| 

Security vulnerability in NVIDIA's proprietary Linux drivers fixed

  • Post author: Omid Farhang
  • Post published: April 12, 2012
  • Reading Time: 1 min
  • Word Count: 213 words

The H-Online: A new version of NVIDIA’s proprietary UNIX graphics drivers for Linux, Solaris and FreeBSD fixes a security vulnerability (CVE-2012-0946) that allowed attackers to read and write arbitrary system memory in order to, for example, obtain root privileges. To take advantage of the vulnerability, an attacker must have access permission for some device files – which, for systems with these drivers, is typically the case for users who can launch a graphical interface as 3D acceleration and some other features cannot be used otherwise. ...

Continue Reading Security vulnerability in NVIDIA's proprietary Linux drivers fixed

Google updates OAuth 2.0 Playground

  • Post author: Omid Farhang
  • Post published: March 31, 2012
  • Reading Time: 2 min
  • Word Count: 220 words

The H-Security: Google has added new features to its OAuth 2.0 Playground, which it launched last November. Developers can now switch to using client-side flow, and the system has added support for APIs that use OAuth 2.0 drafts 10 to 25. Google has also added a feature that makes it easy to see all available API operations supported by the user’s current access token. To make it easier to use the Playground for an extended amount of time, developers now have the ability to refresh their access tokens automatically, and clicking HTTP response links will now populate the request URI field. ...

Continue Reading Google updates OAuth 2.0 Playground

Adobe Flash enables auto-updating while patching two critical flaws

  • Post author: Omid Farhang
  • Post published: March 29, 2012
  • Reading Time: 1 min
  • Word Count: 190 words

SophosLabs: Adobe released Flash Player version 11.2.202.228 for Windows, OS X and Linux today. In my view this is a milestone release as it finally introduces an automatic, silent updating mechanism to help users stay current with the latest releases from here forward. Google Chrome users may consider themselves spoiled, as they have been enjoying the worry-free joy of automatic updating of both their browser and integrated plugins like Flash Player for quite some time. ...

Continue Reading Adobe Flash enables auto-updating while patching two critical flaws

Embarrassing security failure at PayPal

  • Post author: Omid Farhang
  • Post published: March 22, 2012
  • Reading Time: 2 min
  • Word Count: 303 words

The H-Security: Until just a few days ago, web sites belonging to the world’s largest online payment service contained a security vulnerability in a key component that could have been exploited by fraudsters to steal information from customers. PayPal fixed the vulnerability shortly after being notified of its presence by The H’s associates at heise Security. The eBay subsidiary was, however, unable to give any information on how such a serious security problem could have remained undetected. ...

Continue Reading Embarrassing security failure at PayPal

Chrome 17 update fixes high-risk vulnerabilities

  • Post author: Omid Farhang
  • Post published: March 22, 2012
  • Reading Time: 2 min
  • Word Count: 218 words

The H-Security: Google has released version 17.0.963.83 of its Chrome web browser, a maintenance update that fixes issues with Flash games and closes several security holes. The Stable channel update addresses a total of nine vulnerabilities, six of which are rated as “high severity“. These include an integer issue in libpng (the official PNG reference library), a memory corruption problem in WebGL canvas handling and a cross-origin violation related to “magic iframe”, as well as use-after-free errors in first-letter handling, CSS cross-fade handling and block splitting. One medium-risk invalid read in the V8 JavaScript engine and two low-risk problems related to WebUI privileges and unpacked extension installation have also been fixed. ...

Continue Reading Chrome 17 update fixes high-risk vulnerabilities

Pidgin IM client 2.10.2 closes DoS holes

  • Post author: Omid Farhang
  • Post published: March 15, 2012
  • Reading Time: 1 min
  • Word Count: 207 words

The H-Online: Version 2.10.2 of the open source Pidgin instant messaging program has been released. According to its developers, the maintenance and security update brings a number of changes and addresses two denial-of-service (DoS) vulnerabilities that could be exploited by an attacker to cause the application to be terminated. These remote crashes are caused when the MSN server sends messages that are not UTF-8 encoded and also when some types of nickname changes occur in chat rooms using the XMPP protocol. Versions up to and including 2.10.1 are affected. Pidgin 2.10.2 fixes these issues and all users are advised to upgrade. ...

Continue Reading Pidgin IM client 2.10.2 closes DoS holes

Firefox 11 release postponed due to security issues [Updated]

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 2 min
  • Word Count: 314 words

H-Online: The Firefox team has announced that they are postponing the release of Firefox 11, originally planned for today, because of a security report which the team wants to evaluate to make sure the issue will not impact on their code. Jonathan Nightingale, Mozilla’s Senior Director of Firefox Engineering, also Microsoft’s monthly Patch Tuesday security update, also scheduled for today, as a reason to hold back on releasing the new Firefox version. ...

Continue Reading Firefox 11 release postponed due to security issues [Updated]

Chrome security update and researchers' bonuses

  • Post author: Omid Farhang
  • Post published: March 5, 2012
  • Reading Time: 2 min
  • Word Count: 267 words

The H-Security: Google has released a new stable version of its Chrome browser. The update fixes seventeen high severity vulnerabilities and updates the bundled Flash player. Google referred users to Adobe for details of the Flash Player update, and as usual, revealed few details about the seventeen holes that it closed in the release. It did, though, say that the researchers earned between $500 and $3000 for their vulnerability disclosures. ...

Continue Reading Chrome security update and researchers' bonuses

HTTPS Everywhere reaches 2.0, comes to Chrome as beta

  • Post author: Omid Farhang
  • Post published: March 1, 2012
  • Reading Time: 2 min
  • Word Count: 237 words

H-Online: Version 2.0 of the HTTPS Everywhere browser extension has been released. Where possible, the add-on automatically redirects users to more secure HTTPS connections when they access certain web pages. HTTPS Everywhere 2.0 includes an optional “Decentralised SSL Observatory” feature that detects weaknesses in encryption. When the extension detects an encryption issue, such as weak keys, it notifies users that the site they are visiting may contain security vulnerabilities that could be used to for man-in-the-middle (MITM) attacks. “This is an extra level of protection that we encourage Firefox users to download, install, and use” said Electronic Frontier Foundation (EFF) Technology Projects Director Peter Eckersley. ...

Continue Reading HTTPS Everywhere reaches 2.0, comes to Chrome as beta

Shockwave Player critical holes closed

  • Post author: Omid Farhang
  • Post published: February 15, 2012
  • Reading Time: 1 min
  • Word Count: 133 words

The H-Online: Adobe has updated Shockwave Player on Windows and Mac OS X to version 11.6.4.634 after identifying nine critical vulnerabilities. The problems affect Shockwave Player 11.6.3.633 and all earlier versions on Windows and Mac OS X – Adobe recommend updating to the new release by downloading it from get.adobe.com/shockwave. To identify whether Shockwave Player is installed on a system, users should visit the test page on Adobe’s site. The majority of the problems are in the Shockwave 3D Asset where seven memory corruption vulnerabilities could lead to code execution; these were all reported by Hongnang Ren of FortiGuard Labs. An eighth memory corruption issue and a heap overflow vulnerability, both of which could also lead to code execution, were reported by “instruder” of vulnhunt.com and bring the flaw tally up to nine. ...

Continue Reading Shockwave Player critical holes closed