins next week to patch 20 vulnerabilities in Windows, Internet Explorer (IE), Office, and Windows Media Player.
Computerworld News

FBI Scolds NASDAQ Over Out of Date Patches



DMandPenfold writes “NASDAQ’s aging software and out of date security patches played a key part in the stock exchange being hacked last year, according to the reported preliminary results of an FBI investigation. Forensic investigators found some PCs and servers with out-of-date software and uninstalled security patches, Reuters reported, including Microsoft Windows Server 2003. The stock exchange had also incorrectly configured some of its firewalls. NASDAQ, which prides itself on running some of the fastest client-facing systems in the financial world, does have a generally sound PC and network architecture, the FBI reportedly found. But sources close to the investigation told Reuters that NASDAQ had been an ‘easy target’ because of the specific security problems found. Investigators had apparently expressed surprise that the stock exchange had not been more vigilant.”

Read more of this story at Slashdot.


Slashdot

Mozilla ships Firefox 8, adds Twitter search and patches 8 bugs

Mozilla on Tuesday released Firefox 8, adding Twitter search to the browser and patching eight vulnerabilities.
Computerworld News

Microsoft patches critical IE, Silverlight drive-by bugs

Microsoft today shipped eight security updates that patched 23 vulnerabilities in Windows, Internet Explorer (IE), .Net Framework, Silverlight and other bits in its portfolio.
Computerworld News

Mozilla puts Firefox 7 on memory diet, patches 11 bugs

Mozilla on Tuesday patched 11 vulnerabilities in the desktop edition of Firefox as it upgraded the browser to version 7.
Computerworld News