Showing posts with label Critical Vulnerability. Show all posts
Showing posts with label Critical Vulnerability. Show all posts

Monday, 2 November 2015

Forgotten Explorer Vulnerability In Windows 10 Still Patched


Microsoft has previously forgotten vulnerability in Internet Explorer for Windows 10 yet patched. On October 13 released Microsoft Security Bulletin MS15-106 for several critical vulnerabilities in Internet Explorer that could allow an attacker the underlying system could take over completely.

Several of the vulnerabilities were corrected by the Zero Day Initiative (ZDI) of security firm TippingPoint reported to Microsoft. Researchers can at ZDI sell vulnerabilities fee, and TippingPoint notifies the responsible supplier. Next, details of the vulnerability published as the supplier has solved the problem, or has not complied with the deadline of the ZDI.

In this case, made ​​after the publication of the TippingPoint Security Bulletin MS15-106 know that Microsoft is a critical vulnerability in Internet Explorer 11 for Windows 10 had composed, designated as CVE-2015-6045. The vulnerability, however, was not mentioned in the Microsoft Security Bulletin itself, what questions on Twitter made. TippingPoint then pulled the own publication about the vulnerability away.

It now appears that Microsoft had not patched the vulnerability. Thursday appeared namely a new version of the Microsoft Security Bulletin which announces that a new cumulative update was released CVE-2015-6045 in which it is resolved. The update is only for Windows 10, which also need to install the new update. On most systems, however, this happens automatically.

Saturday, 24 October 2015

Google Slow Closing Of Flash Vulnerability In Chrome


A critical vulnerability in Adobe Flash Player which last week an emergency patch released almost a week later poem by Google in Chrome. Notable because Google updates for Flash Player sometimes been rolled out in Chrome than Adobe releases updates to users.

Chrome includes an embedded version of Flash Player must be updated by Google. Last week Friday, October 16th Adobe released an emergency patch for a critical vulnerability in which was actively used to infect computers with malware. Microsoft added this update on October 19 to 10 and Internet Explorer 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Edge on Windows 10. These browsers also feature an embedded Flash Player.

Yesterday, Thursday, October 22, Google came only with a new version of Chrome, the update was processed. It is in this case Chrome 46.0.2490.80 for Windows, Mac and Linux. This version will be automatically installed on most systems. The latest version of Adobe Flash Player 19.0.0.226. Through this page from Adobe, see what version of the system state.

Wednesday, 21 October 2015

Joomla Warns Very Important Update


The makers of the very popular content management system (CMS) Joomla will next Thursday a "very important security" issue, as they have announced. The update would be for a critical vulnerability in the core of Joomla.

Joomla advises managers to be ready for the update Thursday to roll out immediately. "Understand that we are up to the release of the release can provide any further information," according to the developers.

Friday, 2 October 2015

Avast Close Criticism SSL Vulnerability In Anti-Virus Software



The Czech anti-virus company Avast has a critical vulnerability in the anti-virus software patched it was discovered by a researcher from Google and which allowed an attacker to execute arbitrary code by users. The problem arose in Web Shield, part of the anti-virus software.

The virus Avast scans the contents of this web traffic. To be able to check via HTTPS encrypted traffic install the anti-virus software an own root certificate. A controversial practice that was also used by the Super Fish-adware. The way Avast this had been implemented made ​​it possible for websites to execute arbitrary code on the system remotely via a specially crafted SSL certificate.

The vulnerability was discovered by Google researcher Tavis Ormandy, who also significant problems in the anti-virus software from Sophos, ESET and Kaspersky Lab discovered. Ormandy warned Avast on September 25 and yesterday evening the virus fighter rolled an update for the problem. The researcher shows via Twitter, however, know that there are still more arrive.

Sunday, 5 July 2015

Critical Vulnerabilities In Tor And Tails Corrected


There are new versions of Tor Browser and Tails appeared, two programs for people who want to protect their privacy and anonymity on the Internet, where critical vulnerabilities are fixed. Users also have strongly advised to upgrade, since users of Tor Browser still using an old version surfed in the past been the target of attacks, their actual IP address was traced .

Via Tor Browser, users can easily hide their IP address. The browser consists of a modified version Firefox and software to connect to the network-Tor. This week a new version of Firefox, allowing the developers of Tor Browser also had to release a new version. Tor Browser 4.5.3 also includes a new version of OpenSSL and NoScript Torbutton, as well as a fix for a bug that allowed the browser crash and a patch to improve the usability of Tor Browser on websites. Updating via Torproject.org if the update function of the browser.

Tails

Users of Tails get urgent advice to Tails 1.4.1 upgrade. Tails is a complete operating system from a DVD or USB stick to use and is totally focused on privacy. It is based on Debian and contains various tools to access the Internet anonymously, including Tor Browser. In the past, for which the new versions of Tor Browser and Tails were not coordinated.

Therefore Tails users could sometimes several weeks stuck with an outdated Tor Browser. Now Tails development team has been waiting for the new Tor Browser, which added to the operating system. In addition, several Debian-related vulnerabilities are resolved. Updating via the Tails website .

Wednesday, 1 July 2015

Researchers Found Vulnerabilities In Antivirus ESET



A researcher from Google has discovered a vulnerability in the security of the Slovak anti-virus company ESET, but a day before the virus fighter problem patched a group of other researchers unveiled a new vulnerability in ESET Smart Security 8.

Last week Google revealed researcher Tavis Ormandy a critical vulnerability which he computers using ESET software without user interaction could remotely take over completely. After being informed ESET came after three days with an update. Ormandy discovered another problem in the security software. This time could an attacker when unpacking a specially prepared Symbian installation cause a heap overflow, and thus execute malicious code on the computer. On June 26, after having been informed within three days, came ESET with an update to address the vulnerability.

Second vulnerability

Another group of researchers called QWERTY Lab discovered a vulnerability in a part of ESET Smart Security 8. Through the leak an attacker can gain the highest privileges in Windows. Then, the virus can be disabled, but it is also possible to bypass Windows access controls and sandboxes, as the researchers claim. As proof, they published a proof-of-concept exploit.According to the researchers, the problem confirmed Smart Security 8 but were also other anti-virus company vulnerable. On June 25, the issue was made ​​public, the researchers decided to inform ESET in advance.

The virus fighter know that the vulnerability found in several earlier versions for Windows is available. The latest version of the security software is not vulnerable. At present we are working on an update for the problem which "fast" should appear, but an exact date could not give ESET. Following the various vulnerabilities requires another investigator when ESET and other anti-virus companies are auditing their products.

Monday, 2 March 2015

Criticism Leak Discovered In Seagate NAS Systems

Seagate

A researcher has a critical vulnerability in several NAS hard drive manufacturer Seagate discovered that an attacker can potentially thousands of these devices on the internet can take over, but despite months of communication about the problem, there is still no update for affected users are available.

The problem is in the Seagate Business NAS systems, according to the researcher Beyond Binary be used by both consumers and businesses. Through the systems, it is possible to store data and to share. To create users, set access rights, file management and other issues are the NAS systems provide a web management application.

The researcher discovered that this application is based on three outdated technologies, namely PHP version 5.2.13 (2010), CodeIgniter 2.1.0 (2011) and Lighttpd 4.1.28 (2010). The versions of PHP and CodeIgniter contain several vulnerabilities. In addition, also found problems in the application developed by Seagate. An attacker who adapts the session cookie can therefore eventually execute code as the user "root".

Meanwhile, there are a Metasploit module and a Python script developed to vulnerable systems can be attacked. The requirement is that the NAS can be accessed via the internet. A search via the search engine Shodan yielded more than 2,500 potentially vulnerable NAS systems. The problem has been confirmed on NAS systems with firmware 2014.00319 and 2013.60311, but the researcher suggests that basically all firmware versions are vulnerable.

In addition to the access data to attack the NAS systems within an organization can have far greater consequences. The NAS does not work with Active Directory or LDAP. Therefore they need the password for each user who needs access locally. These passwords are vulnerable through the MD5 hashing algorithm hashed. According to the researcher NAS systems at companies are undoubtedly contain passwords that are reused by domain users. An attacker who has access to the NAS can thus steal the MD5 hashes and crack, and discover the domain data.

Despite the severity of the problem, there is no update available, and the question is whether that will come. On 7 October 2014, the researcher reported the problem to Seagate. Then followed sorts messages where it appeared difficult for the investigation to catch the right person. Late January a Seagate employee could reproduce the problem using the supplied exploit. The researcher stated on January 17 that he wanted to publish the issue on 1 March.

However, this did not lead to an update since last Thursday Seagate said that there is no solution yet available. Users who want to protect themselves get therefore advised to make the NAS not accessible from the public Internet and placing the devices behind a firewall and only give several reliable IP addresses access.

Saturday, 31 January 2015

Vulnerabiltiy: Google Reveals Adobe Reader Leak for Mac OS X


Google has unveiled a vulnerability in Adobe Reader in the Windows version of the PDF reader would be patched, but the Mac version is still present. The vulnerability was reported to Adobe in October last year.In December there was an update for the Windows version appeared, but Adobe had to Google that it had failed to deliver a solution for the Mac version.

This week, however, went the deadline had asked Google. "Project Zero Team" of the search giant is looking specifically for vulnerabilities in commonly used software. Once a leak is found will the supplier 90 days to come up with an update, other details are the vulnerability automatically made ​​public. Adobe was warned by Google that it would reveal the details.

Via the leak, it is possible to let the application crash, which is possible up to a "heap-based buffer overflow" can cause.Noteworthy is the way that Adobe to Google said to have patched the flaw in the Windows version. The leak in question, known as CVE-2014-9160, however, does not appear in the list of Adobe Reader update.