Showing posts with label Critical Vulnerabilities. Show all posts
Showing posts with label Critical Vulnerabilities. Show all posts

Wednesday, 10 February 2016

Adobe Close Critical Vulnerabilities In Flash Player And Photoshop



Adobe has patched critical vulnerabilities in Flash Player and Photoshop computers could allow an attacker to take complete. In the case of Flash Player is about 22 critical vulnerabilities which allowed an attacker to execute arbitrary code on the computer, such as installing malware by just visiting a hacked website or see it from an infected ad.

There was no further interaction required from users. As far as known vulnerabilities are not attacked on the Internet. Since attackers often develop after the release of Flash Player updates exploits to attack unpatched users, Adobe advises to update to Flash Player version 20.0.0.306 within 72 hours. This can be done via the automatic update function or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Windows 10 Edge Embedded Flash Player will be updated using the browser. Through this Adobe page can be verified that the system version is installed.

There is also a security update for Adobe Photoshop CC and Adobe Bridge CC appeared. The update fixes three critical vulnerabilities that an attacker could take over your computer if opened a malicious file. Because Photoshop traditionally not been a target for attackers, Adobe advises users and administrators to install the update if it suits them. Updating via the built-in updater of drawing programs. In the case of Photoshop CC 02.04.2014 is the update to download only via Adobe.com.

Thursday, 5 November 2015

Automatic Update QuickTime Does Not Work On Windows 10


There is a problem with the automatic update feature of QuickTime on Windows 8 and 10, which indicates that the updater users up-to-date, even though there is a new version available. In August released QuickTime 7.7.8 in which multiple critical vulnerabilities were patched.

Through the nine vulnerabilities could allow an attacker to crash the progam or arbitrary code on the computer can perform, such as installing malware. The opening of a malicious media file would be sufficient in this case.

According to Alton Blom this is probably because QuickTime is not automatically on Windows 8 and 10 installs a new version, while this is the case with other Windows versions. Blom approached Apple. The company informed him that QuickTime 7.7.8 for Windows 7 and Vista is designed. When Apple this version also automatically on Windows 8 and will roll out later is unknown. Users can as a temporary solution to the latest version from the Apple website to download. Although this is in accordance with Blom initially did not work, the version offered would now be able to be installed without difficulty.

Wednesday, 4 November 2015

Critical Android Leak Fixes In Nexus Devices



During the patch cycle is from November Google poem multiple critical vulnerabilities in the Android version of Nexus devices, allowing an attacker to execute remote code on smartphones and tablets. Just as Microsoft is also Google each month with security updates.

It is in this case for updates to Nexus devices. The updates November fix seven vulnerabilities, two of which are labeled as critical. Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message, or if the user opens an e-mail or website. These are two leaks in the media server and libutils. The remaining five vulnerabilities, including one in the Stage Fright library, have a lesser impact.

According to Google, Android has several security measures that reduce the likelihood that Android leaks can be attacked successfully. For example, there are anti-exploit measures added to newer versions Android. In addition, search the Android Security Team via Verify Apps and SafetyNet to potentially harmful applications. Further send Google Hangouts, and Messenger will not automatically media to processes such as media server.

Updates are over-the-air (OTA) offered and are also available as firmware download. When the updates for the Android handsets from other manufacturers appear is unknown.

Saturday, 22 August 2015

Apple Close Critical Holes In Windows Version QuickTime


For users of QuickTime there's a new version appeared which have been addressed several critical vulnerabilities. Through the nine vulnerabilities, an attacker can crash the Program, or any computer can perform, such as installing malware.

The opening of a malicious media file would be sufficient in this case. Six of the nine vulnerabilities were found by researchers from network giant Cisco, while one vulnerability on account of Apple came. Apple advises users to upgrade to QuickTime 7.7.8, which through Apple.com and Apple Software Update to download.

Sunday, 1 February 2015

Google Pays Researchers 4 Million For Bug Reports


Since Google in 2010 with a program in which the researchers began paying for reporting vulnerabilities and other security issues in their own software has more than 4 million dollars paid to rewards. Last year, more than $ 1.5 million to more than 200 different researchers made. The highest reward was an amount of $ 150,000 , for the well-known hacker George Hotz. Hotz was then invited to walk in the Project Zero Team Google internship that is actively looking for leaks in many popular programs.

Through the rewards Google hopes to find vulnerabilities that might otherwise be missed. Last year more than 500 bugs were discovered in this way and rewarded. This year, Google continues to expand the reward program, as the search giant announced . There is also monetize vulnerabilities in Google applications on Android and iOS and come and scholarships for security researchers. In this case, Google will pay the investigator for his research, even if no vulnerabilities found.

The reward programs would ensure that it is becoming increasingly difficult to find vulnerabilities, which can discourage researchers to invest their time. Therefore now started this experimental program in which researchers already before they have examined a scholarship one line of code, with a maximum amount of $ 3113.70. Research fellows will also find that leak still qualify for the applicable bugbeloning.